Locky Distribution Site :: empoweringinternationalministries.org

Host Information

Locky Distribution Site:empoweringinternationalministries.org
Threat:Distribution Site
Malware:Locky
URL:http://empoweringinternationalministries.org/images/sampledata/parks/animals/w.exe
Host Status:offline
Blacklist check:Spamhaus DBL:Not Listed
 SURBL:Not Listed
Domain Registar:GoDaddy.com, LLC
Firstseen (UTC):2016-03-27 09:39:08
Lastseen (UTC):never

Associated IP addresses

The table below shows all ip addresses (e.g. A records) associated with this Locky Distribution Site. In case the host is a domain name, the table also shows a history of previous A records if there are any.

Active (?This row indicates whether the domain name's A record is currently pointing to an IP address or whether the record is historic (e.g. because the A record has been moved to a different IP address).

yes = Active A record
no = Historical record
)
Firstseen (UTC)Lastseen (UTC)IP addressHostnameSBLAS numberAS nameCountry
no2017-10-13 01:50:212017-10-24 01:51:1850.63.202.29ip-50-63-202-29.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-01-18 01:52:102018-01-29 01:55:44184.168.221.93ip-184-168-221-93.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2016-03-27 09:39:082017-02-27 01:56:35216.224.170.39vps-1163923-22671.manage.myhosting.comNot listedAS22905ITCDELTA - Earthlink, Inc., US- United States (US)
no2017-11-04 01:48:522017-12-01 07:19:3650.63.202.1ip-50-63-202-1.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2017-10-17 01:51:172017-10-22 01:50:0050.63.202.14ip-50-63-202-14.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2017-04-02 02:00:102017-05-06 01:55:4350.63.202.15ip-50-63-202-15.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2017-09-22 01:52:342017-09-26 01:47:2250.63.202.17ip-50-63-202-17.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2017-03-04 12:24:282017-03-26 01:56:5250.63.202.18ip-50-63-202-18.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2017-10-03 01:52:112017-10-06 01:50:5650.63.202.19ip-50-63-202-19.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2017-12-20 05:30:052018-01-11 01:55:2750.63.202.20ip-50-63-202-20.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2017-03-03 01:57:522017-10-04 01:50:1350.63.202.21ip-50-63-202-21.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2017-03-10 13:22:002017-09-23 01:45:4150.63.202.24ip-50-63-202-24.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2017-05-07 02:00:04never50.63.202.26ip-50-63-202-26.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2017-03-14 01:56:252017-12-29 07:26:4750.63.202.27ip-50-63-202-27.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-01-20 01:54:35never184.168.221.85ip-184-168-221-85.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2017-03-27 01:58:262018-01-09 01:53:3150.63.202.3ip-50-63-202-3.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2017-03-22 01:57:04never50.63.202.30ip-50-63-202-30.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-01-12 01:54:16never50.63.202.4ip-50-63-202-4.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2017-10-01 01:48:402017-11-09 01:50:3450.63.202.6ip-50-63-202-6.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-01-25 01:50:31never50.63.202.64ip-50-63-202-64.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-02-16 01:50:18never50.63.202.65ip-50-63-202-65.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-01-30 01:52:06never50.63.202.66ip-50-63-202-66.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-02-07 01:49:25never50.63.202.67ip-50-63-202-67.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2017-03-05 02:00:332017-05-10 01:58:5750.63.202.7ip-50-63-202-7.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-01-26 01:52:102018-02-18 01:51:0650.63.202.74ip-50-63-202-74.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)

# IPs found: 25 (max. 25)

Dropped files

Latest 100 files (malware samples) dropped by this distribution site.

Firstseen (UTC)MD5 hashFilesizeVTSignature
2016-03-27 20:02:1162995e8f96e10f10cf436e8a35de319a133'583 bytesVirustotal results 45/57 (78.95%) Locky
2016-03-27 19:40:201769f98e0070a8332947ed75196b1730108'032 bytesVirustotal results 37/57 (64.91%) ERROR: Too many connections
2016-03-27 17:58:41f065a465b2fa660766497742ed350c98108'032 bytesVirustotal results 22/58 (37.93%) n/a
2016-03-27 09:28:547c9bfec0c0f1756c76088a45b157148e117'511 bytesVirustotal results 28/58 (48.28%) Locky

Unique dropped files: 4