Locky Distribution Site :: winawoof.com

Host Information

Locky Distribution Site:winawoof.com
Threat:Distribution Site
Malware:Locky
URL:http://winawoof.com/7fg3g
Host Status:offline
Blacklist check:Spamhaus DBL:Not Listed
 SURBL:Not Listed
Domain Registar:GODADDY.COM, LLC
Nameserver(s):ns1646.ztomy.com
 ns2646.ztomy.com
Firstseen (UTC):2016-10-28 10:16:09
Lastseen (UTC):never

Associated IP addresses

The table below shows all ip addresses (e.g. A records) associated with this Locky Distribution Site. In case the host is a domain name, the table also shows a history of previous A records if there are any.

Active (?This row indicates whether the domain name's A record is currently pointing to an IP address or whether the record is historic (e.g. because the A record has been moved to a different IP address).

yes = Active A record
no = Historical record
)
Firstseen (UTC)Lastseen (UTC)IP addressHostnameSBLAS numberAS nameCountry
yes2019-01-29 07:26:382019-08-20 07:18:46204.11.56.46Not listedAS40034CONFLUENCE-NETWORK-INC - Confluence Netw[...]- Virgin Islands, British (VG)
no2017-11-17 01:53:242018-06-16 01:57:52108.167.189.49gator4223.hostgator.comNot listedAS20013CYRUSONE - CyrusOne LLC, US- United States (US)
no2016-10-28 11:03:562017-11-16 01:55:08108.179.233.169Not listedAS20013CYRUSONE - CyrusOne LLC, US- United States (US)
no2018-06-22 07:32:462018-06-29 07:36:01184.168.221.69ip-184-168-221-69.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-07-06 07:31:452018-07-19 07:32:06184.168.221.79ip-184-168-221-79.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-07-07 07:35:532018-07-17 07:30:16184.168.221.82ip-184-168-221-82.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-06-18 01:57:192018-07-20 07:34:23184.168.221.90ip-184-168-221-90.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-07-18 07:31:262018-07-21 07:34:17184.168.221.93ip-184-168-221-93.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-08-28 07:35:272019-01-28 07:30:05204.11.56.48Not listedAS40034CONFLUENCE-NETWORK-INC - Confluence Netw[...]- Virgin Islands, British (VG)
no2018-06-20 07:33:022018-07-11 07:36:0150.63.202.75ip-50-63-202-75.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-06-27 07:36:33never50.63.202.87ip-50-63-202-87.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-06-26 07:36:392018-07-16 07:31:4850.63.202.88ip-50-63-202-88.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-06-17 01:55:472018-07-13 07:33:2350.63.202.89ip-50-63-202-89.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-07-10 07:34:20never50.63.202.91ip-50-63-202-91.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)
no2018-06-28 07:35:022018-07-14 07:33:3850.63.202.94ip-50-63-202-94.ip.secureserver.netNot listedAS26496AS-26496-GO-DADDY-COM-LLC - GoDaddy.com,[...]- United States (US)

# IPs found: 15 (max. 25)

Dropped files

Latest 100 files (malware samples) dropped by this distribution site.

Firstseen (UTC)MD5 hashFilesizeVTSignature
2016-10-29 01:00:3020db9dbf8ce79e80f8b0a0c2b9390a33237'568 bytesVirustotal results 5/60 (8.33%) # Not authorized
2016-10-28 10:52:13e6151a0259f7e2b29fd315b542bc9ba2266'240 bytesVirustotal results 0/53 (0.00%) n/a

Unique dropped files: 2