Help RSS API Feed Maltego Contact                        

Domain > cluster4.eu.messagelabs.com

More information on this domain is in AlienVault OTX

Is this malicious?

Files that talk to cluster4.eu.messagelabs.com

MD5A/V
d42c1a59b111316f7481770349e653db[HW32.CDB.87f3] [Malware.Packer.OCD]
3fb83eaf2a665f71ac2065f5f6956d50[HW32.CDB.5da2] [Packed.Win32.Katusha.1!O] [Trojan.Win32.Hlux.cynagk] [Trojan.FakeAV] [Kryptik.CDQY] [Win32/Kelihos.GeEUUIB] [Backdoor.Win32.Hlux.dqkq] [Backdoor.Hlux!m6CCC6SKjdo] [Win32.Backdoor.Hlux.Lose] [Backdoor.Win32.Hlux.DUHE] [Trojan.Packed.26581] [Trojan[Backdoor]/Win32.Hlux] [Win32.Hack.Hlux.dq.(kcloud)] [Backdoor:Win32/Kelihos.F] [Trojan/Win32.Tepfer] [Heur.Trojan.Hlux] [Trojan.Crypt_s] [W32/Hlux.BWUN!tr.bdr] [Crypt_s.GNC] [Backdoor.Win32.Hlux.aDM]
4211b2d7121c11d5f032e6620030a384[HW32.CDB.Cd7e] [Packed.Win32.Katusha.3!O] [Hlux.ZY] [VirTool:Win32/Obfuscator.WT]
db5b440f6419090cd9567f3b33fd3ced[Malware.Packer.HGX1] [BackDoor.SlymENT.1498] [Heuristic.LooksLike.Win32.Suspicious.E] [W32/Kryptik.AXUE!tr]
c7bf064346fafe4fc55b43abcfe96b00[HW32.CDB.E6f3] [Backdoor.Kelihos.r3] [Backdoor.Hlux!zUFIktBYK3s] [Kryptik.CCFN] [Backdoor.Win32.Hlux.djfw] [Trojan.Win32.S.PSW-Tepfer.835600.AM] [UnclassifiedMalware] [BackDoor.Slym.14049] [Mal/Kelihos-A] [Backdoor:Win32/Kelihos] [Trojan/Win32.Tepfer] [W32/Trojan.QQUO-1304] [Backdoor.Hlux] [Trojan.Crypt_s] [W32/Kryptik.BWUN!tr] [Crypt3.HUC] [Trojan.Win32.Kryptik.BZIX]
1cc0cfa5485d814b67ace50cb0a5b100[HW32.CDB.E978] [Kryptik.CDQY] [UnclassifiedMalware] [Trojan.Packed.26527] [Backdoor:Win32/Kelihos] [W32/Trojan.KUPJ-3598] [Heur.Trojan.Hlux] [Win32.SuspectCrc] [W32/Hlux.BWUN!tr.bdr] [Crypt_s.GKU]
7abb1e7e80e0f342f0452ae91375fce3
9c047dc17522767f4abf0ce34044af91[HW32.CDB.741c] [W32/Worm-AAEH.pq!9C047DC17522] [WS.Reputation.1] [Injector.GJTG] [Worm.Win32.VB.NG] [Win32.HLLW.Autoruner2.12544] [Worm/Vobfus.agcpv] [Mal/VB-ALW] [Worm:Win32/Vobfus.ZR] [PE:Malware.XPACK-HIE/Heur!1.9C48] [Worm.Win32.Vobfus] [Inject2.ABEP] [Trojan.Win32.Injector.BCCY] [Win32/Trojan.266]
5ee74c52944265c5a84f878040e02331[HW32.CDB.27c8] [Trojan.Win32.Hlux.cxadam] [Kryptik.CCFN] [Backdoor.Win32.Hlux.dlza] [Backdoor.Hlux!t6Evi7JomQk] [TrojWare.Win32.Kryptik.CASU] [BackDoor.Slym.13362] [Heuristic.BehavesLike.Win32.Suspicious-BAY.G] [Mal/FakeAV-UF] [Trojan[Backdoor]/Win32.Hlux] [VirTool:Win32/Obfuscator.WT] [Trojan/Win32.Tepfer] [Heur.Trojan.Hlux] [Backdoor.Win32.Hlux.AHTW] [Win32/Kryptik.CASL] [Win32.Backdoor.Hlux.Tbjb] [Backdoor.Win32.Kelihos] [W32/Hlux.CASL!tr.bdr]
2c2371e95bb5d87ccd5d19a114492f70[HW32.CDB.18af] [Packed.Win32.Katusha.3!O] [WS.Reputation.1] [Kryptik.CDQY] [TrojWare.Win32.Kryptik.CBCJ] [BackDoor.Slym.13873] [Backdoor:Win32/Kelihos.F] [Trojan/Win32.Tepfer] [Heur.Trojan.Hlux] [Backdoor.Win32.Kelihos] [Crypt_s.GNC] [Trojan.Win32.Kryptik.CBCJ] [Win32/Trojan.0de]
888cf6888e476ab89daef8385b7ae881[HW32.CDB.B8e4] [Backdoor.Hlux.r3] [Trojan.Win32.Hlux.cxcinh] [Kryptik.CCFN] [Backdoor.Win32.Hlux.djfk] [Backdoor.Hlux!Jm3TflIszzA] [Mal/Kelihos-A] [TrojWare.Win32.Kryptik.BZOO] [Trojan.DownLoad3.28912] [Trojan[Backdoor]/Win32.Hlux] [Backdoor:Win32/Kelihos] [Trojan/Win32.Tepfer] [Heur.Trojan.Hlux] [Trojan.Crypt_s] [W32/Hlux.BWUN!tr.bdr] [Crypt_s.GHF] [Trojan.Win32.Kryptik.BZIX]
315325f544912a68464bf38e3edf6371[HW32.CDB.9e5e] [Backdoor/W32.Hlux.829456.H] [Packed.Win32.Katusha.3!O] [Backdoor.Hlux.r3] [Backdoor.Hlux!aauIqdu764w] [Trojan.FakeAV] [Kryptik.CDQY] [Backdoor.Win32.Hlux.dqyy] [Win32.Backdoor.Hlux.Lhdb] [UnclassifiedMalware] [Trojan.Packed.26581] [Win32.Hack.Hlux.dq.(kcloud)] [Backdoor:Win32/Kelihos.F] [Backdoor.Hlux] [Trojan.Crypt_s] [W32/Kryptik.BWUN!tr] [Crypt_s.GNC] [Backdoor.Win32.Hlux.aZvR] [Win32/Trojan.337]
4b93f892d9249b70508ee222e37ee1c6[HW32.CDB.E823] [TrojanPSW.Tepfer.r3] [Trojan.Win32.Kryptik.cxbvtz] [WS.Reputation.1] [Kryptik.CCFN] [Trojan-PSW.Win32.Tepfer.txbj] [Trojan.PWS.Tepfer!TcJrQOwJyhs] [Mal/FakeAV-UF] [BackDoor.Slym.13348] [Heuristic.LooksLike.Win32.Suspicious.E] [Trojan[PSW]/Win32.Tepfer] [Backdoor:Win32/Kelihos.F] [Trojan/Win32.Tepfer] [Heur.Trojan.Hlux] [Trojan.Win32.Kryptik.CAUP] [Trojan.Crypt_s] [W32/Tepfer.CAUP!tr.pws] [Crypt_s.GMK]
2c05ffe297116df3062faac792c44c91[HW32.CDB.B4b9] [Packed.Win32.Katusha.3!O] [WS.Reputation.1] [Kryptik.CDQY] [UnclassifiedMalware] [BackDoor.Slym.13873] [Win32.Troj.Undef.(kcloud)] [Backdoor:Win32/Kelihos.F] [Trojan/Win32.Tepfer] [Heur.Trojan.Hlux] [Trojan.Crypt_s] [W32/Kryptik.BD!tr] [Crypt_s.GNC] [Win32/Trojan.0de]
4be57c95dd1e77ba6b00af63f6c5d79a[BackDoor.Slym.1498] [BDS/Kelihos.F.5092] [Win32.PSWTroj.Tepfer.hd.(kcloud)] [Backdoor:Win32/Kelihos.F] [Backdoor/Win32.Kelihos] [Backdoor.Win32.Kelihos] [W32/Kelihos.JI!tr]
1623be5a046aa215162665c5067332e0[HW32.CDB.Db63] [Packed.Win32.Katusha.3!O] [WS.Reputation.1] [Kryptik.CDQY] [Trojan-PSW.Win32.Tepfer.tybm] [Trojan.PWS.Tepfer!sA6n+JUlMF8] [UnclassifiedMalware] [Trojan.Packed.26581] [Backdoor:Win32/Kelihos.F] [W32/Trojan.YSDP-3009] [Heur.Trojan.Hlux] [Trojan.Crypt_s] [W32/Kryptik.BWUN!tr] [Crypt_s.GNC] [Trojan.Win32.InfoStealer.aRBP]
61b408e2de1c4996c3708f1f46913d60[HW32.CDB.C1b5] [Trojan.Kryptik!QyFpAm9uzfY] [Kryptik.CCFN] [Backdoor.Win32.Hlux.djft] [Trojan.Win32.S.PSW-Tepfer.835600.AI] [UnclassifiedMalware] [BackDoor.Slym.14044] [Mal/Kelihos-A] [Trojan[Backdoor]/Win32.Hlux] [Trojan/Win32.Tepfer] [W32/Trojan.AJYO-7526] [Backdoor.Hlux] [Trojan.Crypt_s] [W32/Kryptik.BWUN!tr] [Crypt3.HUF] [Trojan.Win32.Kryptik.BZIX]
0dd56a0b8ea7bedb57cebf9aacdac40f[Malware.Packer.HGX1] [Heuristic.BehavesLike.Win32.Suspicious-BAY.G] [W32/Kryptik.AXUE!tr]
14bfd82cc98684fb9c3e91971d2490b1[HW32.CDB.Eb32] [Packed.Win32.Katusha.3!O] [WS.Reputation.1] [Kryptik.CDQY] [UnclassifiedMalware] [BackDoor.Slym.13873] [Win32.Troj.Undef.(kcloud)] [Backdoor:Win32/Kelihos.F] [Trojan/Win32.Tepfer] [Heur.Trojan.Hlux] [Trojan.Win32.Kryptik.CBCJ] [Trojan.Crypt_s] [W32/Kryptik.BD!tr] [Crypt_s.GNC]
45e45d9707887dc0cc0da495b7968acd[FakeSecTool-FCX!45E45D970788] [Malware.Packer.FFS] [BackDoor.SlymENT.2075] [Heuristic.LooksLike.Win32.Suspicious.E] [PE:Malware.XPACK/RDM!5.1]

Whois

PropertyValue
NameDomain Manager
Organization Symantec Corporation
Email domains@symantec.com
Address 350 Ellis Street
Zip Code 94043
City Mountain View
State CA
Country US
Phone +1.6505278000
NameServer dns3.messagelabs.com
Created 1999-12-24 09:45:49
Changed 2014-05-29 20:19:04
Expires 2017-12-24 00:00:00
Registrar CSC CORPORATE DOMAIN

DNS Resolutions

DateIP Address
2013-05-1685.158.143.99 (ClassC)
2013-05-1785.158.138.51 (ClassC)
2014-07-0885.158.143.35 (ClassC)
2023-12-1885.158.142.208 (ClassC)
2025-04-03195.245.230.194 (ClassC)
2025-05-08195.245.231.77 (ClassC)

Subdomains

DateDomainIP
dns1.messagelabs.com2025-05-0934.255.225.9
dns2.messagelabs.com2025-05-0918.184.36.165
clients.boundarydefense.geuw2.messagelabs.com2025-04-2035.244.174.211
dns3.messagelabs.com2025-05-0934.236.119.202
dns4.messagelabs.com2025-05-0954.203.46.81
dns5.messagelabs.com2025-05-0718.232.42.210
mail18.messagelabs.com2014-04-25117.120.20.147
mail19.messagelabs.com2024-04-0185.158.139.163
mail79.messagelabs.com2014-07-23195.245.230.147
cluster1.sa.messagelabs.com2013-12-02196.14.170.67
de.messagelabs.com2014-04-10216.156.249.138
api.messagelabs.com2025-05-0834.120.155.164
provisioningapi.messagelabs.com2025-05-0834.120.245.144
cluster2.gsi.messagelabs.com2014-06-1662.25.80.157
cluster.gsi.messagelabs.com2014-05-2385.158.143.19
cluster2.hk.messagelabs.com2013-04-18117.120.16.147
cluster1.uk.messagelabs.com2013-05-1685.158.140.115
cluster1.ap.messagelabs.com2014-06-16117.120.16.147
cluster2.ap.messagelabs.com2013-05-16117.120.20.147
images.messagelabs.com2025-05-0834.117.231.212
cluster1.us.messagelabs.com2014-03-24216.82.249.211
cluster2.us.messagelabs.com2014-06-05216.82.249.211
cluster14.us.messagelabs.com2014-03-24216.82.248.67
cluster4.us.messagelabs.com2014-03-24216.82.250.19
cluster15.us.messagelabs.com2014-03-24216.82.253.148
cluster5.us.messagelabs.com2014-03-24216.82.242.147
cluster6.us.messagelabs.com2014-03-24216.82.254.20
cluster8.us.messagelabs.com2014-03-24216.82.249.147
cluster9.us.messagelabs.com2014-03-24216.82.249.51
cluster4a.us.messagelabs.com2025-04-0952.207.128.88
cluster5a.us.messagelabs.com2014-06-18216.82.251.230
cluster6a.us.messagelabs.com2014-01-30216.82.251.230
cluster8a.us.messagelabs.com2014-01-3085.158.139.103
cluster1.eu.messagelabs.com2013-05-16193.109.254.67
cluster2.eu.messagelabs.com2014-05-22195.245.230.131
cluster13.eu.messagelabs.com2013-12-0285.158.139.194
cluster3.eu.messagelabs.com2014-06-1685.158.137.67
cluster4.eu.messagelabs.com2014-07-0885.158.143.35
cluster5.eu.messagelabs.com2014-03-24193.109.254.3
cluster7.eu.messagelabs.com2013-05-16195.245.230.147
cluster8.eu.messagelabs.com2013-05-1685.158.140.195
cluster9.eu.messagelabs.com2013-05-16193.109.254.147
cluster1a.eu.messagelabs.com2025-03-2834.253.63.114
cluster2a.eu.messagelabs.com2025-03-3034.253.63.114
cluster3a.eu.messagelabs.com2025-04-0734.253.63.114
cluster4a.eu.messagelabs.com2025-04-0334.253.63.114
cluster5a.eu.messagelabs.com2024-12-1946.137.95.199
cluster8a.eu.messagelabs.com2014-06-18216.82.251.230
cluster9a.eu.messagelabs.com2024-11-1046.137.95.199
cluster3vk.eu.messagelabs.com2013-12-1885.158.137.67
www.messagelabs.com2014-04-23209.8.115.126
View on OTX | View on ThreatMiner








Data with thanks to AlienVault OTX, VirusTotal, Malwr and others. [Sitemap]



� Copyright 2019 AlienVault, Inc. | Legal| Status| Do Not Sell My Personal Information