Help RSS API Feed Maltego Contact                        

Domain > cluster4a.us.messagelabs.com

More information on this domain is in AlienVault OTX

Is this malicious?

Files that talk to cluster4a.us.messagelabs.com

MD5A/V
803fdad60a108f80a0e664405cc2e176[HW32.CDB.37af] [Trojan.Packed.18626] [Heuristic.BehavesLike.Win32.ModifiedUPX.C] [Suspicious] [W32/Injector.ABXY!tr]
b1b1ae8fe089441e0e2e820d25475513[Win32.Mimail.S@mm] [Worm/W32.Mimail.11520] [W32.Mimail.R] [W32/Mimail.s@MM] [W32/Mimail.S@MM] [Win32.Mimail.S@mm] [Trojan.Win32.Mimail.fwgh] [W32/Mimail.S@mm] [W32.Mimail.S@mm] [Win32/Mimail.T] [WORM_MIMAIL.AB] [Worm.Mimail.R] [Email-Worm.Win32.Mimail.s] [I-Worm.Mimail.S] [I-Worm.Win32.Mimail.11520[h]] [W32.W.Mimail.s!c] [Win32.Mimail.S@mm] [W32/Mimail-S] [Worm.Win32.Mimail.T] [Win32.Mimail.S@mm] [Win32.HLLM.Foo] [Worm.Mimail.Win32.13] [WORM_MIMAIL.AB] [BehavesLike.Win32.Downloader.lc] [W32/Mimail.IGZZ-5850] [I-Worm/Mimail.s] [WORM/Mimail.S] [Worm[Email]/Win32.Mimail] [Worm:Win32/Mimail.S@mm] [Win32.Mimail.E18B31] [Win32/Mimail.worm.11520] [Win32.Mimail.S@mm] [Win32/Mimail.S] [Win32.Mimail.S@mm] [Worm.Mimail] [W32/Mimail.S.worm] [I-Worm.Mimail.T] [Win32.Worm-email.Mimail.Peyz] [Email-Worm.Win32.Mimail.U] [I-Worm/Mimail.S] [Worm.Win32.Mimail.T]
5dd40f7a82a917e18febd2ac10aa63f9[W32/Mimail.o@MM] [W32/Mimail.O@MM] [Trojan.Win32.Mimail.endv] [W32/Heuristic-257!Eldorado] [Trojan.ADH] [Mal_Avp] [Trojan.Dropper.JS.Mimail.B] [Email-Worm.Win32.Mimail.o] [I-Worm.Mimail!Xr1spbXMZWU] [Win32.HLLM.Foo] [Worm.Mimail.Win32.33] [Mal_Avp] [BehavesLike.Win32.Downloader.gz] [W32/Heuristic-257!Eldorado] [Worm/Mimail.q] [Worm[Email]/Win32.Mimail] [Worm.Mimail.o.502304.(kcloud)] [Worm:Win32/Mimail.S@mm] [Worm/Win32.Mimail] [Worm.Mimail] [Win32.Worm-Email.Mimail.bjnw] [Email-Worm.Win32.Mimail] [W32/Mimail.O@mm] [I-Worm/Mimail.O] [Worm.Win32.Mimail.at]
3d906c3174d208146532e57f7a382cf6[Win32/Mimail.C] [Win32.Mimail.C] [W32/Mimail.c@MM] [W32/Mimail.C@MM] [I-Worm.Mimail.C] [W32/Mimail.C@mm] [Win32/Mimail.C] [Trojan.Win32.Mimail.endj] [I-Worm.Win32.Mimail.28192[h]] [W32/Mimail-C] [Worm.Win32.Mimail.C] [Win32.HLLM.Foo] [Worm.Mimail.Win32.22] [BehavesLike.Win32.StartPage.mm] [W32/Mimail.DJCZ-4024] [I-Worm/Mimail.c] [WORM/Mimail.C1] [Worm[Email]/Win32.Mimail] [Worm:Win32/Mimail.C@mm] [Win32/Mimail.worm.26656.B] [Worm.Mimail] [I-Worm.Mimail.C] [Email-Worm.Win32.Mimail.U] [I-Worm/Mimail.C] [Worm.Win32.Mimail.AxB]
fa57458d47236f210f1cb3668e865116[Worm/W32.Mimail.10784.B] [W32.Mimail.F] [Artemis!FA57458D4723] [W32/Mimail.f] [Trojan.Win32.Mimail.endm] [W32/Mimail] [Win32/Mimail.F] [Email-Worm.Win32.Mimail.f] [I-Worm.Mimail.F] [I-Worm.Win32.A.Mimail.10784[h]] [W32/Mimail-E] [Worm.Win32.Mimail.F] [Win32.HLLM.Foo] [Worm.Mimail.Win32.9] [W32/Mimail.MFYK-7350] [I-Worm/Mimail.j] [WORM/Mimail.F] [Worm[Email]/Win32.Mimail] [Worm.Mimail.f.(kcloud)] [Worm:Win32/Mimail.G@mm] [Trojan/Win32.HDC] [Worm.Mimail] [W32/Mimail.P.worm] [I-Worm.Mimail.F] [Win32.Worm-email.Mimail.Edxf] [Email-Worm.Win32.Mimail.U] [W32/Mimail.F@mm] [I-Worm/Mimail.F] [Worm.Win32.Mimail.F]
99a0890b87a501e33cb4a26a3d0c2e08[Win32.Mimail.TXU] [Worm/W32.Mimail.10784] [W32.Mimail.D] [Win32.Mimail.TXU] [Win32.Mimail.TXU] [I-Worm.Mimail!Ubvyra2vcrc] [W32/Mimail.E@mm] [W32.Mimail.F@mm] [Win32/Mimail.E] [Worm.Mimail.E] [Email-Worm.Win32.Mimail.e] [Trojan.Win32.Mimail.endl] [I-Worm.Win32.Mimail.10784[h]] [W32.W.Mimail.e!c] [Win32.Mimail.TXU] [W32/Mimail-E] [Worm.Win32.Mimail.E] [Win32.Mimail.TXU] [Win32.HLLM.Foo] [Worm.Mimail.Win32.17] [BehavesLike.Win32.Dropper.lc] [W32/Mimail.HYUF-5134] [I-Worm/Mimail.i] [Worm[Email]/Win32.Mimail] [Worm:Win32/Mimail.E@mm] [Win32.Mimail.TXU] [Trojan/Win32.HDC] [Win32.Mimail.TXU] [Win32/Mimail.E] [Artemis!99A0890B87A5] [Worm.Mimail] [W32/Mimail.E.worm] [I-Worm.Mimail.E] [Win32.Worm-email.Mimail.Hvsq] [Email-Worm.Win32.Mimail.U] [W32/Mimail.E@mm] [I-Worm/Mimail.E]
df4d435f77d8cf561c76bd439f580c27[Win32/Mimail.A] [Win32.Mimail.A@mm] [Worm/W32.Mimail.26656] [W32.Mimail.A] [Worm.Mimail.Win32.12] [Win32.Mimail.A@mm] [I-Worm.Mimail.A] [W32/Mimail] [Win32/Mimail.A.unp] [Trojan.Dropper.JS.Mimail.B] [Win32.Mimail.A@mm] [Email-Worm.Win32.Mimail.a] [Trojan.Win32.Mimail.fwgf] [I-Worm.Win32.A.Mimail.26656.A[h]] [W32/Mimail-A] [Worm.Win32.Mimail.A.unp] [Win32.Mimail.A@mm] [Win32.HLLM.Foo] [BehavesLike.Win32.StartPage.mm] [W32/Mimail.LWBS-5616] [I-Worm/Mimail] [WORM/Mimail.A2] [Worm[Email]/Win32.Mimail] [Win32.Mimail.E90817] [Win32/Mimail.worm.26656.B] [Worm:Win32/Mimail.X@mm] [Win32.Mimail.A@mm] [I-Worm.Mimail.A] [Win32.Worm-email.Mimail.Wtnp] [Email-Worm.Win32.Mimail.U] [W32/Mimail.fam@mm] [I-Worm/Mimail.A] [Worm.Win32.A.unp]
b1ad7269b179113d43c7c7564dcf67e0[W32.Clod245.Trojan.7f77] [Win32/Mimail.I] [Win32.Mimail.TXV] [Win32.Mimail.TXV] [W32.Mimail.I] [Win32.Mimail.TXV] [Worm.Mimail.Win32.32] [Win32.Mimail.TXV] [W32/Mimail.I@mm] [W32.Mimail.I@mm] [Win32/Mimail.I] [WORM_MIMAIL.X] [Win.Worm.Mimail-19] [Email-Worm.Win32.Mimail.i] [Win32.Mimail.TXV] [Trojan.Win32.Mimail.endp] [W32.W.Mimail.l6Qz] [Win32.Worm-email.Mimail.Pepp] [Win32.Mimail.TXV] [Worm.Win32.Mimail.I] [Win32.Mimail.TXV] [Win32.HLLM.Foo] [WORM_MIMAIL.X] [BehavesLike.Win32.Dropper.lc] [W32/Mimail-Fam] [W32/Mimail.UJMG-5798] [I-Worm/Mimail.j(Paylap)] [WORM/Mimail.I1] [Worm[Email]/Win32.Mimail] [Worm:Win32/Mimail.I@mm] [I-Worm.Win32.Mimail.12832.B[h]] [Win32.Mimail.TXV] [Win32/Mimail.worm.12832.B] [Artemis!B1AD7269B179] [Worm.Mimail] [Worm.Win32.Mimail.i] [I-Worm.Mimail.I] [I-Worm.Mimail.I] [Email-Worm.Win32.Mimail.U] [W32/Mimail.fam@mm] [I-Worm/Mimail.I] [W32/Mimail.I.worm]

Whois

PropertyValue
NameDomain Manager
Organization Symantec Corporation
Email domains@symantec.com
Address 350 Ellis Street
Zip Code 94043
City Mountain View
State CA
Country US
Phone +1.6505278000
NameServer dns3.messagelabs.com
Created 1999-12-24 09:45:49
Changed 2014-05-29 20:19:04
Expires 2017-12-24 00:00:00
Registrar CSC CORPORATE DOMAIN

DNS Resolutions

DateIP Address
2025-04-0952.207.128.88 (ClassC)
2025-07-0454.243.60.31 (ClassC)
2025-07-3034.75.172.113 (ClassC)

Subdomains

DateDomainIP
dns1.messagelabs.com2025-07-3034.255.225.9
dns2.messagelabs.com2025-06-2318.184.36.165
clients.boundarydefense.geuw2.messagelabs.com2025-06-2335.244.174.211
dns3.messagelabs.com2025-06-1734.236.119.202
dns4.messagelabs.com2025-07-1154.203.46.81
dns5.messagelabs.com2025-07-1018.232.42.210
mail18.messagelabs.com2014-04-25117.120.20.147
mail19.messagelabs.com2025-05-3185.158.138.179
mail79.messagelabs.com2014-07-23195.245.230.147
cluster1.sa.messagelabs.com2013-12-02196.14.170.67
de.messagelabs.com2014-04-10216.156.249.138
api.messagelabs.com2025-07-1634.120.155.164
provisioningapi.messagelabs.com2025-07-0234.120.245.144
cluster2.gsi.messagelabs.com2014-06-1662.25.80.157
cluster.gsi.messagelabs.com2014-05-2385.158.143.19
cluster2.hk.messagelabs.com2013-04-18117.120.16.147
cluster1.uk.messagelabs.com2013-05-1685.158.140.115
cluster1a.uk.messagelabs.com2025-07-0946.137.95.199
cluster1.ap.messagelabs.com2014-06-16117.120.16.147
cluster2.ap.messagelabs.com2013-05-16117.120.20.147
images.messagelabs.com2025-06-2634.117.231.212
cluster1.us.messagelabs.com2014-03-24216.82.249.211
cluster2.us.messagelabs.com2014-06-05216.82.249.211
cluster14.us.messagelabs.com2014-03-24216.82.248.67
cluster4.us.messagelabs.com2014-03-24216.82.250.19
cluster15.us.messagelabs.com2014-03-24216.82.253.148
cluster5.us.messagelabs.com2014-03-24216.82.242.147
cluster6.us.messagelabs.com2014-03-24216.82.254.20
cluster8.us.messagelabs.com2014-03-24216.82.249.147
cluster9.us.messagelabs.com2014-03-24216.82.249.51
cluster4a.us.messagelabs.com2025-04-0952.207.128.88
cluster5a.us.messagelabs.com2014-06-18216.82.251.230
cluster6a.us.messagelabs.com2014-01-30216.82.251.230
cluster8a.us.messagelabs.com2014-01-3085.158.139.103
cluster1.eu.messagelabs.com2013-05-16193.109.254.67
cluster2.eu.messagelabs.com2014-05-22195.245.230.131
cluster13.eu.messagelabs.com2013-12-0285.158.139.194
cluster3.eu.messagelabs.com2014-06-1685.158.137.67
cluster4.eu.messagelabs.com2014-07-0885.158.143.35
cluster5.eu.messagelabs.com2014-03-24193.109.254.3
cluster7.eu.messagelabs.com2013-05-16195.245.230.147
cluster8.eu.messagelabs.com2013-05-1685.158.140.195
cluster9.eu.messagelabs.com2013-05-16193.109.254.147
cluster1a.eu.messagelabs.com2025-03-2834.253.63.114
cluster2a.eu.messagelabs.com2025-03-3034.253.63.114
cluster3a.eu.messagelabs.com2025-04-0734.253.63.114
cluster4a.eu.messagelabs.com2025-04-0334.253.63.114
cluster5a.eu.messagelabs.com2025-05-0834.253.63.114
cluster8a.eu.messagelabs.com2014-06-18216.82.251.230
cluster9a.eu.messagelabs.com2025-05-0834.253.63.114
cluster3vk.eu.messagelabs.com2013-12-1885.158.137.67
www.messagelabs.com2014-04-23209.8.115.126
View on OTX | View on ThreatMiner








Data with thanks to AlienVault OTX, VirusTotal, Malwr and others. [Sitemap]



� Copyright 2019 AlienVault, Inc. | Legal| Status| Do Not Sell My Personal Information