Help RSS API Feed Maltego Contact                        

Domain > mx2.emailsrvr.com

More information on this domain is in AlienVault OTX

Is this malicious?

Files that talk to mx2.emailsrvr.com

MD5A/V
803fdad60a108f80a0e664405cc2e176[HW32.CDB.37af] [Trojan.Packed.18626] [Heuristic.BehavesLike.Win32.ModifiedUPX.C] [Suspicious] [W32/Injector.ABXY!tr]
c7bf064346fafe4fc55b43abcfe96b00[HW32.CDB.E6f3] [Backdoor.Kelihos.r3] [Backdoor.Hlux!zUFIktBYK3s] [Kryptik.CCFN] [Backdoor.Win32.Hlux.djfw] [Trojan.Win32.S.PSW-Tepfer.835600.AM] [UnclassifiedMalware] [BackDoor.Slym.14049] [Mal/Kelihos-A] [Backdoor:Win32/Kelihos] [Trojan/Win32.Tepfer] [W32/Trojan.QQUO-1304] [Backdoor.Hlux] [Trojan.Crypt_s] [W32/Kryptik.BWUN!tr] [Crypt3.HUC] [Trojan.Win32.Kryptik.BZIX]
165f5084043893cc35334b568d0f6ec0[HW32.CDB.73df] [Packed.Win32.Katusha.3!O] [Win32.Malware!Drop] [Backdoor.Hlux!tc7SLh6zR0c] [WS.Reputation.1] [Kryptik.CCFN] [UnclassifiedMalware] [Backdoor:Win32/Kelihos] [Heur.Trojan.Hlux] [Win32/Kryptik.CBNK] [Backdoor.Win32.Kelihos] [W32/Kryptik.BD!tr] [Crypt_s.GPC] [Backdoor.Win32.Hlux.aBgj] [Win32/Trojan.337]
1be1d71fb76a46afa15fc4ee16ac1d11[HW32.CDB.39c9] [Backdoor.Hlux.r3] [RDN/q2z-art6.s_318383!a] [Kryptik.CCFN] [Backdoor.Win32.Hlux.dnzz] [Backdoor.Hlux!eaxFLDBT/AM] [Mal/FakeAV-UF] [BackDoor.Slym.13348] [Heuristic.LooksLike.Win32.Suspicious.E] [Trojan[Backdoor]/Win32.Hlux] [VirTool:Win32/Obfuscator.WT] [Trojan/Win32.Tepfer] [Heur.Trojan.Hlux] [Win32/Kryptik.CASL] [Trojan.Crypt_s] [W32/Hlux.BWUN!tr.bdr] [Trojan.Win32.Kryptik.CASL]
4ca7d150cc798011d5cb7d4c5be89f41[HW32.CDB.7b74] [Backdoor.Hlux.r3] [Trojan.Win32.Hlux.cxcisy] [Backdoor.Win32.Hlux.diqm] [Backdoor.Hlux!ISaeAq95IMk] [TrojWare.Win32.Kryptik.BLUU] [BackDoor.Slym.14044] [TR/Kryptik.oeons] [Mal/Kelihos-A] [Trojan[Backdoor]/Win32.Hlux] [Backdoor:Win32/Kelihos.F] [Trojan/Win32.Tepfer] [Heur.Trojan.Hlux] [Trojan.Crypt_s] [W32/Hlux.BWUN!tr.bdr] [Crypt_s.GGV] [Trojan.Win32.Kryptik.BZDO]
639dd203d5ceeee335bccca69d4e8050[HW32.CDB.9a0b] [Backdoor.Hlux.r3] [Kryptik.CCFN] [Backdoor.Win32.Hlux.djdi] [Backdoor.Hlux!dcOGw3a4azY] [Mal/Kelihos-A] [TrojWare.Win32.Kryptik.BZOO] [Trojan.DownLoad3.28912] [Trojan[Backdoor]/Win32.Hlux] [Backdoor:Win32/Kelihos] [Trojan/Win32.Tepfer] [Heur.Trojan.Hlux] [Trojan.Crypt_s] [W32/Hlux.BWUN!tr.bdr] [Crypt_s.GHF] [Trojan.Win32.Kryptik.BZIX]
981a83b3f0d4a74b0b38becda7c8cb9c[Artemis!981A83B3F0D4] [Trojan.Win32.Crypt.cxd] [W32/Yakes.FHJN!tr] [Win32/Cryptor]
61b408e2de1c4996c3708f1f46913d60[HW32.CDB.C1b5] [Trojan.Kryptik!QyFpAm9uzfY] [Kryptik.CCFN] [Backdoor.Win32.Hlux.djft] [Trojan.Win32.S.PSW-Tepfer.835600.AI] [UnclassifiedMalware] [BackDoor.Slym.14044] [Mal/Kelihos-A] [Trojan[Backdoor]/Win32.Hlux] [Trojan/Win32.Tepfer] [W32/Trojan.AJYO-7526] [Backdoor.Hlux] [Trojan.Crypt_s] [W32/Kryptik.BWUN!tr] [Crypt3.HUF] [Trojan.Win32.Kryptik.BZIX]
1a809031288d3e1ef3327e87dfefa861[HW32.CDB.042b] [Backdoor.Hlux.r3] [Trojan.Win32.Hlux.cxahyf] [Kryptik.CCFN] [Backdoor.Win32.Hlux.crc] [Backdoor.Hlux!jqpo62AJz0o] [TrojWare.Win32.Kryptik.BZOO] [BackDoor.Slym.13852] [Mal/Kelihos-A] [Trojan[Backdoor]/Win32.Hlux] [Trojan:Win32/Sisron] [W32/Trojan.HFOT-6937] [Trojan/Win32.Tepfer] [Heur.Trojan.Hlux] [Trojan.Win32.Kryptik.BZMB] [Trojan.Crypt_s] [W32/Hlux.BWUN!tr.bdr] [Crypt_s.GHF] [Win32/Trojan.337]
2e568dcb408ed49a98f0fca23d157f40[HW32.CDB.D876] [Heur.Win32.Veebee.1!O] [Worm.Vobfus.r4] [W32/Worm-AAEH.pf!2E568DCB408E] [Worm.Vobfus!d8HycLiwI7Y] [WS.Reputation.1] [Vobfus.QXEZ] [Trojan.Win32.Vobfus.cxbewb] [TrojWare.Win32.VB.ICOY] [Win32.HLLW.Autoruner2.11727] [Worm/Vobfus.erxc] [Mal/SillyFDC-AH] [Worm/Win32.Vobfus] [Worm.Vobfus.er.(kcloud)] [Worm:Win32/Vobfus.ZD] [TScope.Trojan.VB] [Trojan-Downloader.Win32.Beebone] [W32/Injector.VOX!tr] [Trojan.Win32.Injector.BBHU]
17124a0c3ffde1fd0de7168990278c06[HW32.CDB.439f] [Packed.Win32.Katusha.3!O] [WS.Reputation.1] [Kryptik.CDQY] [TrojWare.Win32.Kryptik.CBCJ] [BackDoor.Slym.13873] [Win32.Troj.Undef.(kcloud)] [Backdoor:Win32/Kelihos.F] [Trojan/Win32.Tepfer] [W32/Trojan.DNNY-5917] [Heur.Trojan.Hlux] [Trojan.Crypt_s] [Crypt_s.GNC] [Trojan.Win32.Kryptik.CBCJ]
45e45d9707887dc0cc0da495b7968acd[FakeSecTool-FCX!45E45D970788] [Malware.Packer.FFS] [BackDoor.SlymENT.2075] [Heuristic.LooksLike.Win32.Suspicious.E] [PE:Malware.XPACK/RDM!5.1]
86122dbf79ec3a983d9ecb120470a00f[Artemis!86122DBF79EC] [Trojan.Win32.Yakes.fhyw] [TR/Changeling.A.3509] [Win32.Trojan.Yakes.Dyfy] [Trojan.Win32.Spammer] [Win32/Cryptor] [Trojan.Win32.Spammer.bAC] [Win32/Trojan.Multi.daf]
d90bf83bd6aa6a9dce3505f7ab584977
853bc80df66ea885e7d4adf565401121[HW32.CDB.Bc28] [W32/Worm-AAEH.pq!853BC80DF66E] [Injector.GJTG] [Worm.Win32.VB.NG] [Win32.HLLW.Autoruner2.12544] [Worm/Vobfus.agcpv] [Mal/VB-ALW] [Worm:Win32/Vobfus.ZR] [PE:Malware.XPACK-HIE/Heur!1.9C48] [Worm.Win32.Vobfus] [Inject2.ABEP] [Trojan.Win32.Injector.BCCY] [Win32/Trojan.afe]
20837cfed9fcc3df5a3e414c18eff646[Packed.Win32.Katusha.3!O] [WS.Reputation.1] [Kryptik.CDQY] [TrojWare.Win32.Kryptik.CBCJ] [BackDoor.Slym.13873] [Win32.Troj.Undef.(kcloud)] [Backdoor:Win32/Kelihos.F] [Trojan/Win32.Tepfer] [Heur.Trojan.Hlux] [Trojan.Crypt_s] [Crypt_s.GNC] [Trojan.Win32.Kryptik.CBCJ]
8aed502427321fd9f331b8a1abb0514c

Whois

PropertyValue
NameDomain Admin
Organization Rackspace US, Inc.
Email domains@rackspace.com
Address 1 Fanatical Place
Zip Code 78218
City San Antonio
State TX
Country US
Phone +1.2103124630
Fax +1.2103124848
NameServer pdns2.ultradns.net
Created 2003-01-14 02:45:11
Changed 2015-02-19 18:46:56
Expires 2017-01-14 00:00:00
Registrar CSC CORPORATE DOMAIN

DNS Resolutions

DateIP Address
2013-09-22173.203.2.32 (ClassC)
2017-05-1950.87.144.68 (ClassC)
2024-07-16184.106.54.2 (ClassC)
2025-04-20108.166.43.2 (ClassC)
2025-07-15173.203.187.2 (ClassC)
2025-08-10146.20.161.2 (ClassC)

Subdomains

DateDomainIP
mx1.emailsrvr.com2014-03-2498.129.184.131
mx2.emailsrvr.com2013-09-22173.203.2.32
ord1a.emailsrvr.com2025-06-29173.203.2.19
iad3a.emailsrvr.com2025-07-06204.232.170.252
mex07a.emailsrvr.com2025-08-0267.192.133.244
static.emailsrvr.com2024-11-19152.195.19.97
secure.emailsrvr.com2025-04-29184.106.54.10
mail.emailsrvr.com2013-09-12207.97.245.100
webmail.emailsrvr.com2013-09-02207.97.245.100
cdn.emailsrvr.com2014-09-2496.17.111.115
smtp.emailsrvr.com2025-06-11184.106.54.11
mx1.exp.emailsrvr.com2014-06-29173.203.2.40
autodiscover.emailsrvr.com2025-06-26161.47.143.37
images.emailsrvr.com2025-08-02162.209.121.71
connect.emailsrvr.com2025-08-09184.106.31.88
www.emailsrvr.com2025-08-0274.205.6.223
View on OTX | View on ThreatMiner








Data with thanks to AlienVault OTX, VirusTotal, Malwr and others. [Sitemap]



� Copyright 2019 AlienVault, Inc. | Legal| Status| Do Not Sell My Personal Information