Help RSS API Feed Maltego Contact                        

Domain > mx2.pattersoncompanies.com.gslb.pphosted.com

More information on this domain is in AlienVault OTX

Is this malicious?

Files that talk to mx2.pattersoncompanies.com.gslb.pphosted.com

MD5A/V
75147b8dd7796762a48bd315293f0817[FakeSecTool-FCI!75147B8DD779] [Malware.Packer.FFS] [Heuristic.LooksLike.Win32.Suspicious.E] [W32/Kryptik.BDPK!tr] [Crypt_s.EPS]
8835f7fb6071ec49aaac1e7a87231c81[HW32.CDB.56ce] [Backdoor.Hlux.r3] [Backdoor.Hlux!1YBsnlQ+0io] [Kryptik.CCFN] [Backdoor.Win32.Hlux.dllz] [Trojan.Win32.Kryptik.cxcjig] [Trojan.Packed.26544] [Heuristic.LooksLike.Win32.Suspicious.E] [Trojan[Backdoor]/Win32.Hlux] [Backdoor:Win32/Kelihos] [Trojan/Win32.Tepfer] [Heur.Trojan.Hlux] [Trojan.Crypt_s] [W32/Kryptik.BWUN!tr] [Trojan.Win32.Kryptik.CASU] [Win32/Trojan.337]
2db060643b02ebffce2e3957e0b47311[Packed.Win32.Katusha.3!O] [Backdoor.Hlux!w7qQeHPCTX8] [WS.Reputation.1] [Kryptik.CCFN] [Backdoor.Win32.Hlux.dsut] [BackDoor.Slym.13011] [Trojan[Backdoor]/Win32.Hlux] [VirTool:Win32/Obfuscator.WT] [Heur.Trojan.Hlux] [Win32/Kryptik.CBNK] [Trojan.Crypt_s] [W32/Kryptik.DJH!tr] [Crypt_s.GNC] [Backdoor.Win32.Hlux.ABwI] [Win32/Trojan.337]
56b02dc8b8072c1f787058a56eae64f0[HW32.CDB.9b1c] [Backdoor.Hlux.r3] [Trojan.Win32.Hlux.cwhrmp] [Kryptik.CCFN] [Backdoor.Win32.Hlux.djkd] [Mal/Kelihos-A] [TrojWare.Win32.Kryptik.BZOO] [Trojan.DownLoad3.28912] [Trojan[Backdoor]/Win32.Hlux] [Backdoor:Win32/Kelihos] [Trojan/Win32.Tepfer] [Heur.Trojan.Hlux] [Trojan.Crypt_s] [W32/Hlux.BWUN!tr.bdr] [Crypt_s.GHE] [Trojan.Win32.Kryptik.BZIX] [Win32/Trojan.ef7]
24a034d09222c5370365c4cdadde0f65[HW32.CDB.Da0d] [Packed.Win32.Katusha.3!O] [Kryptik.CDQY] [TrojWare.Win32.Kryptik.CBCJ] [Trojan.Packed.26581] [Backdoor:Win32/Kelihos.F] [Trojan/Win32.Tepfer] [Heur.Trojan.Hlux] [Trojan.Crypt_s] [W32/Kryptik.BD!tr] [Crypt_s.GNC] [Trojan.Win32.Kryptik.CBCJ] [Win32/Trojan.0de]
292ad75fbab2288a453c7f7db162eed0[HW32.CDB.A2b5] [Packed.Win32.Katusha.3!O] [Backdoor.Hlux!xuwpKhCjMA8] [WS.Reputation.1] [Kryptik.CDQY] [Backdoor.Win32.Hlux.dqzg] [UnclassifiedMalware] [Trojan.Packed.26581] [Trojan[Backdoor]/Win32.Hlux] [Backdoor:Win32/Kelihos] [W32/Trojan.HATR-5126] [Heur.Trojan.Hlux] [Trojan.Crypt_s] [W32/Kryptik.BWUN!tr] [Crypt_s.GNC] [Backdoor.Win32.Hlux.Aj] [Win32/Trojan.112]

Whois

PropertyValue
Email dns@proofpoint.com
NameServer NS3.PROOFPOINT.COM
Created 2007-07-11 00:00:00
Changed 2014-05-19 00:00:00
Expires 2016-07-11 00:00:00
Registrar MARKMONITOR INC.

DNS Resolutions

DateIP Address
2014-07-0467.231.152.14 (ClassC)
2025-08-0767.231.144.14 (ClassC)

Subdomains

DateDomainIP
mx1.power-one.com.gslb.pphosted.com2013-11-0667.231.144.8
mx1.ttifloorcare.com.gslb.pphosted.com2014-04-2567.231.152.64
mx1.cityholding.com.gslb.pphosted.com2025-07-0267.231.144.39
mx1.dealertrack.com.gslb.pphosted.com2014-03-2467.231.144.69
mx1.oceanbank.com.gslb.pphosted.com2014-04-2567.231.144.74
mx2.efirstbank.com.gslb.pphosted.com2013-12-0267.231.144.11
mx1.subzero.com.gslb.pphosted.com2014-05-3067.231.152.75
mx1.clickbooq.com.gslb.pphosted.com2014-07-0167.231.144.19
mx1.pattersoncompanies.com.gslb.pphosted.com2014-05-2967.231.144.14
mx2.pattersoncompanies.com.gslb.pphosted.com2014-07-0467.231.152.14
mx1.bobstores.com.gslb.pphosted.com2014-04-2567.231.152.54
mx1.saintfrancis.com.gslb.pphosted.com2013-04-1867.231.144.67
mx1.kslresorts.com.gslb.pphosted.com2013-05-1667.231.144.84
mx2.genfast.com.gslb.pphosted.com2014-05-3067.231.152.3
mx1.teleflex.com.gslb.pphosted.com2013-12-0467.231.144.29
mx1.tjx.com.gslb.pphosted.com2013-04-1867.231.152.22
mx1.la-z-boy.com.gslb.pphosted.com2013-11-1167.231.152.55
View on OTX | View on ThreatMiner








Data with thanks to AlienVault OTX, VirusTotal, Malwr and others. [Sitemap]



� Copyright 2019 AlienVault, Inc. | Legal| Status| Do Not Sell My Personal Information