SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 1757dd0125ca88a59c56b4ea84422187e8e42ea6.

Database Entry


SHA1 Fingerprint:1757dd0125ca88a59c56b4ea84422187e8e42ea6
Certificate Common Name (CN):001.ocentral.qua.one
Issuer Distinguished Name (DN):Let's Encrypt Authority X3
TLS Version:TLS 1.2
First seen:2020-02-12 15:44:51 UTC
Last seen:2020-03-23 08:49:00 UTC
Status:Blacklisted
Listing reason:Adwind C&C
Listing date:2020-02-14 18:48:36
Malware samples:26
Botnet C&Cs:1

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2020-03-23 08:49:00a77c2d9529ea209bd803857fbd84b378n/aAdwind167.172.164.197:8443
2020-03-20 13:17:266dca12a98805ac8df3efe5e572bbd72an/aAdwind167.172.164.197:8443
2020-03-11 01:41:454f1fd0e308880bdd53a3aad68a2a2810n/aAdwind167.172.164.197:8443
2020-03-10 17:25:12c9e0b7811bc7b7e6163599302c556cf9n/aAdwind167.172.164.197:8443
2020-03-10 13:01:551d4ee1aea2a949a490b28c28d3f1cb62n/aAdwind167.172.164.197:8443
2020-03-05 17:33:001d648fe099ecae126e7516669d21d86bn/aAdwind167.172.164.197:8443
2020-03-05 15:44:23b675b131618453e0cc536ed984684ef9n/aAdwind167.172.164.197:8443
2020-03-05 12:53:200b68f7e36b93056deb5a0a459ad21948n/aAdwind167.172.164.197:8443
2020-03-04 10:37:42e19f1b36fb699c990bac0e519935de8dVirustotal results 1 / 63 (1.59%) Adwind167.172.164.197:8443
2020-03-03 14:05:1019f2d043e745a453337d0b07eb53fae8n/aAdwind167.172.164.197:8443
2020-03-03 12:37:57fe2320f6cf0971e206d78f8963bb2baen/aAdwind167.172.164.197:8443
2020-03-02 21:01:4946d988a1fb3433ce8192577469c59857Virustotal results 19 / 61 (31.15%) Adwind167.172.164.197:8443
2020-03-02 20:30:154cbce2c071b358c730da2715943c6e1fn/aAdwind167.172.164.197:8443
2020-02-27 19:14:41bb65b5ebd4d1c62038b0547bf37d7021Virustotal results 2 / 63 (3.17%) Adwind167.172.164.197:8443
2020-02-26 02:18:12645a6d7846874d077a5e7e07ef8434c5Virustotal results 18 / 63 (28.57%) Adwind167.172.164.197:8443
2020-02-26 01:46:56f90cca9869678fc9a45c54459d9e4094n/aAdwind167.172.164.197:8443
2020-02-25 18:45:49054defb52ebddca533c485b89c6d60d8n/aAdwind167.172.164.197:8443
2020-02-25 17:48:001e5c33bfa80c4e4760b01d3567326382n/aAdwind167.172.164.197:8443
2020-02-24 02:26:045966ca638f314795d4e9543e186c8cc4Virustotal results 18 / 63 (28.57%) Adwind167.172.164.197:8443
2020-02-18 10:30:43c7a583745df676615eb1b7cab158d397n/aAdwind167.172.164.197:8443
2020-02-18 08:39:25b594f7cc96b977010fb31f93219c70bdn/aAdwind167.172.164.197:8443
2020-02-18 06:03:056701ef120ea71faeb5d3d32b866f0b48n/aAdwind167.172.164.197:8443
2020-02-14 18:15:46261b4ea9f7301d15aa80cf91c86afcefn/aAdwind167.172.164.197:8443
2020-02-12 18:38:054023e075e0ab8aa32f528fb40c270e90n/a167.172.164.197:8443
2020-02-12 17:49:384c0d7e2de8dc8b96fb686debb117688en/a167.172.164.197:8443
2020-02-12 15:44:51b6640bfe0d6945de414e0a6f7fed6627n/aAdwind167.172.164.197:8443

# of entries: 26 (max: 100)