SSL Certificates
The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 193df87aa01c362b4dd26f0cdb9ca3b1958eb965.
Database Entry
SHA1 Fingerprint: | 193df87aa01c362b4dd26f0cdb9ca3b1958eb965 |
---|---|
Certificate Common Name (CN): | utomoiavisubl.kn |
Issuer Distinguished Name (DN): | utomoiavisubl.kn |
TLS Version: | TLS 1.2 |
First seen: | 2016-01-21 11:09:49 UTC |
Last seen: | 2016-01-27 00:22:09 UTC |
Status: | Blacklisted |
Listing reason: | Dridex C&C |
Listing date: | 2016-01-21 11:27:37 |
Malware samples: | 2 |
Botnet C&Cs: | 2 |
Malware Samples
The table below documents all malware samples associated with this SSL certificate.
Timestamp (UTC) | Malware Sample (MD5 hash) | VT | Signature | Botnet C&C (IP:port) |
---|---|---|---|---|
2016-01-27 00:22:09 | 91d1699a1e3a904a0a1ba80dc9862cc5 | 22/54 (40.74%) | Dridex | 117.239.192.228:443 |
2016-01-27 00:22:09 | 91d1699a1e3a904a0a1ba80dc9862cc5 | 22/54 (40.74%) | Dridex | 117.239.192.228:443 |
2016-01-21 11:09:49 | e6f67b358009f66f1a4840c1eff19c2e | 4/53 (7.55%) | Dridex | 198.154.62.28:444 |
2016-01-21 11:09:49 | e6f67b358009f66f1a4840c1eff19c2e | 4/53 (7.55%) | Dridex | 198.154.62.28:444 |
# of entries: 4 (max: 100)