SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 259500493b3d962686644a9a0529b1c1a060cbcc.

Database Entry


SHA1 Fingerprint:259500493b3d962686644a9a0529b1c1a060cbcc
Certificate Common Name (CN):nexuslogger.com
Issuer Distinguished Name (DN):COMODO RSA Domain Validation Secure Server CA
TLS Version:TLSv1
First seen:2017-02-02 01:51:23 UTC
Last seen:2017-02-27 10:47:49 UTC
Status:Blacklisted
Listing reason:Nexuslogger C&C
Listing date:2017-02-27 10:53:26
Malware samples:12
Botnet C&Cs:1

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2017-02-27 10:47:496b9e08c6812cd0a84aab4a4f8c77cb33Virustotal results 11/58 (18.97%) Nexuslogger176.31.252.15:443
2017-02-27 10:47:496b9e08c6812cd0a84aab4a4f8c77cb33Virustotal results 11/58 (18.97%) Nexuslogger176.31.252.15:443
2017-02-25 03:25:36fa50c991346a74e40d71b7c4ef5bb352Virustotal results 9/59 (15.25%) Nexuslogger176.31.252.15:443
2017-02-25 03:25:36fa50c991346a74e40d71b7c4ef5bb352Virustotal results 9/59 (15.25%) Nexuslogger176.31.252.15:443
2017-02-24 16:29:514d82ae534cd3848579594544d04a4615Virustotal results 19/57 (33.33%) Nexuslogger176.31.252.15:443
2017-02-24 16:29:514d82ae534cd3848579594544d04a4615Virustotal results 19/57 (33.33%) Nexuslogger176.31.252.15:443
2017-02-19 21:03:52b1296422bd96b9572778fff07a7b9510Virustotal results 33/59 (55.93%) Nexuslogger176.31.252.15:443
2017-02-19 21:03:52b1296422bd96b9572778fff07a7b9510Virustotal results 33/59 (55.93%) Nexuslogger176.31.252.15:443
2017-02-18 09:05:393905118e4b1f128114169b10074e185fVirustotal results 27/58 (46.55%) Nexuslogger176.31.252.15:443
2017-02-18 09:05:393905118e4b1f128114169b10074e185fVirustotal results 27/58 (46.55%) Nexuslogger176.31.252.15:443
2017-02-17 11:50:00d0e71a44e8613fd96d30090c43aaa842Virustotal results 27/59 (45.76%) Nexuslogger176.31.252.15:443
2017-02-17 11:50:00d0e71a44e8613fd96d30090c43aaa842Virustotal results 27/59 (45.76%) Nexuslogger176.31.252.15:443
2017-02-14 11:54:187b32e5e9714f9a031fdae63843f06726Virustotal results 8/58 (13.79%) Downloader.Pony176.31.252.15:443
2017-02-14 11:54:187b32e5e9714f9a031fdae63843f06726Virustotal results 8/58 (13.79%) Downloader.Pony176.31.252.15:443
2017-02-08 18:39:5040b764870769e99a3a980b9b3a74ea7cVirustotal results 40/59 (67.80%) Nexuslogger176.31.252.15:443
2017-02-08 18:39:5040b764870769e99a3a980b9b3a74ea7cVirustotal results 40/59 (67.80%) Nexuslogger176.31.252.15:443
2017-02-05 11:43:332ffefcb9005c6b0352df400d292e5799Virustotal results 25/57 (43.86%) Nexuslogger176.31.252.15:443
2017-02-05 11:43:332ffefcb9005c6b0352df400d292e5799Virustotal results 25/57 (43.86%) Nexuslogger176.31.252.15:443
2017-02-04 03:33:58b42d67f74470cc92e470f27fe241b6e6Virustotal results 31/57 (54.39%) Nexuslogger176.31.252.15:443
2017-02-04 03:33:58b42d67f74470cc92e470f27fe241b6e6Virustotal results 31/57 (54.39%) Nexuslogger176.31.252.15:443
2017-02-03 15:53:56c50bf16c763dace748aef8994b5351d3Virustotal results 19/57 (33.33%) Nexuslogger176.31.252.15:443
2017-02-03 15:53:56c50bf16c763dace748aef8994b5351d3Virustotal results 19/57 (33.33%) Nexuslogger176.31.252.15:443
2017-02-02 01:51:2382d7a3521b091ebcb2afbca2f4e728daVirustotal results 11/57 (19.30%) Nexuslogger176.31.252.15:443
2017-02-02 01:51:2382d7a3521b091ebcb2afbca2f4e728daVirustotal results 11/57 (19.30%) Nexuslogger176.31.252.15:443

# of entries: 24 (max: 100)