SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 28197c7350d68c4df8fbf83629bf3304b6a89f4a.

Database Entry


SHA1 Fingerprint:28197c7350d68c4df8fbf83629bf3304b6a89f4a
Certificate Common Name (CN):changeaie.top
Issuer Distinguished Name (DN):WE1
TLS Version:TLS 1.2
First seen:2025-04-11 22:27:48 UTC
Last seen:2025-04-12 18:09:37 UTC
Status:Blacklisted
Listing reason:LummaStealer C&C
Listing date:2025-04-13 07:23:25
Malware samples:9
Botnet C&Cs:2

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2025-04-12 18:09:37e21e5a8ba80a27be580a386a52b64d15n/a104.21.42.7:443
2025-04-12 09:18:1127de841dac910cd5fa8b31e25e9179f2n/a104.21.42.7:443
2025-04-12 08:12:27e130f55133c41e91984ba551d9316d28n/a104.21.42.7:443
2025-04-12 07:33:04fac9214c35af0181c30099c68920f445n/a172.67.197.226:443
2025-04-12 00:27:065797842a42f0c81ce380267f9dd5ab2dn/a172.67.197.226:443
2025-04-12 00:24:100dbff254abf29f1adbf7f446ec4f3877n/a172.67.197.226:443
2025-04-12 00:16:21ea61922dae2d227f2a8541d653801603n/a172.67.197.226:443
2025-04-12 00:05:304f75c135ffac3afcd7de2e4a2b81d5afn/a172.67.197.226:443
2025-04-11 22:27:481d1a07ffb3d17680e6ab26cbdc0945d3n/a172.67.197.226:443

# of entries: 9 (max: 100)