SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 2b083b952d9a7a22d11578cdd6ad37a496ea2a06.

Database Entry


SHA1 Fingerprint:2b083b952d9a7a22d11578cdd6ad37a496ea2a06
Certificate Common Name (CN):example.com
Issuer Distinguished Name (DN):example.com
TLS Version:TLS 1.2
First seen:2017-12-09 16:34:26 UTC
Last seen:2018-02-03 19:42:43 UTC
Status:Blacklisted
Listing reason:TrickBot C&C
Listing date:2017-12-10 18:17:11
Malware samples:2
Botnet C&Cs:1

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2018-02-03 19:42:43a06c6db03537e98e1036085eb5aaa734Virustotal results 39/68 (57.35%) TrickBot 109.120.155.23:443
2018-02-03 19:42:43a06c6db03537e98e1036085eb5aaa734Virustotal results 39/68 (57.35%) TrickBot 109.120.155.23:443
2018-02-03 19:42:43a06c6db03537e98e1036085eb5aaa734Virustotal results 39/68 (57.35%) TrickBot 109.120.155.23:443
2018-02-03 19:42:43a06c6db03537e98e1036085eb5aaa734Virustotal results 39/68 (57.35%) TrickBot 109.120.155.23:443
2017-12-09 16:34:2600a24069186c0079fe6d8a8554ab1e29Virustotal results 50/67 (74.63%) TrickBot 109.120.155.23:443
2017-12-09 16:34:2600a24069186c0079fe6d8a8554ab1e29Virustotal results 50/67 (74.63%) TrickBot 109.120.155.23:443
2017-12-09 16:34:2600a24069186c0079fe6d8a8554ab1e29Virustotal results 50/67 (74.63%) TrickBot 109.120.155.23:443
2017-12-09 16:34:2600a24069186c0079fe6d8a8554ab1e29Virustotal results 50/67 (74.63%) TrickBot 109.120.155.23:443

# of entries: 8 (max: 100)