SSL Certificates
The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 2ef006ec84c0e6baac9abb9c585a97d4c43213f6.
Database Entry
SHA1 Fingerprint: | 2ef006ec84c0e6baac9abb9c585a97d4c43213f6 |
---|---|
Certificate Common Name (CN): | C=XX, L=Default City, O=Default Company Ltd |
Issuer Distinguished Name (DN): | C=XX, L=Default City, O=Default Company Ltd |
TLS Version: | TLS 1.2 |
First seen: | 2015-05-12 06:18:18 UTC |
Last seen: | 2015-05-16 09:52:32 UTC |
Status: | Blacklisted |
Listing reason: | Ransomware C&C |
Listing date: | 2015-08-12 15:28:43 |
Malware samples: | 11 |
Botnet C&Cs: | 1 |
Malware Samples
The table below documents all malware samples associated with this SSL certificate.
Timestamp (UTC) | Malware Sample (MD5 hash) | VT | Signature | Botnet C&C (IP:port) |
---|---|---|---|---|
2015-05-16 09:52:32 | 61e9cbc95b52c21ff8a0ebd435cd2aa5 | 36/57 (63.16%) | Ransomware | 185.91.175.94:443 |
2015-05-16 09:52:32 | 61e9cbc95b52c21ff8a0ebd435cd2aa5 | 36/57 (63.16%) | Ransomware | 185.91.175.94:443 |
2015-05-15 23:58:59 | e6782f6c699858006a8ed16a1803583a | 26/56 (46.43%) | Ransomware | 185.91.175.94:443 |
2015-05-15 23:58:59 | e6782f6c699858006a8ed16a1803583a | 26/56 (46.43%) | Ransomware | 185.91.175.94:443 |
2015-05-15 11:49:07 | 8a1736e5df2dde3e20a9e3967052eeb7 | 19/57 (33.33%) | Ransomware | 185.91.175.94:443 |
2015-05-15 11:49:07 | 8a1736e5df2dde3e20a9e3967052eeb7 | 19/57 (33.33%) | Ransomware | 185.91.175.94:443 |
2015-05-15 03:13:34 | c1ec0cc14bb508db0fb88ca8e3f4c67c | 36/57 (63.16%) | 185.91.175.94:443 | |
2015-05-15 03:13:34 | c1ec0cc14bb508db0fb88ca8e3f4c67c | 36/57 (63.16%) | 185.91.175.94:443 | |
2015-05-15 02:30:11 | d35c5b95c81edae197f521ff388d3d2e | 6/54 (11.11%) | 185.91.175.94:443 | |
2015-05-15 02:30:11 | d35c5b95c81edae197f521ff388d3d2e | 6/54 (11.11%) | 185.91.175.94:443 | |
2015-05-15 01:23:15 | d43df158fe66af2dc3dcfcc5da954700 | 8/56 (14.29%) | 185.91.175.94:443 | |
2015-05-15 01:23:15 | d43df158fe66af2dc3dcfcc5da954700 | 8/56 (14.29%) | 185.91.175.94:443 | |
2015-05-14 20:14:28 | 3dc75b0331b7562fbf26a739d6e86a30 | 28/57 (49.12%) | Ransomware | 185.91.175.94:443 |
2015-05-14 20:14:28 | 3dc75b0331b7562fbf26a739d6e86a30 | 28/57 (49.12%) | Ransomware | 185.91.175.94:443 |
2015-05-13 23:49:52 | 6977887f27836257a20b219c61428d8a | 27/57 (47.37%) | 185.91.175.94:443 | |
2015-05-13 23:49:52 | 6977887f27836257a20b219c61428d8a | 27/57 (47.37%) | 185.91.175.94:443 | |
2015-05-13 19:36:28 | 6c7ba1bbbdbd7506a95767500ddf38af | 29/48 (60.42%) | 185.91.175.94:443 | |
2015-05-13 19:36:28 | 6c7ba1bbbdbd7506a95767500ddf38af | 29/48 (60.42%) | 185.91.175.94:443 | |
2015-05-12 22:40:44 | 2ec795a7be28e60e24f763c6dd25f208 | 27/57 (47.37%) | 185.91.175.94:443 | |
2015-05-12 22:40:44 | 2ec795a7be28e60e24f763c6dd25f208 | 27/57 (47.37%) | 185.91.175.94:443 | |
2015-05-12 06:18:18 | a5c38513b07786833fda425213f7d467 | 8/57 (14.04%) | 185.91.175.94:443 | |
2015-05-12 06:18:18 | a5c38513b07786833fda425213f7d467 | 8/57 (14.04%) | 185.91.175.94:443 |
# of entries: 22 (max: 100)