SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 336c3ccda369bf0c6e498622e43d9a6f2e9cf76f.

Database Entry


SHA1 Fingerprint:336c3ccda369bf0c6e498622e43d9a6f2e9cf76f
Certificate Common Name (CN):we'd.info
Issuer Distinguished Name (DN):we'd.info
TLS Version:TLS 1.2
First seen:2019-04-22 13:08:59 UTC
Last seen:2019-05-13 14:21:15 UTC
Status:Blacklisted
Listing reason:IcedID C&C
Listing date:2019-04-24 12:04:15
Malware samples:27
Botnet C&Cs:5

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2019-05-13 14:21:150e0f20bf0b8dcfee3805b123b8bab75bVirustotal results 27/69 (39.13%) IcedID 195.69.187.86:443
2019-05-03 03:41:502834d0c6467c5b5439dbc0678e45dc97Virustotal results 15/73 (20.55%) IcedID 178.57.218.162:443
2019-05-03 01:00:087c097bdbd3cf3a61edb78c8786f15e69n/aIcedID 178.57.218.162:443
2019-05-02 18:16:51ea16e1b9a8e9c9e524c35b70b5a058e0Virustotal results 16/72 (22.22%) IcedID 178.57.218.162:443
2019-05-01 16:40:46cb19b23dec75383bd8c345a159ea135en/aIcedID 185.74.255.161:443
2019-05-01 15:13:03f263e6c84cc6e6ae2de1b6c3359c5b72n/aIcedID 185.74.255.161:443
2019-05-01 11:04:28cee7c0a3393f938027e802fba8ce2d79n/aIcedID 185.74.255.161:443
2019-05-01 10:20:52fe36321853f8b2327e06dd6975f75136n/aIcedID 185.74.255.161:443
2019-05-01 10:07:12a4a7057c1cf14cd0a17ec58b6f364142n/aIcedID 185.74.255.161:443
2019-04-30 23:15:0374fbf14a5ad1b1e6491d2be7bc51852bVirustotal results 15/70 (21.43%) 185.74.255.161:443
2019-04-30 14:27:516b5e3227684b5da5e2a947152dff9d7bn/aIcedID 185.74.255.161:443
2019-04-26 07:52:3693f8e537beb30f074b94da9e335786d7Virustotal results 35/71 (49.30%) IcedID 185.66.9.114:443
2019-04-26 04:54:05ebe68efd925eba3d6dbfee954009d18aVirustotal results 33/66 (50.00%) IcedID 185.66.9.114:443
2019-04-26 04:44:24e993c6e1f6f9c6b6e895a30afb40157aVirustotal results 28/71 (39.44%) IcedID 185.66.9.114:443
2019-04-26 04:00:4922765f78ac88e523064b74297eb33e82n/aIcedID 185.66.9.114:443
2019-04-25 14:43:1466ae5ca97f8061c2d211e4c9fc6e1f52n/aIcedID 185.66.9.114:443
2019-04-25 05:43:2472692d2870f052f08b8794c67ff250c4n/aIcedID 185.66.9.114:443
2019-04-25 04:17:164d95eef062945033e49416cf6c35998bVirustotal results 23/66 (34.85%) 185.66.9.114:443
2019-04-25 00:59:36be5bd77b1ea44c74dc7b0addf4c1f781n/a185.66.9.114:443
2019-04-24 23:45:478b834e75b2434f61cf99600cf10c2d68Virustotal results 29/65 (44.62%) IcedID 185.66.9.114:443
2019-04-24 15:29:41e9908f7905896b0716e58a7fd39cbfa0n/aIcedID 185.66.9.114:443
2019-04-24 14:23:39e83394f689e4d95d930b4da1e4b47b7aVirustotal results 32/71 (45.07%) IcedID 185.66.9.114:443
2019-04-24 06:24:117e13eeabfa002d9790f5eb52e4410816n/a77.222.60.127:443
2019-04-24 04:39:09cd613e4d2cdf676ad530431b55428908Virustotal results 24/66 (36.36%) 77.222.60.127:443
2019-04-24 02:53:506bead983685bb86f3ffdbae040156ddbVirustotal results 25/67 (37.31%) 77.222.60.127:443
2019-04-22 13:52:56823766c2b57604a25a46f4f7b2198c4bVirustotal results 14/71 (19.72%) 77.222.60.127:443
2019-04-22 13:08:59d8d901a1b0e0f909cd2ddeb0302fff67Virustotal results 30/68 (44.12%) IcedID 77.222.60.127:443

# of entries: 27 (max: 100)