SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 34a92e41d4cf61f1fc510e40afd362d2ddc00ff7.

Database Entry


SHA1 Fingerprint:34a92e41d4cf61f1fc510e40afd362d2ddc00ff7
Certificate Common Name (CN):kuklovodw.com/emailAddress=admin@kuklovodw.com
Issuer Distinguished Name (DN):kuklovodw.com/emailAddress=admin@kuklovodw.com
TLS Version:TLS 1.2
First seen:2016-01-22 06:11:44 UTC
Last seen:2016-01-26 02:07:32 UTC
Status:Blacklisted
Listing reason:Qadars C&C
Listing date:2016-01-22 10:54:02
Malware samples:14
Botnet C&Cs:4

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2016-01-26 02:07:32534eada82992d9c0d5c9d224841f6dd2Virustotal results 4/54 (7.41%) Qadars 192.210.137.123:443
2016-01-26 02:07:32534eada82992d9c0d5c9d224841f6dd2Virustotal results 4/54 (7.41%) Qadars 192.210.137.123:443
2016-01-25 08:07:30b39775be63bd9af7daf72e6c0a636969Virustotal results 4/54 (7.41%) Qadars 192.210.137.123:443
2016-01-25 08:07:30b39775be63bd9af7daf72e6c0a636969Virustotal results 4/54 (7.41%) Qadars 192.210.137.123:443
2016-01-24 19:37:1195daac9c9356a019c4a6fff507fb2389n/aQadars 107.161.145.175:443
2016-01-24 19:37:1195daac9c9356a019c4a6fff507fb2389n/aQadars 107.161.145.175:443
2016-01-24 15:54:18475a4b295f28c432f68bc7b541d3b7ebVirustotal results 12/54 (22.22%) Qadars 216.170.126.138:443
2016-01-24 15:54:18475a4b295f28c432f68bc7b541d3b7ebVirustotal results 12/54 (22.22%) Qadars 216.170.126.138:443
2016-01-24 11:03:41a844f64f80d4374c7030ebd2ccf79f7cVirustotal results 5/55 (9.09%) Qadars 216.170.126.138:443
2016-01-24 11:03:41a844f64f80d4374c7030ebd2ccf79f7cVirustotal results 5/55 (9.09%) Qadars 216.170.126.138:443
2016-01-23 23:49:319f299d0ade1b22a8bfc906bf283f12faVirustotal results 34/58 (58.62%) Qadars 216.170.126.138:443
2016-01-23 23:49:319f299d0ade1b22a8bfc906bf283f12faVirustotal results 34/58 (58.62%) Qadars 216.170.126.138:443
2016-01-23 23:10:0260acb407e3a5dfbaa5bd4b33b79d92baVirustotal results 2/55 (3.64%) Qadars 107.161.145.175:443
2016-01-23 23:10:0260acb407e3a5dfbaa5bd4b33b79d92baVirustotal results 2/55 (3.64%) Qadars 107.161.145.175:443
2016-01-23 11:38:471c40e655e972caa2adef94be3e433d6bVirustotal results 4/54 (7.41%) Qadars 107.161.145.175:443
2016-01-23 11:38:471c40e655e972caa2adef94be3e433d6bVirustotal results 4/54 (7.41%) Qadars 107.161.145.175:443
2016-01-23 08:00:555af260f1c35cc6d81fb9825962af62dfVirustotal results 6/55 (10.91%) Qadars 107.161.145.175:443
2016-01-23 08:00:555af260f1c35cc6d81fb9825962af62dfVirustotal results 6/55 (10.91%) Qadars 107.161.145.175:443
2016-01-22 16:09:26bcb405b821ccf6a6be399c6f63651695n/aQadars 185.25.116.98:443
2016-01-22 16:09:26bcb405b821ccf6a6be399c6f63651695n/aQadars 185.25.116.98:443
2016-01-22 12:57:58c5e39a02790f3af1596a10345912778fn/aQadars 216.170.126.138:443
2016-01-22 12:57:58c5e39a02790f3af1596a10345912778fn/aQadars 216.170.126.138:443
2016-01-22 10:03:059fe67f9cd145d1d7eb2d931804c7ba55Virustotal results 34/54 (62.96%) Qadars 185.25.116.98:443
2016-01-22 10:03:059fe67f9cd145d1d7eb2d931804c7ba55Virustotal results 34/54 (62.96%) Qadars 185.25.116.98:443
2016-01-22 08:16:37e73e1ca84ac1e897300b084645020adcVirustotal results 36/55 (65.45%) Qadars 216.170.126.138:443
2016-01-22 08:16:37e73e1ca84ac1e897300b084645020adcVirustotal results 36/55 (65.45%) Qadars 216.170.126.138:443
2016-01-22 06:11:4453123d79b3e1a33bfde42bb884781fefVirustotal results 3/55 (5.45%) Qadars 185.25.116.98:443
2016-01-22 06:11:4453123d79b3e1a33bfde42bb884781fefVirustotal results 3/55 (5.45%) Qadars 185.25.116.98:443

# of entries: 28 (max: 100)