SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 34f06057eea1ba0ecd0734fb7890e5b54b3f89dc.

Database Entry


SHA1 Fingerprint:34f06057eea1ba0ecd0734fb7890e5b54b3f89dc
Certificate Common Name (CN):John/emailAddress=John_Alaska@gmail.com
Issuer Distinguished Name (DN):John/emailAddress=John_Alaska@gmail.com
TLS Version:TLSv1
First seen:2017-09-12 08:12:32 UTC
Last seen:2018-11-29 15:47:57 UTC
Status:Blacklisted
Listing reason:TrickBot C&C
Listing date:2017-09-15 18:19:37
Malware samples:34
Botnet C&Cs:17

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2018-11-29 15:47:5795653261dc0f78fb68903898f7380ee0Virustotal results 33/68 (48.53%) Trickbot 194.5.250.162:443
2018-11-29 15:47:5795653261dc0f78fb68903898f7380ee0Virustotal results 33/68 (48.53%) Trickbot 194.5.250.162:443
2018-10-10 15:34:37d61ca02b30b949fcc13e1876304a66a4Virustotal results 9/68 (13.24%) Dyre198.46.207.107:443
2018-05-20 16:36:342537fdf1cb5a4d463b1d0b4383ce414aVirustotal results 33/65 (50.77%) TrickBot 185.249.255.172:443
2018-05-20 16:36:342537fdf1cb5a4d463b1d0b4383ce414aVirustotal results 33/65 (50.77%) TrickBot 185.249.255.172:443
2018-05-01 15:22:36622c851a810ac57fb6d0da4d79778f2aVirustotal results 24/67 (35.82%) TrickBot 185.249.255.172:443
2018-05-01 15:22:36622c851a810ac57fb6d0da4d79778f2aVirustotal results 24/67 (35.82%) TrickBot 185.249.255.172:443
2018-04-06 16:44:39a2266baca1e5c71209f6c957af18e3f4Virustotal results 11/67 (16.42%) TrickBot 109.234.35.230:443
2018-04-06 16:44:39a2266baca1e5c71209f6c957af18e3f4Virustotal results 11/67 (16.42%) TrickBot 109.234.35.230:443
2018-03-17 07:51:526b157c2d658c9c23fb337403f211b99aVirustotal results 31/65 (47.69%) TrickBot 185.180.197.58:443
2018-03-17 07:51:526b157c2d658c9c23fb337403f211b99aVirustotal results 31/65 (47.69%) TrickBot 185.180.197.58:443
2018-03-12 20:33:5178deb917d8e1b381428c2ff210576cabVirustotal results 35/67 (52.24%) Trickbot 46.249.62.206:443
2018-03-12 20:33:5178deb917d8e1b381428c2ff210576cabVirustotal results 35/67 (52.24%) Trickbot 46.249.62.206:443
2018-02-22 11:58:22a4958c779945d274d39becca24a58d72Virustotal results 8/68 (11.76%) TrickBot 195.133.144.185:443
2018-02-22 11:58:22a4958c779945d274d39becca24a58d72Virustotal results 8/68 (11.76%) TrickBot 195.133.144.185:443
2018-02-21 08:22:56f70f3e91e3dcdbb9bfe5c58b38a81ab2Virustotal results 36/68 (52.94%) Smoke Loader 195.133.144.185:443
2018-02-21 05:31:09f1bfb63e2067bb3c64dfd73307ab029dVirustotal results 8/36 (22.22%) TrickBot 195.133.144.185:443
2018-02-21 05:31:09f1bfb63e2067bb3c64dfd73307ab029dVirustotal results 8/36 (22.22%) TrickBot 195.133.144.185:443
2018-02-20 00:07:36941a240325932cfc6d382f271ee013fbVirustotal results 33/66 (50.00%) TrickBot 195.133.144.185:443
2018-02-20 00:07:36941a240325932cfc6d382f271ee013fbVirustotal results 33/66 (50.00%) TrickBot 195.133.144.185:443
2018-02-19 19:54:4215f1da09971bd03f997d5d5db2e3a23eVirustotal results 42/68 (61.76%) Smoke Loader 195.133.144.185:443
2018-02-19 19:29:283431cb8e677d1882ad64a15aaf6c6910Virustotal results 37/65 (56.92%) Smoke Loader 195.133.144.185:443
2018-02-01 07:37:01bf425050bd30221979dcb16e8efc2ca3Virustotal results 26/66 (39.39%) TrickBot 194.87.92.147:443
2018-02-01 07:37:01bf425050bd30221979dcb16e8efc2ca3Virustotal results 26/66 (39.39%) TrickBot 194.87.92.147:443
2018-01-31 14:17:16081348f5f3997ef87aff831998b0bb41Virustotal results 43/66 (65.15%) AZORult 92.53.77.125:443
2018-01-17 15:29:004f0f587f62a5bf772f3e71cdbb5dd52dVirustotal results 38/67 (56.72%) TrickBot 194.87.92.147:443
2018-01-17 15:29:004f0f587f62a5bf772f3e71cdbb5dd52dVirustotal results 38/67 (56.72%) TrickBot 194.87.92.147:443
2018-01-16 23:52:48733c780755f81beafce799495e0a1709Virustotal results 36/68 (52.94%) TrickBot 194.87.92.147:443
2018-01-16 23:52:48733c780755f81beafce799495e0a1709Virustotal results 36/68 (52.94%) TrickBot 194.87.92.147:443
2018-01-16 22:05:057461bd0e3482f7f6b295d74ad6c25660Virustotal results 37/68 (54.41%) TrickBot 194.87.92.147:443
2018-01-16 22:05:057461bd0e3482f7f6b295d74ad6c25660Virustotal results 37/68 (54.41%) TrickBot 194.87.92.147:443
2018-01-16 20:22:336fc346ca78e3a9fabf332eeaa92953deVirustotal results 42/68 (61.76%) TrickBot 194.87.92.147:443
2018-01-16 20:22:336fc346ca78e3a9fabf332eeaa92953deVirustotal results 42/68 (61.76%) TrickBot 194.87.92.147:443
2018-01-16 13:27:1105b67b1e9d3d03401e456c1de02dc475Virustotal results 41/66 (62.12%) TrickBot 194.87.92.147:443
2018-01-16 13:27:1105b67b1e9d3d03401e456c1de02dc475Virustotal results 41/66 (62.12%) TrickBot 194.87.92.147:443
2018-01-15 19:59:522c52e2654eb8e5aabcd0c680606c6497Virustotal results 30/67 (44.78%) Tofsee 194.87.92.147:443
2018-01-15 14:23:418cf69033e2b95442e3b18943411ee4a2Virustotal results 15/68 (22.06%) TrickBot 194.87.92.147:443
2018-01-15 14:23:418cf69033e2b95442e3b18943411ee4a2Virustotal results 15/68 (22.06%) TrickBot 194.87.92.147:443
2018-01-15 13:18:42884fdecd196f00a1db08da7aaac98aa1Virustotal results 13/68 (19.12%) TrickBot 194.87.92.147:443
2018-01-15 13:18:42884fdecd196f00a1db08da7aaac98aa1Virustotal results 13/68 (19.12%) TrickBot 194.87.92.147:443
2017-11-27 01:23:346ba7b201e098601063f39e5b57738556Virustotal results 42/68 (61.76%) TrickBot 91.92.128.45:443
2017-11-27 01:23:346ba7b201e098601063f39e5b57738556Virustotal results 42/68 (61.76%) TrickBot 91.92.128.45:443
2017-11-05 10:55:302db23db86a941cff88ca42a49a2e3b01Virustotal results 26/68 (38.24%) TrickBot 179.43.147.235:443
2017-11-05 10:55:302db23db86a941cff88ca42a49a2e3b01Virustotal results 26/68 (38.24%) TrickBot 179.43.147.235:443
2017-10-21 08:28:374f226d3219fa3989d2fcd6cb67dba6d4Virustotal results 33/64 (51.56%) TrickBot 185.80.128.27:443
2017-10-21 08:28:374f226d3219fa3989d2fcd6cb67dba6d4Virustotal results 33/64 (51.56%) TrickBot 185.80.128.27:443
2017-10-07 07:59:1802426f5fc90196044ba109643bde9b2bVirustotal results 17/66 (25.76%) TrickBot 185.158.115.61:443
2017-10-07 07:59:1802426f5fc90196044ba109643bde9b2bVirustotal results 17/66 (25.76%) TrickBot 185.158.115.61:443
2017-09-23 17:41:1998996f53bc6574c7a0015aa89d7de912Virustotal results 35/65 (53.85%) TrickBot 185.158.115.61:443
2017-09-23 17:41:1998996f53bc6574c7a0015aa89d7de912Virustotal results 35/65 (53.85%) TrickBot 185.158.115.61:443
2017-09-21 02:32:337e389a770b1e50dd3d5f96509b95fa1eVirustotal results 34/65 (52.31%) TrickBot 107.189.162.131:443
2017-09-21 02:32:337e389a770b1e50dd3d5f96509b95fa1eVirustotal results 34/65 (52.31%) TrickBot 107.189.162.131:443
2017-09-15 18:11:43db4e0c14f002676be5648b729e61480bVirustotal results 28/65 (43.08%) TrickBot 185.80.128.230:443
2017-09-15 18:11:43db4e0c14f002676be5648b729e61480bVirustotal results 28/65 (43.08%) TrickBot 185.80.128.230:443
2017-09-12 08:12:3291a04150c0c3c5a276e97b30b25c337cVirustotal results 16/65 (24.62%) TrickBot 185.80.128.230:443
2017-09-12 08:12:3291a04150c0c3c5a276e97b30b25c337cVirustotal results 16/65 (24.62%) TrickBot 185.80.128.230:443
2017-08-22 15:04:1275d0f86ef8956bf9f496e40db0c95b8aVirustotal results 11/64 (17.19%) TrickBot 93.123.73.16:443
2017-08-22 15:04:1275d0f86ef8956bf9f496e40db0c95b8aVirustotal results 11/64 (17.19%) TrickBot 93.123.73.16:443
2017-08-22 15:04:1275d0f86ef8956bf9f496e40db0c95b8aVirustotal results 11/64 (17.19%) TrickBot 93.123.73.16:443
2017-08-22 15:04:1275d0f86ef8956bf9f496e40db0c95b8aVirustotal results 11/64 (17.19%) TrickBot 93.123.73.16:443
2017-08-15 22:54:35e02238c1e0a5cc66cbbbf77c42ee5139Virustotal results 9/64 (14.06%) TrickBot 93.123.73.16:443
2017-08-15 22:54:35e02238c1e0a5cc66cbbbf77c42ee5139Virustotal results 9/64 (14.06%) TrickBot 93.123.73.16:443
2017-08-15 22:54:35e02238c1e0a5cc66cbbbf77c42ee5139Virustotal results 9/64 (14.06%) TrickBot 93.123.73.16:443
2017-08-15 22:54:35e02238c1e0a5cc66cbbbf77c42ee5139Virustotal results 9/64 (14.06%) TrickBot 93.123.73.16:443
2017-08-10 13:08:36b271c5cacf0828c86b3fa0309066b21aVirustotal results 15/64 (23.44%) TrickBot 64.15.75.83:443
2017-08-10 13:08:36b271c5cacf0828c86b3fa0309066b21aVirustotal results 15/64 (23.44%) TrickBot 64.15.75.83:443
2017-08-10 13:08:36b271c5cacf0828c86b3fa0309066b21aVirustotal results 15/64 (23.44%) TrickBot 64.15.75.83:443
2017-08-10 13:08:36b271c5cacf0828c86b3fa0309066b21aVirustotal results 15/64 (23.44%) TrickBot 64.15.75.83:443

# of entries: 68 (max: 100)