SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 37f5caec6916965a7f9c2a4d2622334ae5f14c3a.

Database Entry


SHA1 Fingerprint:37f5caec6916965a7f9c2a4d2622334ae5f14c3a
Certificate Common Name (CN):fleil42.com
Issuer Distinguished Name (DN):RapidSSL SHA256 CA
TLS Version:TLS 1.2
First seen:2016-12-01 17:56:28 UTC
Last seen:2016-12-13 18:34:31 UTC
Status:Blacklisted
Listing reason:Chthonic C&C
Listing date:2016-12-07 10:19:50
Malware samples:21
Botnet C&Cs:4

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2016-12-13 18:34:3163ed7edf5294f33def7e250bd318cb55n/aChthonic 54.213.4.206:443
2016-12-10 14:21:0667bf9b2b9e964f747fbe8d3eca38ae59Virustotal results 24/57 (42.11%) Chthonic 192.3.21.24:443
2016-12-10 06:43:358a85af32a9a608132f3548d00da10948n/aChthonic 192.3.21.24:443
2016-12-08 19:08:17e062b2f969db35ff4ff6c721a656d60an/a192.3.21.24:443
2016-12-08 17:33:24c3cc3c33b1a6753640de041f47c1077dn/aChthonic 192.3.21.24:443
2016-12-07 06:42:38670f0e0d8cb0c43dd8bfb604589c62f2Virustotal results 35/68 (51.47%) Chthonic 172.245.62.117:443
2016-12-06 19:12:54d3f6515457dddc975204350f160d649cn/aChthonic 172.245.62.117:443
2016-12-06 02:20:06fa495110b05f2bb572e46214a681e3f3n/a154.16.245.154:443
2016-12-05 21:41:05650e335ef21b1430ca2ed6c539eb0b63Virustotal results 12/56 (21.43%) 172.245.62.117:443
2016-12-04 10:41:375546838ee6af00841f2ed24713c4a00dn/aChthonic 154.16.245.154:443
2016-12-04 09:57:42a7c3f95141cc0ec318d554ab9481650fVirustotal results 6/56 (10.71%) 154.16.245.154:443
2016-12-03 16:15:54109b687b902a9c25b3e4f9e91ef89792Virustotal results 28/55 (50.91%) Chthonic 154.16.245.154:443
2016-12-03 03:43:085257bd4c7504838fb883cf3113a58359Virustotal results 35/58 (60.34%) Chthonic 154.16.245.154:443
2016-12-02 13:13:581a8c0b47d5a6ff119b9ebc021701c10cVirustotal results 35/56 (62.50%) Chthonic 172.245.62.117:443
2016-12-02 07:21:24ec659e04903dd521eb3c406fc9045d01n/aChthonic 172.245.62.117:443
2016-12-02 03:59:1550ede75eb74a0a795500cc7b8c6c9f54Virustotal results 24/57 (42.11%) Chthonic 154.16.245.154:443
2016-12-02 02:16:58e630535de5b3b0124b46567cb2b6283fn/aChthonic 172.245.62.117:443
2016-12-02 00:57:22c3ebe869bf1b41b9133069c310716c24n/aChthonic 154.16.245.154:443
2016-12-01 22:46:417cd9d4b8bf32b5c39cb0bbb742dd58b8Virustotal results 18/59 (30.51%) 172.245.62.117:443
2016-12-01 18:21:443a9d58853a38ad9b6cc5595d825cf0b4n/aChthonic 172.245.62.117:443
2016-12-01 17:56:283ef6a158bc6bcf31c387ed2db7ec2474n/aChthonic 172.245.62.117:443

# of entries: 21 (max: 100)