SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 413820202525ec6122adb587a215a9ddd2ef86f0.

Database Entry


SHA1 Fingerprint:413820202525ec6122adb587a215a9ddd2ef86f0
Certificate Common Name (CN):dothetheont.lb
Issuer Distinguished Name (DN):dothetheont.lb
TLS Version:TLS 1.2
First seen:2016-01-06 12:53:08 UTC
Last seen:2016-01-07 12:09:15 UTC
Status:Blacklisted
Listing reason:Dridex C&C
Listing date:2016-01-06 12:56:45
Malware samples:2
Botnet C&Cs:1

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2016-01-07 12:09:15088724715613ff48edf090a74c8b6413Virustotal results 3/54 (5.56%) Dridex 78.47.119.93:666
2016-01-07 12:09:15088724715613ff48edf090a74c8b6413Virustotal results 3/54 (5.56%) Dridex 78.47.119.93:666
2016-01-06 12:53:08fdd95b4cc10b536934486c7d3fdee04fVirustotal results 5/55 (9.09%) Dridex 78.47.119.93:666
2016-01-06 12:53:08fdd95b4cc10b536934486c7d3fdee04fVirustotal results 5/55 (9.09%) Dridex 78.47.119.93:666

# of entries: 4 (max: 100)