SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 4a5171cf80f8d9950be32fe3dd220a92a3116fa6.

Database Entry


SHA1 Fingerprint:4a5171cf80f8d9950be32fe3dd220a92a3116fa6
Certificate Common Name (CN):0Sotivecershi.citic
Issuer Distinguished Name (DN):0Sotivecershi.citic
TLS Version:TLS 1.2' NOTBEF
First seen:2018-11-24 00:44:20 UTC
Last seen:2018-12-10 15:40:42 UTC
Status:Blacklisted
Listing reason:Dridex C&C
Listing date:2018-12-08 09:45:32
Malware samples:4
Botnet C&Cs:1

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2018-12-10 15:40:420c26b2cc52b429a8472574fa20b80dd1Virustotal results 46/70 (65.71%) Dridex 185.158.251.55:443
2018-12-10 15:40:420c26b2cc52b429a8472574fa20b80dd1Virustotal results 46/70 (65.71%) Dridex 185.158.251.55:443
2018-12-03 18:05:21be4733da4ced8716cb092a60291242d5Virustotal results 39/70 (55.71%) Dridex 185.158.251.55:443
2018-12-03 18:05:21be4733da4ced8716cb092a60291242d5Virustotal results 39/70 (55.71%) Dridex 185.158.251.55:443
2018-11-27 16:09:566fda62c46c49b83bd11aeabbd3a32904n/aGozi 185.158.251.55:443
2018-11-27 16:09:566fda62c46c49b83bd11aeabbd3a32904n/aGozi 185.158.251.55:443
2018-11-24 00:44:200f707a19a9d0f8c1072b7449b206caa6Virustotal results 38/69 (55.07%) Dridex 185.158.251.55:443
2018-11-24 00:44:200f707a19a9d0f8c1072b7449b206caa6Virustotal results 38/69 (55.07%) Dridex 185.158.251.55:443

# of entries: 8 (max: 100)