SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 55d72e3e7c4450b2f1356dced3be706cb48864d0.

Database Entry


SHA1 Fingerprint:55d72e3e7c4450b2f1356dced3be706cb48864d0
Certificate Common Name (CN):Orcus Server
Issuer Distinguished Name (DN):Orcus Server
TLS Version:TLSv1
First seen:2019-04-12 23:37:18 UTC
Last seen:2019-04-14 20:58:39 UTC
Status:Blacklisted
Listing reason:OrcusRAT C&C
Listing date:2019-04-13 07:27:11
Malware samples:3
Botnet C&Cs:1

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2019-04-14 20:58:39a16d9087a50e10a8a5e54f622006f2efVirustotal results 44/72 (61.11%) Adwind185.136.168.134:10134
2019-04-14 20:58:39a16d9087a50e10a8a5e54f622006f2efVirustotal results 44/72 (61.11%) Adwind185.136.168.134:10134
2019-04-13 01:50:3257d3b5ec4c5c8b4fc35c1ba3a3ff814bVirustotal results 36/67 (53.73%) OrcusRAT 185.136.168.134:10134
2019-04-13 01:50:3257d3b5ec4c5c8b4fc35c1ba3a3ff814bVirustotal results 36/67 (53.73%) OrcusRAT 185.136.168.134:10134
2019-04-12 23:37:18b1bd74768f5777f3f0ed42536fe6d691Virustotal results 35/67 (52.24%) OrcusRAT 185.136.168.134:10134
2019-04-12 23:37:18b1bd74768f5777f3f0ed42536fe6d691Virustotal results 35/67 (52.24%) OrcusRAT 185.136.168.134:10134

# of entries: 6 (max: 100)