SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 599f2aa0faa861d0ba6f6a742d198389eee49be9.

Database Entry


SHA1 Fingerprint:599f2aa0faa861d0ba6f6a742d198389eee49be9
Certificate Common Name (CN):cegu.shop
Issuer Distinguished Name (DN):R10
TLS Version:TLS 1.2
First seen:2024-12-26 15:49:14 UTC
Last seen:2025-01-03 20:59:42 UTC
Status:Blacklisted
Listing reason:LummaStealer C&C
Listing date:2025-01-04 14:17:27
Malware samples:14
Botnet C&Cs:1

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2025-01-03 20:59:4225f8c962f3ae839691debd96148bf3e1n/a185.161.251.21:443
2025-01-03 04:11:1779972f296cb418a20b17d2440850d790n/a185.161.251.21:443
2025-01-02 11:36:45e51e2f42b1171def63a9baa11bc55c64n/a185.161.251.21:443
2025-01-02 00:32:0466f0ce2dedf4f639c6d0c356728087a9n/a185.161.251.21:443
2025-01-01 18:54:2244512d17e8d71a3aeec8da8cdf680b03n/a185.161.251.21:443
2024-12-30 19:42:04b106a3a66916985d5e5b6cbbb6c5b07cn/a185.161.251.21:443
2024-12-30 18:24:472f30fcf726e3fcdcbdaec184de4eef49n/a185.161.251.21:443
2024-12-29 15:43:13c6f709a40a7d35051ee49ad1e367df65n/a185.161.251.21:443
2024-12-29 02:55:089fed7135d164c0fb31b859fcd5acfe5fn/a185.161.251.21:443
2024-12-27 19:28:140981c44a10cc0831ff1223aa55383192n/a185.161.251.21:443
2024-12-27 09:25:107c498eca1b725e8a85fef298184ccbb9n/a185.161.251.21:443
2024-12-26 22:14:48704c5b384f7c80fcd6f683f48ac447b1n/a185.161.251.21:443
2024-12-26 21:14:296022ea9ea0fc4e40342cf0a31e35b6f3n/a185.161.251.21:443
2024-12-26 15:49:1451409c968880d1422635af1355423e7an/a185.161.251.21:443

# of entries: 14 (max: 100)