SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 5e7c239541ada7230e39b6fc2e61b67ffde91007.

Database Entry


SHA1 Fingerprint:5e7c239541ada7230e39b6fc2e61b67ffde91007
Certificate Common Name (CN):idcythef.tj
Issuer Distinguished Name (DN):idcythef.tj
TLS Version:TLS 1.2
First seen:2015-08-11 08:34:12 UTC
Last seen:2015-08-12 13:31:34 UTC
Status:Blacklisted
Listing reason:Dridex C&C
Listing date:2015-08-11 08:43:08
Malware samples:5
Botnet C&Cs:2

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2015-08-12 13:31:3435646e6bb33303e35a685580222bdf78Virustotal results 23/57 (40.35%) Dridex 141.0.177.142:443
2015-08-12 08:25:01266d7ec1c68bcf695a954e1b5161e116Virustotal results 5/57 (8.77%) Dridex 94.23.110.45:443
2015-08-12 07:24:45583b987ab786b387518e755e11c04621Virustotal results 5/57 (8.77%) Dridex 94.23.110.45:443
2015-08-11 16:47:119b4611ae8cea3d0f7e155b95e49f669eVirustotal results 1/57 (1.75%) Dridex 94.23.110.45:443
2015-08-11 08:34:12f5a280d43b27a2a7256b319902773ed5Virustotal results 6/55 (10.91%) Dridex 94.23.110.45:443

# of entries: 5 (max: 100)