SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 5eb43e37e17b5c6c856b33fdde78177d7b8a0442.

Database Entry


SHA1 Fingerprint:5eb43e37e17b5c6c856b33fdde78177d7b8a0442
Certificate Common Name (CN):gucdhwpcfjmmcefypliv.com
Issuer Distinguished Name (DN):R3
TLS Version:TLSv1
First seen:2021-08-09 03:37:03 UTC
Last seen:2021-08-09 08:35:09 UTC
Status:Blacklisted
Listing reason:ZLoader C&C
Listing date:2021-08-09 04:43:01
Malware samples:5
Botnet C&Cs:1

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2021-08-09 08:35:090b8b4d1854add7dfc1a27b1e93fb002bVirustotal results 2 / 58 (3.45%) 5.63.154.248:443
2021-08-09 08:35:090b8b4d1854add7dfc1a27b1e93fb002bVirustotal results 2 / 58 (3.45%) 5.63.154.248:443
2021-08-09 08:33:20bdc0145a839b8cc3be24f07f18e196b5n/a5.63.154.248:443
2021-08-09 08:33:20bdc0145a839b8cc3be24f07f18e196b5n/a5.63.154.248:443
2021-08-09 08:32:41e1897e464b353e4b33f5974626c745caVirustotal results 8 / 59 (13.56%) 5.63.154.248:443
2021-08-09 08:32:41e1897e464b353e4b33f5974626c745caVirustotal results 8 / 59 (13.56%) 5.63.154.248:443
2021-08-09 08:32:170d7e37a6f4a468e95f360fd2a14973fan/a5.63.154.248:443
2021-08-09 08:32:170d7e37a6f4a468e95f360fd2a14973fan/a5.63.154.248:443
2021-08-09 03:37:033740851312af7f75741d950015901cb7n/aZLoader 5.63.154.248:443
2021-08-09 03:37:033740851312af7f75741d950015901cb7n/aZLoader 5.63.154.248:443

# of entries: 10 (max: 100)