SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 65058a2a003f61572cda9611797f596a2039e104.

Database Entry


SHA1 Fingerprint:65058a2a003f61572cda9611797f596a2039e104
Certificate Common Name (CN):www.carinsup.com/emailAddress=aa@a.cc
Issuer Distinguished Name (DN):www.carinsup.com/emailAddress=aa@a.cc
TLS Version:TLS 1.2
First seen:2015-02-18 19:39:56 UTC
Last seen:2015-08-15 09:13:45 UTC
Status:Blacklisted
Listing reason:KINS C&C
Listing date:2015-06-09 07:35:20
Malware samples:12
Botnet C&Cs:4

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2015-08-15 09:13:4523877e74b44452778b56855cdf83d9b9Virustotal results 20/57 (35.09%) Downloader.Upatre62.76.44.111:443
2015-08-13 08:38:22d241324f5ed8e0f03fd6d417a4127520n/a62.76.44.111:443
2015-07-27 16:59:541250c26a707f1abd60799658cd13d14dVirustotal results 22/55 (40.00%) 62.76.44.111:443
2015-07-13 10:49:282ada71fba3dc1fc9155c776b523b76b4Virustotal results 4/56 (7.14%) ZeuS 46.151.52.100:443
2015-06-09 05:39:35078fd45cdb00fbce73be5a89aaf534b9Virustotal results 25/57 (43.86%) ZeuS 62.76.179.123:443
2015-06-05 14:16:08f3bc4a38aed08afb39c2e79175b571fen/aZeuS 62.76.179.123:443
2015-05-28 14:46:232ee0edb0e06171821a3ecc129103b411Virustotal results 20/56 (35.71%) 62.76.44.111:443
2015-04-18 16:49:31c937b2afc55c736f7c62e4885cbe8e9cVirustotal results 7/56 (12.50%) ZeuS 62.76.179.123:443
2015-04-17 16:58:585ebe5fd9d3edd3243fd8ffe24cfb8d62Virustotal results 15/57 (26.32%) ZeuS 62.76.179.123:443
2015-04-16 10:46:19d0713dd24cd34a5b92237b47207c2b40Virustotal results 4/57 (7.02%) ZeuS 62.76.179.123:443
2015-04-04 23:08:04b9cd23b5375bd232b5b6ebcae946d6bbVirustotal results 32/56 (57.14%) ZeuS 62.76.179.123:443
2015-02-18 19:39:5639c0c63b6ed3d9b2c3a20d6e58ebf6d0Virustotal results 5/57 (8.77%) 37.228.92.188:443

# of entries: 12 (max: 100)