SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 68f0a2ef0a7eadc2e055203327309ba7abdb8b61.

Database Entry


SHA1 Fingerprint:68f0a2ef0a7eadc2e055203327309ba7abdb8b61
Certificate Common Name (CN):trtheawa.ml
Issuer Distinguished Name (DN):trtheawa.ml
TLS Version:TLS 1.2
First seen:2015-08-01 14:16:22 UTC
Last seen:2015-09-03 15:45:20 UTC
Status:Blacklisted
Listing reason:Dridex C&C
Listing date:2015-08-01 14:39:40
Malware samples:7
Botnet C&Cs:1

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2015-09-03 15:45:200864bc6951795b86d435176c3320a8bcVirustotal results 3/55 (5.45%) Dridex 95.163.121.252:443
2015-08-07 07:23:13da575b916f419b9e8bfea12168fa9902Virustotal results 5/55 (9.09%) 95.163.121.252:443
2015-08-05 08:27:298f3063ef8032799f71507b8f88f8a1c5Virustotal results 3/55 (5.45%) Dridex 95.163.121.252:443
2015-08-04 12:58:4938bc5f2b0e9028069e2a5034556ea385Virustotal results 2/54 (3.70%) Dridex 95.163.121.252:443
2015-08-04 12:03:15f3a17cb9919d6d5e92af37f0a3f71575Virustotal results 2/55 (3.64%) Dridex 95.163.121.252:443
2015-08-03 12:28:55939ee3b203b79f6422ef4a96fde11393Virustotal results 2/55 (3.64%) Dridex 95.163.121.252:443
2015-08-01 14:16:229ed6c45d678adf825482af399ee48a39Virustotal results 3/55 (5.45%) Dridex 95.163.121.252:443

# of entries: 7 (max: 100)