SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 6fb23d09fa946b5fef1090f952702933414547f9.

Database Entry


SHA1 Fingerprint:6fb23d09fa946b5fef1090f952702933414547f9
Certificate Common Name (CN):lorgyline.com/emailAddress=mail@lorgyline.com
Issuer Distinguished Name (DN):lorgyline.com/emailAddress=mail@lorgyline.com
TLS Version:TLSv1
First seen:2015-08-06 09:27:12 UTC
Last seen:2015-09-08 13:30:12 UTC
Status:Blacklisted
Listing reason:Qadars C&C
Listing date:2015-08-16 08:52:05
Malware samples:23
Botnet C&Cs:1

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2015-09-08 13:30:120a17e16be1d02761bd18b7fe3318c0dbVirustotal results 6/57 (10.53%) 188.138.71.67:443
2015-09-08 13:30:120a17e16be1d02761bd18b7fe3318c0dbVirustotal results 6/57 (10.53%) 188.138.71.67:443
2015-08-31 09:06:180625e9be2e772ff8f1088f6fe41bf106Virustotal results 25/48 (52.08%) Qadars 188.138.71.67:443
2015-08-31 09:06:180625e9be2e772ff8f1088f6fe41bf106Virustotal results 25/48 (52.08%) Qadars 188.138.71.67:443
2015-08-16 04:07:038b80583e77ec6a864fe3e3b6b0cbe1bcVirustotal results 4/57 (7.02%) Qadars 188.138.71.67:443
2015-08-16 04:07:038b80583e77ec6a864fe3e3b6b0cbe1bcVirustotal results 4/57 (7.02%) Qadars 188.138.71.67:443
2015-08-16 00:03:4700fda881ad6ad86182e513cc1a805458Virustotal results 25/57 (43.86%) Qadars 188.138.71.67:443
2015-08-16 00:03:4700fda881ad6ad86182e513cc1a805458Virustotal results 25/57 (43.86%) Qadars 188.138.71.67:443
2015-08-15 10:08:57e737757d4c5dc68e3afe0a9c6ee4ab16Virustotal results 5/55 (9.09%) 188.138.71.67:443
2015-08-15 10:08:57e737757d4c5dc68e3afe0a9c6ee4ab16Virustotal results 5/55 (9.09%) 188.138.71.67:443
2015-08-14 17:29:1577ee846932d0ec4e9fef1e2bd48e2ebfVirustotal results 6/57 (10.53%) 188.138.71.67:443
2015-08-14 17:29:1577ee846932d0ec4e9fef1e2bd48e2ebfVirustotal results 6/57 (10.53%) 188.138.71.67:443
2015-08-13 21:46:51a0170e4ef11fdec393d3c0048d818ad6Virustotal results 3/57 (5.26%) 188.138.71.67:443
2015-08-13 21:46:51a0170e4ef11fdec393d3c0048d818ad6Virustotal results 3/57 (5.26%) 188.138.71.67:443
2015-08-13 08:50:10d530619aaebd621c3110508e22d9da95Virustotal results 2/56 (3.57%) 188.138.71.67:443
2015-08-13 08:50:10d530619aaebd621c3110508e22d9da95Virustotal results 2/56 (3.57%) 188.138.71.67:443
2015-08-13 08:14:29c86c51c0aa0afdf6f29d4589189c005cVirustotal results 4/57 (7.02%) 188.138.71.67:443
2015-08-13 08:14:29c86c51c0aa0afdf6f29d4589189c005cVirustotal results 4/57 (7.02%) 188.138.71.67:443
2015-08-13 07:19:01b4b5da3689755868e3bf8ebf770d2a35Virustotal results 24/57 (42.11%) 188.138.71.67:443
2015-08-13 07:19:01b4b5da3689755868e3bf8ebf770d2a35Virustotal results 24/57 (42.11%) 188.138.71.67:443
2015-08-12 20:33:228d7fe3cf5a2e801ae6e507c45e8c2da4Virustotal results 7/57 (12.28%) 188.138.71.67:443
2015-08-12 20:33:228d7fe3cf5a2e801ae6e507c45e8c2da4Virustotal results 7/57 (12.28%) 188.138.71.67:443
2015-08-12 19:10:03b500dd3e55ad6fc5b0d0f192b4dd3fe0Virustotal results 1/56 (1.79%) 188.138.71.67:443
2015-08-12 19:10:03b500dd3e55ad6fc5b0d0f192b4dd3fe0Virustotal results 1/56 (1.79%) 188.138.71.67:443
2015-08-11 09:54:47723ecb85f030d7ec970d01673a64b66bVirustotal results 18/55 (32.73%) Qadars 188.138.71.67:443
2015-08-11 09:54:47723ecb85f030d7ec970d01673a64b66bVirustotal results 18/55 (32.73%) Qadars 188.138.71.67:443
2015-08-11 02:58:16a9e0381ea134f5c6a92dd69ea4a84a6dVirustotal results 4/56 (7.14%) Qadars 188.138.71.67:443
2015-08-11 02:58:16a9e0381ea134f5c6a92dd69ea4a84a6dVirustotal results 4/56 (7.14%) Qadars 188.138.71.67:443
2015-08-11 02:26:2493f0b945351959be368204c46d34efe5Virustotal results 5/56 (8.93%) 188.138.71.67:443
2015-08-11 02:26:2493f0b945351959be368204c46d34efe5Virustotal results 5/56 (8.93%) 188.138.71.67:443
2015-08-10 21:36:494aa6425f2e3a5077ddf83a921135c839Virustotal results 5/56 (8.93%) 188.138.71.67:443
2015-08-10 21:36:494aa6425f2e3a5077ddf83a921135c839Virustotal results 5/56 (8.93%) 188.138.71.67:443
2015-08-10 21:07:382257fe651e4debe1bc082b02902f03e8Virustotal results 2/56 (3.57%) 188.138.71.67:443
2015-08-10 21:07:382257fe651e4debe1bc082b02902f03e8Virustotal results 2/56 (3.57%) 188.138.71.67:443
2015-08-08 22:19:11bbc20e1c0e357df682064b87550bcb14Virustotal results 5/56 (8.93%) Qadars 188.138.71.67:443
2015-08-08 22:19:11bbc20e1c0e357df682064b87550bcb14Virustotal results 5/56 (8.93%) Qadars 188.138.71.67:443
2015-08-08 10:38:054b02d2c4b2f04014949c19ea791bbf8fVirustotal results 6/56 (10.71%) Qadars 188.138.71.67:443
2015-08-08 10:38:054b02d2c4b2f04014949c19ea791bbf8fVirustotal results 6/56 (10.71%) Qadars 188.138.71.67:443
2015-08-08 00:23:075652bef60740739aa6c208e7f23d850cVirustotal results 8/56 (14.29%) Qadars 188.138.71.67:443
2015-08-08 00:23:075652bef60740739aa6c208e7f23d850cVirustotal results 8/56 (14.29%) Qadars 188.138.71.67:443
2015-08-07 20:32:187188eaaba7e1eeeabfa72efeff3d3530Virustotal results 0/55 (0.00%) Qadars 188.138.71.67:443
2015-08-07 20:32:187188eaaba7e1eeeabfa72efeff3d3530Virustotal results 0/55 (0.00%) Qadars 188.138.71.67:443
2015-08-07 13:42:402a7c1fa131c819846609af498052aff9Virustotal results 25/55 (45.45%) Qadars 188.138.71.67:443
2015-08-07 13:42:402a7c1fa131c819846609af498052aff9Virustotal results 25/55 (45.45%) Qadars 188.138.71.67:443
2015-08-06 09:27:12cfc1b831425d126d91362486a43fe663Virustotal results 5/56 (8.93%) Qadars 188.138.71.67:443
2015-08-06 09:27:12cfc1b831425d126d91362486a43fe663Virustotal results 5/56 (8.93%) Qadars 188.138.71.67:443

# of entries: 46 (max: 100)