SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 72894e2a5890e7605e82efbd83eab693c31ae363.

Database Entry


SHA1 Fingerprint:72894e2a5890e7605e82efbd83eab693c31ae363
Certificate Common Name (CN):coreryfacorm.gg
Issuer Distinguished Name (DN):coreryfacorm.gg
TLS Version:TLS 1.2
First seen:2015-07-27 10:29:36 UTC
Last seen:2015-07-29 08:59:57 UTC
Status:Blacklisted
Listing reason:Dridex C&C
Listing date:2015-07-27 10:36:31
Malware samples:5
Botnet C&Cs:1

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2015-07-29 08:59:575be14022a092eec9855e28c2498f5adaVirustotal results 4/55 (7.27%) Dridex 93.171.132.5:743
2015-07-29 08:59:575be14022a092eec9855e28c2498f5adaVirustotal results 4/55 (7.27%) Dridex 93.171.132.5:743
2015-07-29 05:22:4927e7a76a691dc562b30da8d98014d686Virustotal results 23/56 (41.07%) Dridex 93.171.132.5:743
2015-07-29 05:22:4927e7a76a691dc562b30da8d98014d686Virustotal results 23/56 (41.07%) Dridex 93.171.132.5:743
2015-07-28 21:48:472c6c56287ea2bcedba7cd265650d37dbVirustotal results 2/55 (3.64%) Dridex 93.171.132.5:743
2015-07-28 21:48:472c6c56287ea2bcedba7cd265650d37dbVirustotal results 2/55 (3.64%) Dridex 93.171.132.5:743
2015-07-27 13:00:52ca6e11baa28b724e032326898d8a1a3cVirustotal results 2/55 (3.64%) Dridex 93.171.132.5:743
2015-07-27 13:00:52ca6e11baa28b724e032326898d8a1a3cVirustotal results 2/55 (3.64%) Dridex 93.171.132.5:743
2015-07-27 10:29:362cc139e1099dcc999084bae6f99b0fbaVirustotal results 1/54 (1.85%) Dridex 93.171.132.5:743
2015-07-27 10:29:362cc139e1099dcc999084bae6f99b0fbaVirustotal results 1/54 (1.85%) Dridex 93.171.132.5:743

# of entries: 10 (max: 100)