SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 7750df982f35fa4285de8c7ec831e11334e87067.

Database Entry


SHA1 Fingerprint:7750df982f35fa4285de8c7ec831e11334e87067
Certificate Common Name (CN):pornhub.xxx
Issuer Distinguished Name (DN):pornhub.xxx
TLS Version:SSLv3
First seen:2015-05-22 22:42:02 UTC
Last seen:2015-05-30 10:05:54 UTC
Status:Blacklisted
Listing reason:Dridex C&C
Listing date:2015-06-07 18:07:07
Malware samples:4
Botnet C&Cs:1

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2015-05-30 10:05:5483887d4c5e54353e23bc9e9b529212f8Virustotal results 41/55 (74.55%) Dridex 91.215.138.108:443
2015-05-30 10:05:5483887d4c5e54353e23bc9e9b529212f8Virustotal results 41/55 (74.55%) Dridex 91.215.138.108:443
2015-05-23 07:54:024d877072fd81b5b18c2c585f5a58a56eVirustotal results 1/57 (1.75%) Dridex 91.215.138.108:443
2015-05-23 07:54:024d877072fd81b5b18c2c585f5a58a56eVirustotal results 1/57 (1.75%) Dridex 91.215.138.108:443
2015-05-23 07:01:409c6398de0101e6b3811cf35de6fc7b79Virustotal results 17/57 (29.82%) 91.215.138.108:443
2015-05-23 07:01:409c6398de0101e6b3811cf35de6fc7b79Virustotal results 17/57 (29.82%) 91.215.138.108:443
2015-05-22 22:42:02600e5df303765ff73dccff1c3e37c03aVirustotal results 18/56 (32.14%) Andromeda91.215.138.108:443
2015-05-22 22:42:02600e5df303765ff73dccff1c3e37c03aVirustotal results 18/56 (32.14%) Andromeda91.215.138.108:443

# of entries: 8 (max: 100)