SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 7dea4f9356c8470ff95cc850af22090474f9deeb.

Database Entry


SHA1 Fingerprint:7dea4f9356c8470ff95cc850af22090474f9deeb
Certificate Common Name (CN):vatvavers.re
Issuer Distinguished Name (DN):vatvavers.re
TLS Version:TLSv1
First seen:2015-11-07 17:44:58 UTC
Last seen:2015-11-23 16:54:24 UTC
Status:Blacklisted
Listing reason:Dridex C&C
Listing date:2015-11-07 20:43:04
Malware samples:10
Botnet C&Cs:1

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2015-11-23 16:54:245173d1be2f44e2346678f8249379bb84Virustotal results 5/53 (9.43%) Dridex 89.108.71.148:8843
2015-11-23 13:29:337e6cfd542440e913e661a94f6a711ab4Virustotal results 3/55 (5.45%) Dridex 89.108.71.148:8843
2015-11-21 19:24:257a5317ddc26c5e53db1886241fa12f72Virustotal results 17/50 (34.00%) Dridex 89.108.71.148:8843
2015-11-19 03:12:5832faf9bf0fcdd67a6caf47c843dafd82Virustotal results 27/55 (49.09%) Dridex 89.108.71.148:8843
2015-11-12 20:12:52dc30d2ef4c5f58b8a4b93eaeda71f323Virustotal results 1/54 (1.85%) Dridex 89.108.71.148:8843
2015-11-12 14:27:05f4460df1798e6fd64996694642454f7bVirustotal results 3/54 (5.56%) Dridex 89.108.71.148:8843
2015-11-12 05:24:5449a0b46bcf6a99f7e20d1bdde54c604fVirustotal results 20/56 (35.71%) Dridex 89.108.71.148:8843
2015-11-10 12:10:562845499946fd5882f94cc9a4375b364aVirustotal results 2/52 (3.85%) Dridex 89.108.71.148:8843
2015-11-07 18:07:23ccbf04c318f66f55533b3c41ed4fe224Virustotal results 7/54 (12.96%) Dridex 89.108.71.148:8843
2015-11-07 17:44:5844d378ff4b9e6f0d0e253382da5c5d91Virustotal results 3/55 (5.45%) Dridex 89.108.71.148:8843

# of entries: 10 (max: 100)