SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 80fb1c50e80881ca4e07b12b191135efa10d37be.

Database Entry


SHA1 Fingerprint:80fb1c50e80881ca4e07b12b191135efa10d37be
Certificate Common Name (CN):spritheed.dz
Issuer Distinguished Name (DN):spritheed.dz
TLS Version:TLS 1.2
First seen:2015-10-27 02:50:06 UTC
Last seen:2016-01-27 18:11:11 UTC
Status:Blacklisted
Listing reason:Dridex C&C
Listing date:2015-11-07 20:48:49
Malware samples:20
Botnet C&Cs:4

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2016-01-27 18:11:115db72207a88951164f2f5a7f9e155428Virustotal results 37/55 (67.27%) Dridex 117.239.192.228:443
2016-01-25 18:58:473d7e1e8d02d4cf8ff2106f467a415b39Virustotal results 1/53 (1.89%) Dridex 117.239.192.228:443
2016-01-08 19:19:15a74c6dc81ef24ed55d287f3f45ec5716Virustotal results 6/55 (10.91%) Dridex 93.185.75.21:443
2016-01-08 16:59:15a81a19478dbe13778f06191cf39c8143Virustotal results 6/54 (11.11%) Dridex 202.129.57.130:443
2016-01-08 15:36:20613f5e4139e8006e9d47cb562450bc4aVirustotal results 35/56 (62.50%) Dridex 117.239.192.228:443
2016-01-07 12:09:15088724715613ff48edf090a74c8b6413Virustotal results 3/54 (5.56%) Dridex 117.239.192.228:443
2016-01-06 12:53:08fdd95b4cc10b536934486c7d3fdee04fVirustotal results 5/55 (9.09%) Dridex 117.239.192.228:443
2015-12-02 18:44:57c7e88e9ebd659473e07c8f025b623d2eVirustotal results 2/55 (3.64%) Dridex 187.141.112.98:443
2015-12-02 14:02:25f5cff3570f89ce76bfa6d19b5d3724deVirustotal results 6/55 (10.91%) Dridex 187.141.112.98:443
2015-11-18 07:57:580ca2a71d0f412c142132b5d5c3c7a76dVirustotal results 22/54 (40.74%) Dridex 187.141.112.98:443
2015-11-17 07:45:504656c1ab193c1d7a31c158aa29add4d6Virustotal results 10/53 (18.87%) Dridex 202.129.57.130:443
2015-11-16 16:49:49527b7f44376120b799c6a45a20b236a7Virustotal results 2/54 (3.70%) Dridex 93.185.75.21:443
2015-11-09 11:52:30248d8eb484739d2c112e2b735dea7d0fVirustotal results 1/53 (1.89%) Dridex 93.185.75.21:443
2015-11-09 05:36:37e0d09a5ce075d622162cf5575440fff8Virustotal results 6/55 (10.91%) Dridex 93.185.75.21:443
2015-11-06 16:06:1478915223a76ac6ff8c63495465942987Virustotal results 0/55 (0.00%) 93.185.75.21:443
2015-11-04 19:06:06f2b660069dfdf8d79139ea083d45ece2Virustotal results 27/56 (48.21%) 93.185.75.21:443
2015-10-29 16:27:06fcb74bbc59d90a51df252c2b695cb679Virustotal results 4/55 (7.27%) 93.185.75.21:443
2015-10-28 23:52:0317d4ce924436bd31e78a28df7716f9e0Virustotal results 18/54 (33.33%) 202.129.57.130:443
2015-10-28 21:11:220353a7702daeb560d64b10947458206aVirustotal results 6/54 (11.11%) 202.129.57.130:443
2015-10-27 02:50:068829bf4bc1400360e28ccc88c669c129Virustotal results 2/55 (3.64%) 93.185.75.21:443

# of entries: 20 (max: 100)