SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 820cd09994b3e76f6e89926a4b94ec0ccacd888c.

Database Entry


SHA1 Fingerprint:820cd09994b3e76f6e89926a4b94ec0ccacd888c
Certificate Common Name (CN):railchalk.xyz
Issuer Distinguished Name (DN):WE1
TLS Version:TLS 1.2
First seen:2026-07-22 11:46:56 UTC
Last seen:2026-07-22 14:20:52 UTC
Status:Blacklisted
Listing reason:OffLoader C&C
Listing date:2026-07-23 18:42:41
Malware samples:5
Botnet C&Cs:2

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2026-07-22 14:20:52b94aae0075434ab42dfa60d1edc4d235n/a104.21.32.149:443
2026-07-22 14:04:13a57c77cfc4f0f3d02d55b842d69a9794n/a172.67.186.235:443
2026-07-22 13:36:045fcac24c54aa12aa52ea66a1649aba47n/a104.21.32.149:443
2026-07-22 12:00:531c1ee897d5b3fff962e553e6e6707726n/a104.21.32.149:443
2026-07-22 11:46:5620a67e869b83400778fdacc52310e6f5n/a104.21.32.149:443

# of entries: 5 (max: 100)