SSL Certificates
The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 8b604402e670210987a7a22d2cafd66a57f39bae.
Database Entry
SHA1 Fingerprint: | 8b604402e670210987a7a22d2cafd66a57f39bae |
---|---|
Certificate Common Name (CN): | DcRat |
Issuer Distinguished Name (DN): | DcRat Server, OU=qwqdanchun, O=DcRat By qwqdanchun, L=SH, C=CN |
TLS Version: | TLSv1 |
First seen: | 2023-09-07 19:33:04 UTC |
Last seen: | 2023-09-08 14:54:01 UTC |
Status: | Blacklisted |
Listing reason: | DCRat C&C |
Listing date: | 2023-09-08 19:36:01 |
Malware samples: | 2 |
Botnet C&Cs: | 1 |
Malware Samples
The table below documents all malware samples associated with this SSL certificate.
Timestamp (UTC) | Malware Sample (MD5 hash) | VT | Signature | Botnet C&C (IP:port) |
---|---|---|---|---|
2023-09-08 14:54:01 | 4719f04e68dfaad4767604118fed7251 | 51 / 71 (71.83%) | RemcosRAT | 179.13.2.154:7000 |
2023-09-08 14:54:01 | 4719f04e68dfaad4767604118fed7251 | 51 / 71 (71.83%) | RemcosRAT | 179.13.2.154:7000 |
2023-09-07 19:33:04 | bb07f51bd5bcb653c780f736b76c68b7 | 55 / 71 (77.46%) | RemcosRAT | 179.13.2.154:7000 |
2023-09-07 19:33:04 | bb07f51bd5bcb653c780f736b76c68b7 | 55 / 71 (77.46%) | RemcosRAT | 179.13.2.154:7000 |
# of entries: 4 (max: 100)