SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 8b604402e670210987a7a22d2cafd66a57f39bae.

Database Entry


SHA1 Fingerprint:8b604402e670210987a7a22d2cafd66a57f39bae
Certificate Common Name (CN):DcRat
Issuer Distinguished Name (DN):DcRat Server, OU=qwqdanchun, O=DcRat By qwqdanchun, L=SH, C=CN
TLS Version:TLSv1
First seen:2023-09-07 19:33:04 UTC
Last seen:2023-09-08 14:54:01 UTC
Status:Blacklisted
Listing reason:DCRat C&C
Listing date:2023-09-08 19:36:01
Malware samples:2
Botnet C&Cs:1

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2023-09-08 14:54:014719f04e68dfaad4767604118fed7251Virustotal results 51 / 71 (71.83%) RemcosRAT179.13.2.154:7000
2023-09-08 14:54:014719f04e68dfaad4767604118fed7251Virustotal results 51 / 71 (71.83%) RemcosRAT179.13.2.154:7000
2023-09-07 19:33:04bb07f51bd5bcb653c780f736b76c68b7Virustotal results 55 / 71 (77.46%) RemcosRAT179.13.2.154:7000
2023-09-07 19:33:04bb07f51bd5bcb653c780f736b76c68b7Virustotal results 55 / 71 (77.46%) RemcosRAT179.13.2.154:7000

# of entries: 4 (max: 100)