SSL Certificates
The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 8b604402e670210987a7a22d2cafd66a57f39bae.
Database Entry
| SHA1 Fingerprint: | 8b604402e670210987a7a22d2cafd66a57f39bae |
|---|---|
| Certificate Common Name (CN): | DcRat |
| Issuer Distinguished Name (DN): | DcRat Server, OU=qwqdanchun, O=DcRat By qwqdanchun, L=SH, C=CN |
| TLS Version: | TLSv1 |
| First seen: | 2023-09-07 19:33:04 UTC |
| Last seen: | 2023-09-08 14:54:01 UTC |
| Status: | Blacklisted |
| Listing reason: | DCRat C&C |
| Listing date: | 2023-09-08 19:36:01 |
| Malware samples: | 2 |
| Botnet C&Cs: | 1 |
Malware Samples
The table below documents all malware samples associated with this SSL certificate.
| Timestamp (UTC) | Malware Sample (MD5 hash) | VT | Signature | Botnet C&C (IP:port) |
|---|---|---|---|---|
| 2023-09-08 14:54:01 | 4719f04e68dfaad4767604118fed7251 | RemcosRAT | 179.13.2.154:7000 | |
| 2023-09-08 14:54:01 | 4719f04e68dfaad4767604118fed7251 | RemcosRAT | 179.13.2.154:7000 | |
| 2023-09-07 19:33:04 | bb07f51bd5bcb653c780f736b76c68b7 | RemcosRAT | 179.13.2.154:7000 | |
| 2023-09-07 19:33:04 | bb07f51bd5bcb653c780f736b76c68b7 | RemcosRAT | 179.13.2.154:7000 |
# of entries: 4 (max: 100)