SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 8dabf91f5c686235871cb263aa4d70ac27be5316.

Database Entry


SHA1 Fingerprint:8dabf91f5c686235871cb263aa4d70ac27be5316
Certificate Common Name (CN):pornhub.xxx
Issuer Distinguished Name (DN):pornhub.xxx
TLS Version:TLSv1
First seen:2015-06-04 08:28:41 UTC
Last seen:2015-06-10 00:41:28 UTC
Status:Blacklisted
Listing reason:Dridex C&C
Listing date:2015-06-04 10:37:31
Malware samples:4
Botnet C&Cs:2

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2015-06-10 00:41:285481bba9ec88a756a5a1a36390038049Virustotal results 3/57 (5.26%) Dridex 185.92.221.196:443
2015-06-10 00:41:285481bba9ec88a756a5a1a36390038049Virustotal results 3/57 (5.26%) Dridex 185.92.221.196:443
2015-06-09 00:16:065c27ce841ea8afd218944bc4cac64c9fVirustotal results 7/57 (12.28%) Dridex 185.92.221.196:443
2015-06-09 00:16:065c27ce841ea8afd218944bc4cac64c9fVirustotal results 7/57 (12.28%) Dridex 185.92.221.196:443
2015-06-07 15:40:1495d21fe72ebb34d8e46ecc0e7dc5b38bVirustotal results 6/57 (10.53%) Dridex 5.135.28.117:443
2015-06-07 15:40:1495d21fe72ebb34d8e46ecc0e7dc5b38bVirustotal results 6/57 (10.53%) Dridex 5.135.28.117:443
2015-06-04 08:28:4145f36577f92253880a7bed7620593d90Virustotal results 11/56 (19.64%) Dridex 185.92.221.196:443
2015-06-04 08:28:4145f36577f92253880a7bed7620593d90Virustotal results 11/56 (19.64%) Dridex 185.92.221.196:443

# of entries: 8 (max: 100)