SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 94c96b10a43c6a48b4a2f07dd073ab958cc61e94.

Database Entry


SHA1 Fingerprint:94c96b10a43c6a48b4a2f07dd073ab958cc61e94
Certificate Common Name (CN):Ctbofcotyto.citic
Issuer Distinguished Name (DN):Ctbofcotyto.citic
TLS Version:TLSv1' NOTBEFOR
First seen:2019-08-22 11:03:21 UTC
Last seen:2019-08-22 23:25:04 UTC
Status:Blacklisted
Listing reason:Dridex C&C
Listing date:2019-08-22 11:48:43
Malware samples:2
Botnet C&Cs:1

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2019-08-22 23:25:04fc81d570e1985dd47a5cd7bf55a993b9Virustotal results 21 / 70 (30.00%) Dridex 74.208.64.187:3389
2019-08-22 23:25:04fc81d570e1985dd47a5cd7bf55a993b9Virustotal results 21 / 70 (30.00%) Dridex 74.208.64.187:3389
2019-08-22 11:03:21c69585d584497dbcec267b6a0444a160Virustotal results 21 / 64 (32.81%) Dridex 74.208.64.187:3389
2019-08-22 11:03:21c69585d584497dbcec267b6a0444a160Virustotal results 21 / 64 (32.81%) Dridex 74.208.64.187:3389

# of entries: 4 (max: 100)