SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 9c6d80bd524275aaab7c35f9e1c8d17aca14da56.

Database Entry


SHA1 Fingerprint:9c6d80bd524275aaab7c35f9e1c8d17aca14da56
Certificate Common Name (CN):O=Nextcloud
Issuer Distinguished Name (DN):O=Nextcloud
TLS Version:TLS 1.2
First seen:2024-01-16 17:32:48 UTC
Last seen:2024-01-21 15:11:27 UTC
Status:Blacklisted
Listing reason:AsyncRAT C&C
Listing date:2024-01-21 16:08:39
Malware samples:24
Botnet C&Cs:1

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2024-01-21 15:11:2770283026ba9695e80afb00878f717166n/aRedLineStealer45.15.156.13:443
2024-01-21 10:33:09bfc9048b5381ff08e29ca318b0cacd70n/aRiseProStealer45.15.156.13:443
2024-01-21 07:15:1333cb562a49f8030eb993c210f4fb1221n/aTeamBot45.15.156.13:443
2024-01-21 06:40:354bf40a595b37b88d2f0967eb52a30d7dn/aRiseProStealer45.15.156.13:443
2024-01-20 23:11:28219e7425b61f8b9f627e1a4659901f2dn/aRiseProStealer45.15.156.13:443
2024-01-20 17:29:12f6ff3a0cbac3c500cbb81c2b4b7ad4bcn/aRedLineStealer45.15.156.13:443
2024-01-20 14:49:592a8acf7f94a29576615a032a66cbcff1n/aTeamBot45.15.156.13:443
2024-01-20 13:18:49557499e92f38268a8c2dbc0df429af45n/aStealc45.15.156.13:443
2024-01-20 10:14:173dd9bb3ade421f4eab256da0f42646a3n/aRedLineStealer45.15.156.13:443
2024-01-20 06:22:2171f8c64c8401696c1b9ac019a41a5560Virustotal results 29 / 68 (42.65%) RedLineStealer45.15.156.13:443
2024-01-20 02:09:0413945cbf3c3e5b489d31d4b455cbaecfVirustotal results 47 / 69 (68.12%) RedLineStealer45.15.156.13:443
2024-01-20 00:28:44fd6e2c2a7ec65fad669f417889f84c01n/aRedLineStealer45.15.156.13:443
2024-01-19 19:58:00868515a887db8abcc95220ee552fff24n/aRedLineStealer45.15.156.13:443
2024-01-19 18:48:180518d9c6db9a614769bf43fbff180167n/aStealc45.15.156.13:443
2024-01-19 16:58:01cecd3d6f1c7b8d576d8cf06dcea88fb3n/aAmadey45.15.156.13:443
2024-01-19 16:52:5943c66bb7924057abaf91e8ac6cc54072n/aRedLineStealer45.15.156.13:443
2024-01-19 13:12:0411549be2ba97133ebb7fefa2ab72f07eVirustotal results 27 / 66 (40.91%) RedLineStealer45.15.156.13:443
2024-01-19 10:59:2759948cd893faf099be39f2f29772f819n/aRedLineStealer45.15.156.13:443
2024-01-18 10:23:27458210ef2582bca66b0afd0f218cfaben/aLummaStealer45.15.156.13:443
2024-01-17 23:26:35670c15df899a987829b0a7c80635a7a0n/aRedLineStealer45.15.156.13:443
2024-01-17 08:10:34541a947f3486e027e9b0272e040753adn/aRedLineStealer45.15.156.13:443
2024-01-17 06:04:238240eb3d826794476f74b0fc5da88bfdVirustotal results 23 / 63 (36.51%) TeamBot45.15.156.13:443
2024-01-17 00:45:14c270f55b4f6be6256d136dd2932993d9Virustotal results 25 / 68 (36.76%) TeamBot45.15.156.13:443
2024-01-16 17:32:483f5253347efcd059dbd4c0ac9d571fb2Virustotal results 24 / 69 (34.78%) RedLineStealer45.15.156.13:443

# of entries: 24 (max: 100)