SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint a571fb26952c9f6ecad7c6aec928bda870aa0d31.

Database Entry


SHA1 Fingerprint:a571fb26952c9f6ecad7c6aec928bda870aa0d31
Certificate Common Name (CN):mariton.ws
Issuer Distinguished Name (DN):R3
TLS Version:TLS 1.2
First seen:2022-05-24 18:37:06 UTC
Last seen:2022-05-29 06:03:27 UTC
Status:Blacklisted
Listing reason:Smoke Loader C&C
Listing date:2022-05-29 06:30:39
Malware samples:34
Botnet C&Cs:5

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2022-05-29 06:03:270f7a49f47b0f704238adfbf57777663eVirustotal results 30 / 64 (46.88%) Smoke Loader 80.66.64.42:443
2022-05-28 19:22:38efbb4d097679be92c9a9a70a5f3ef660n/aSmoke Loader 80.66.64.42:443
2022-05-28 19:14:3455dce7a598eb859cf4b050757c7b5185Virustotal results 42 / 64 (65.62%) Smoke Loader 80.66.64.42:443
2022-05-28 14:02:332a2435261ebb760fd06af06ce77a8f2cn/aSmoke Loader 80.66.64.42:443
2022-05-28 13:30:3091070c3789e10d09e391c748d9d7478cVirustotal results 54 / 68 (79.41%) Smoke Loader 80.66.64.42:443
2022-05-27 21:21:51a6d00c6a710021a5f8c99eafcc4d90eeVirustotal results 45 / 68 (66.18%) Amadey80.66.64.42:443
2022-05-27 16:30:27307990859eb551fcfba77c6e3269cbbfVirustotal results 24 / 69 (34.78%) Smoke Loader 195.2.81.11:443
2022-05-27 10:18:203c582e60aa38c371f3784055409b1f40Virustotal results 32 / 66 (48.48%) Smoke Loader 5.188.90.197:443
2022-05-27 09:53:31b48b7bd7884fc01871d476f25c542facVirustotal results 26 / 68 (38.24%) OnlyLogger5.188.90.197:443
2022-05-27 06:57:03e110b014af21ac7a1fb4005ecf089767Virustotal results 38 / 68 (55.88%) Smoke Loader 92.255.111.11:443
2022-05-27 06:52:34dbc75d5ebd8a2aeafd7d166ab4909956Virustotal results 34 / 68 (50.00%) Smoke Loader 92.255.111.11:443
2022-05-27 06:50:28b6db17f1536d7f5bc2b18e9fa2bf027bVirustotal results 34 / 67 (50.75%) Smoke Loader 92.255.111.11:443
2022-05-27 03:52:54ae4ee3b1d5147879c6ca93b686a20f3dVirustotal results 48 / 68 (70.59%) OnlyLogger92.255.111.11:443
2022-05-26 17:58:46c85ca413cc81ee30582d149a719f5ff0Virustotal results 47 / 69 (68.12%) OnlyLogger92.255.111.11:443
2022-05-26 17:15:256a293112ddd6920aa38458641768157aVirustotal results 22 / 66 (33.33%) Smoke Loader 92.255.111.11:443
2022-05-26 16:58:523b6ed56aeca3ac9e92a4019b26b348b5Virustotal results 25 / 64 (39.06%) OnlyLogger92.255.111.11:443
2022-05-26 16:52:04c856b16661a4dbe81f1bd46269c3f35bVirustotal results 39 / 68 (57.35%) OnlyLogger92.255.111.11:443
2022-05-26 14:06:32c6ab86c845e763dfe78b6f07242fa444Virustotal results 28 / 69 (40.58%) Smoke Loader 92.255.111.11:443
2022-05-26 12:22:145e43103cbd880222b144c55181c7ce4aVirustotal results 27 / 69 (39.13%) Smoke Loader 92.255.111.11:443
2022-05-26 11:03:264d8d2c0c4a29b98bf5a8752fdd0a91a5n/aSmoke Loader 92.255.111.11:443
2022-05-26 06:59:28754ec19dd74855ff2e72e82fc0e0f118n/aSmoke Loader 92.255.111.11:443
2022-05-26 06:50:24f263c3a622fe93df3bae206d591aefe4n/aSmoke Loader 92.255.111.11:443
2022-05-26 06:02:36c896eb7af44f18839af649ff8fb49951n/aSmoke Loader 92.255.111.11:443
2022-05-26 05:40:195a8540d03783ed24f54529b0bd843e60n/aSmoke Loader 92.255.111.11:443
2022-05-26 04:24:12bbfa44b9608b314d4e7bcea29576134fVirustotal results 43 / 68 (63.24%) RedLineStealer92.255.111.11:443
2022-05-26 04:15:59e9498c255d73a244d445cdda0c7a54can/aSmoke Loader 92.255.111.11:443
2022-05-25 23:04:27d7cdd2c8a258a83092e120e310dd64e0Virustotal results 23 / 67 (34.33%) Smoke Loader 92.255.111.11:443
2022-05-25 22:24:4119b5f78fdf161953eae1ac87f196cf7cVirustotal results 26 / 69 (37.68%) Smoke Loader 92.255.111.11:443
2022-05-25 16:56:535d4b5d26b63da2ad2c1e9fc282529321n/aSmoke Loader 5.188.89.1:443
2022-05-25 14:37:39490b609fbafed8092084986e332fca9cn/aSmoke Loader 5.188.89.1:443
2022-05-25 07:13:43ac06f9bca0eb89e6ff92a6dba5593fb9Virustotal results 39 / 68 (57.35%) RedLineStealer5.188.89.1:443
2022-05-25 04:03:372c7b02dedb123e0c947ba0755adf319eVirustotal results 19 / 66 (28.79%) Smoke Loader 5.188.89.1:443
2022-05-24 19:37:29464106b8c60c410f12db2ee06068cd3fn/aSmoke Loader 5.188.89.1:443
2022-05-24 18:37:068e77d6848af7de802d828d237de18b70n/aSmoke Loader 5.188.89.1:443

# of entries: 34 (max: 100)