SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint aa1ba80505c16939f9e8ecda3aab066351dcb231.

Database Entry


SHA1 Fingerprint:aa1ba80505c16939f9e8ecda3aab066351dcb231
Certificate Common Name (CN):airportmonth.info
Issuer Distinguished Name (DN):WE1
TLS Version:TLS 1.2
First seen:2025-06-27 10:22:46 UTC
Last seen:2025-06-30 17:37:14 UTC
Status:Blacklisted
Listing reason:OffLoader C&C
Listing date:2025-06-28 14:05:25
Malware samples:12
Botnet C&Cs:2

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2025-06-30 17:37:14d3926bb1709ef5f19b446d7915d62a69n/a172.67.170.220:443
2025-06-30 17:27:00d37c67eab7a7b51873a2da7bf93e3e9dn/a172.67.170.220:443
2025-06-29 21:25:1643daf87be89a99c31409e2c9118d52dan/a104.21.28.142:443
2025-06-29 14:51:03d7040da5373471ed58b50067812d39e9n/a104.21.28.142:443
2025-06-29 03:50:20a0223159716e18d48a4b71185edc5b5en/a172.67.170.220:443
2025-06-29 03:40:158c74f96f699165d4fba80302046683e4n/a104.21.28.142:443
2025-06-29 03:23:45839460e4a4d9f47718609635841c0cfdn/a104.21.28.142:443
2025-06-29 03:08:417ef82ca1907023c2dc1fed490c4f4edfn/a104.21.28.142:443
2025-06-27 22:46:5036f981bd3166d77d46c6f910ee20a582n/a172.67.170.220:443
2025-06-27 20:49:260bff006744b657857b6a51d3d087eb4an/a104.21.28.142:443
2025-06-27 18:39:41b80a54349da588a3012afc2b0f1e1804n/a104.21.28.142:443
2025-06-27 10:22:467f447ef3c552a02f71ac5816d06219d1n/a172.67.170.220:443

# of entries: 12 (max: 100)