SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint aa3c5a4d930667dbcb38a502db7a2509a8aa95da.

Database Entry


SHA1 Fingerprint:aa3c5a4d930667dbcb38a502db7a2509a8aa95da
Certificate Common Name (CN):example.com
Issuer Distinguished Name (DN):example.com
TLS Version:TLS 1.2
First seen:2017-12-15 23:33:19 UTC
Last seen:2017-12-20 02:24:02 UTC
Status:Blacklisted
Listing reason:TrickBot C&C
Listing date:2017-12-17 12:52:11
Malware samples:3
Botnet C&Cs:1

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2017-12-20 02:24:0206c108582721442f227cd4fe562e958aVirustotal results 9/66 (13.64%) TrickBot 94.242.58.113:443
2017-12-20 02:24:0206c108582721442f227cd4fe562e958aVirustotal results 9/66 (13.64%) TrickBot 94.242.58.113:443
2017-12-17 11:52:34a5de0a18e513b2a7747d054e650e9310Virustotal results 30/68 (44.12%) TrickBot 94.242.58.113:443
2017-12-17 11:52:34a5de0a18e513b2a7747d054e650e9310Virustotal results 30/68 (44.12%) TrickBot 94.242.58.113:443
2017-12-15 23:33:198e36565e7e87102e70a755f5ba85ae71Virustotal results 36/68 (52.94%) TrickBot 94.242.58.113:443
2017-12-15 23:33:198e36565e7e87102e70a755f5ba85ae71Virustotal results 36/68 (52.94%) TrickBot 94.242.58.113:443

# of entries: 6 (max: 100)