SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint b0e59355af6bfbe66974f1c0d38a93a351974679.

Database Entry


SHA1 Fingerprint:b0e59355af6bfbe66974f1c0d38a93a351974679
Certificate Common Name (CN):caraway.info
Issuer Distinguished Name (DN):caraway.info
TLS Version:TLS 1.2
First seen:2019-01-28 14:10:03 UTC
Last seen:2019-02-07 04:51:55 UTC
Status:Blacklisted
Listing reason:IcedID C&C
Listing date:2019-02-04 15:24:53
Malware samples:29
Botnet C&Cs:2

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2019-02-07 04:51:5552cd99321cf2a8c72e30d3e309620108Virustotal results 31/71 (43.66%) IcedID 87.236.22.142:443
2019-02-07 00:08:23ae9d708071d65b820cbeb49a7b78bc7bn/a87.236.22.142:443
2019-02-06 18:23:00a5f0e05734c58f9182e83aebf66a7e44Virustotal results 29/69 (42.03%) IcedID 87.236.22.142:443
2019-02-06 17:36:56f7ca07e1b157696d629c0c40944d9f4eVirustotal results 17/69 (24.64%) IcedID 87.236.22.142:443
2019-02-06 15:25:138f592759ff14253e42f63d339ce6a416Virustotal results 16/70 (22.86%) IcedID 87.236.22.142:443
2019-02-06 10:00:1103da7e570bd1a2b5ba01845e9d934df7Virustotal results 4/71 (5.63%) IcedID 87.236.22.142:443
2019-02-06 06:09:26e83b18736673afd13c629e19575ad1b7Virustotal results 14/71 (19.72%) IcedID 87.236.22.142:443
2019-02-06 05:43:5051158a2be10306d4da5719232694b3ben/aIcedID 87.236.22.142:443
2019-02-06 01:47:38af4cd874361940cbfcf19898ea198971Virustotal results 26/70 (37.14%) IcedID 87.236.22.142:443
2019-02-05 22:23:51fd8ee6840a6ce51991dd50b03fb1383dVirustotal results 30/71 (42.25%) 87.236.22.142:443
2019-02-05 21:43:3964b6f9691f3df5fce3de20ea4b1a830eVirustotal results 18/71 (25.35%) IcedID 87.236.22.142:443
2019-02-05 19:48:06d3461508c1bbdced56dda9f491d39e80Virustotal results 31/70 (44.29%) 87.236.22.142:443
2019-02-04 15:25:2633fcb779da2081fc07e3a205541554acVirustotal results 17/70 (24.29%) IcedID 185.22.65.5:443
2019-02-04 14:32:52494c47130a1e964dc5f1d9e16436303dVirustotal results 45/70 (64.29%) IcedID 185.22.65.5:443
2019-02-04 14:00:539a68d99d709b5791735ceb9c72779d4en/aIcedID 185.22.65.5:443
2019-02-04 13:17:23479ac32e30b4d122d72755ca5eb312d3n/aIcedID 185.22.65.5:443
2019-02-04 08:33:269de48677a0ffa329fd9e9347a4d2b0ccn/a185.22.65.5:443
2019-01-30 07:05:518963b9242f021797a384074a8828993cVirustotal results 46/70 (65.71%) IcedID 185.22.65.5:443
2019-01-29 10:37:531b36b2fa42a60279b9e87b9fc724cedbVirustotal results 45/70 (64.29%) IcedID 185.22.65.5:443
2019-01-29 09:25:3186b35beea55c48f822e8c99416e2e0f9Virustotal results 39/70 (55.71%) IcedID 185.22.65.5:443
2019-01-29 08:36:3055985fbec29e27f9aa0ab01ddf6e3438Virustotal results 44/68 (64.71%) IcedID 185.22.65.5:443
2019-01-29 00:33:15505c0bb6d713e8813ed426d2360300beVirustotal results 45/71 (63.38%) IcedID 185.22.65.5:443
2019-01-28 23:59:0977fa5f73912c63dbe854b5f2fd967f30Virustotal results 47/70 (67.14%) IcedID 185.22.65.5:443
2019-01-28 23:34:377d30ac19d5ab6674679a521b21e44301Virustotal results 40/71 (56.34%) IcedID 185.22.65.5:443
2019-01-28 19:32:40b8823ef797738ef1bb3e7df2d4f8ec5eVirustotal results 42/71 (59.15%) IcedID 185.22.65.5:443
2019-01-28 17:02:33a649dd28b4dea908ebd6d3f741b7b258Virustotal results 29/71 (40.85%) IcedID 185.22.65.5:443
2019-01-28 14:42:3092308fda64ef111706f8159d9a507ea7Virustotal results 29/71 (40.85%) IcedID 185.22.65.5:443
2019-01-28 14:11:3570c842cfbe6e9d4777e8a526f7a8d4e2Virustotal results 38/70 (54.29%) IcedID 185.22.65.5:443
2019-01-28 14:10:0322b9a4263f59b228b55791d3c7fb3853Virustotal results 29/70 (41.43%) IcedID 185.22.65.5:443

# of entries: 29 (max: 100)