SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint bdd78030c894dbd5d72cd63ed8c28d55dea6dd3f.

Database Entry


SHA1 Fingerprint:bdd78030c894dbd5d72cd63ed8c28d55dea6dd3f
Certificate Common Name (CN):trnguestbenda.hn
Issuer Distinguished Name (DN):trnguestbenda.hn
TLS Version:SSLv3
First seen:2016-01-29 18:18:08 UTC
Last seen:2016-01-31 09:30:02 UTC
Status:Blacklisted
Listing reason:Dridex C&C
Listing date:2016-01-30 08:09:01
Malware samples:3
Botnet C&Cs:1

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2016-01-31 09:30:028acd22cea0aa46c28cc59ee99b129918Virustotal results 14/54 (25.93%) Dridex 85.143.166.200:1743
2016-01-31 09:30:028acd22cea0aa46c28cc59ee99b129918Virustotal results 14/54 (25.93%) Dridex 85.143.166.200:1743
2016-01-29 18:42:08d88c2bed761c7384d0e8657477af9da7Virustotal results 4/54 (7.41%) Dridex 85.143.166.200:1743
2016-01-29 18:42:08d88c2bed761c7384d0e8657477af9da7Virustotal results 4/54 (7.41%) Dridex 85.143.166.200:1743
2016-01-29 18:18:087420e1a673025f3f46dffe30f85032c8Virustotal results 2/53 (3.77%) Dridex 85.143.166.200:1743
2016-01-29 18:18:087420e1a673025f3f46dffe30f85032c8Virustotal results 2/53 (3.77%) Dridex 85.143.166.200:1743

# of entries: 6 (max: 100)