SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint beefb54f6b801e58625a85c71986f37ecea7ac23.

Database Entry


SHA1 Fingerprint:beefb54f6b801e58625a85c71986f37ecea7ac23
Certificate Common Name (CN):shipfang.xyz
Issuer Distinguished Name (DN):WE1
TLS Version:TLS 1.2
First seen:2025-08-16 21:54:56 UTC
Last seen:2025-08-18 15:44:04 UTC
Status:Blacklisted
Listing reason:Malware C&C
Listing date:2025-08-17 12:41:43
Malware samples:16
Botnet C&Cs:2

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2025-08-18 15:44:04e7e401299bd2bc3bee8d3c59a83cb41dn/a172.67.147.214:443
2025-08-17 21:39:5334c91b4c4ecf3a58bd959aae387c991en/a104.21.79.204:443
2025-08-17 16:10:04ef640339f35b5a6c1e00ac55e454d0fbn/a172.67.147.214:443
2025-08-17 14:45:07dae2662ec42395cab3810364260ac03an/a104.21.79.204:443
2025-08-17 14:21:50e98b0cff2bf8177ec01fd006b0a87e42n/a104.21.79.204:443
2025-08-17 13:04:47ec2660217ed035487ab5ab9ee6a7ae64n/a104.21.79.204:443
2025-08-17 11:48:149509eb5568b306809fed8f348a7fc7a9n/a172.67.147.214:443
2025-08-17 10:53:21cee8feaece8cea5f5b75bca74335a38fn/a104.21.79.204:443
2025-08-17 10:20:34c73e1a6093879d1ef966ede96159e0e0n/a104.21.79.204:443
2025-08-17 09:47:25a6e5841370ece7fcbc8cdb1dfce0d74fn/a104.21.79.204:443
2025-08-17 04:41:06755495354cca993de2be297a1a1869afn/a104.21.79.204:443
2025-08-17 03:48:2468ad54d78db90a255edba8dade37e3d1n/a104.21.79.204:443
2025-08-17 02:21:2351e7ddb69797998dfe568b0b3bb12928n/a172.67.147.214:443
2025-08-17 01:38:1644fe870f0fc8593cc82551b57e2b3b20n/a104.21.79.204:443
2025-08-17 00:14:17206106330db069cd10106a2647d329f3n/a104.21.79.204:443
2025-08-16 21:54:560edd6eee00f9924f868eb462350a86f8n/a172.67.147.214:443

# of entries: 16 (max: 100)