SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint cdb548cade0afb9d70daa7fac43a51fd23048540.

Database Entry


SHA1 Fingerprint:cdb548cade0afb9d70daa7fac43a51fd23048540
Certificate Common Name (CN):work4/L=Some-city/O=work4/ST=Some-state/OU=unit
Issuer Distinguished Name (DN):root
TLS Version:TLS 1.2
First seen:2017-10-18 19:36:25 UTC
Last seen:2018-04-09 08:59:22 UTC
Status:Blacklisted
Listing reason:Corebot C&C
Listing date:2017-12-11 19:26:32
Malware samples:29
Botnet C&Cs:2

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2018-04-09 08:59:22bcfde1e420a589b9ed3d5cb93b65c05eVirustotal results 42/68 (61.76%) Adware.Techsnab216.126.58.132:443
2017-12-20 07:40:3181a16485db349e5f3f231642ab3e1001Virustotal results 19/68 (27.94%) Adware.Techsnab216.126.58.132:443
2017-12-19 16:05:290882114550e2de5bf5d6d92501a71a26Virustotal results 5/66 (7.58%) Adware.Techsnab37.220.31.41:443
2017-12-17 22:41:27dcf0b2dff0b229d1772ff3daf434e3e1Virustotal results 27/67 (40.30%) Corebot 216.126.58.132:443
2017-12-17 13:59:45093a1680efaadfe3ec362be95629b5aaVirustotal results 38/68 (55.88%) Corebot 216.126.58.132:443
2017-12-17 05:53:35df9ac99987ef515b6d8470b6b6dc7ef5Virustotal results 16/67 (23.88%) Corebot 37.220.31.41:443
2017-12-16 15:28:47641970098972c155f618a338b6c715b2Virustotal results 38/67 (56.72%) Adware.Techsnab37.220.31.41:443
2017-12-15 22:30:592247167c7e10c9d40ef914fcbd550b85Virustotal results 10/67 (14.93%) Corebot 37.220.31.41:443
2017-12-12 10:28:481e7a35c7f13f1ab1aef68bc3dffca04bVirustotal results 37/68 (54.41%) Adware.Techsnab216.126.58.132:443
2017-12-11 13:54:53aac72becc942e3242d4c4c2846f4295an/aAdware.Techsnab216.126.58.132:443
2017-12-11 13:40:38c58b118059fe424d3e86c51712c15839Virustotal results 30/67 (44.78%) Adware.Techsnab216.126.58.132:443
2017-12-11 11:03:52ea22b139b5fb9ae2e221caac5afb97a4Virustotal results 39/68 (57.35%) Corebot 216.126.58.132:443
2017-12-10 21:30:53f2fde318c6f821685fda574d944548e8Virustotal results 31/68 (45.59%) Adware.Techsnab216.126.58.132:443
2017-12-10 15:15:09f7b5fc0a787b8954782c4a1d8fb8e35fVirustotal results 35/68 (51.47%) Corebot 216.126.58.132:443
2017-12-08 17:03:138185367baf396cd0fe4700caccdc308aVirustotal results 34/67 (50.75%) Corebot 216.126.58.132:443
2017-12-08 06:37:2812262e20e1478ea29d1e67370230823cVirustotal results 38/67 (56.72%) Adware.Techsnab216.126.58.132:443
2017-12-07 22:24:251d77dceeffeb963e5c854959e3367710Virustotal results 28/68 (41.18%) Adware.Techsnab216.126.58.132:443
2017-12-07 05:50:119b696058cd677d116af62589d13c7348Virustotal results 39/68 (57.35%) Corebot 216.126.58.132:443
2017-12-05 15:26:14e1afed807850a59c10f52fbd48547835Virustotal results 34/68 (50.00%) Adware.Techsnab216.126.58.132:443
2017-12-05 05:37:3244b645d44dfebb88b73c782d4630d364Virustotal results 33/67 (49.25%) Corebot 216.126.58.132:443
2017-12-04 17:05:3232c8c402a8730474e121009eeabd7b0aVirustotal results 36/68 (52.94%) Adware.Techsnab216.126.58.132:443
2017-12-04 08:20:38437b27539a9db9abb3f05ea64695af16Virustotal results 42/67 (62.69%) Adware.Techsnab216.126.58.132:443
2017-12-01 03:35:10d72d144b00e856c1ae033aa3658345bcVirustotal results 32/68 (47.06%) Adware.Techsnab216.126.58.132:443
2017-11-03 14:04:01a0a19f4c8f3ff24032cf7aabbcc4c912Virustotal results 9/66 (13.64%) Corebot 37.220.31.41:443
2017-10-31 08:49:4297cd279ae5014f6a49dffcfa72a4dec0n/aCorebot 37.220.31.41:443
2017-10-31 07:53:433aeabbd22cf2afb645e28f4fd9428bedn/aCorebot 37.220.31.41:443
2017-10-21 18:11:265d83c9e98e3bfe18d0db5c9642bb7d08Virustotal results 9/66 (13.64%) Adware.Techsnab37.220.31.41:443
2017-10-20 06:24:4120054390e05f10cbf2af0b49954b7430Virustotal results 21/63 (33.33%) Adware.Techsnab37.220.31.41:443
2017-10-18 19:36:25ad79dfefd765f2bc093683915ddea169Virustotal results 16/66 (24.24%) Corebot 37.220.31.41:443

# of entries: 29 (max: 100)