SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint ce30b00cf259d1f5e527918953d19e7d6560e5fa.

Database Entry


SHA1 Fingerprint:ce30b00cf259d1f5e527918953d19e7d6560e5fa
Certificate Common Name (CN):endeavor.org
Issuer Distinguished Name (DN):endeavor.org
TLS Version:TLS 1.2
First seen:2019-09-22 12:26:36 UTC
Last seen:2019-10-01 17:59:14 UTC
Status:Blacklisted
Listing reason:IcedID C&C
Listing date:2019-09-25 11:22:22
Malware samples:6
Botnet C&Cs:3

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2019-10-01 17:59:1404372810ca4c7dc25cdbfa1292e2d6aen/aIcedID 193.0.61.106:443
2019-09-30 20:48:021fd8e38f4772545349bec4586f42037fVirustotal results 13 / 70 (18.57%) IcedID 91.203.5.180:443
2019-09-25 08:27:49a6955f14b72221adb34c3ee3d25ed285n/aIcedID 81.16.141.25:443
2019-09-24 20:34:05ff5d89daf691cfb9934e1d06721959afVirustotal results 22 / 70 (31.43%) IcedID 81.16.141.25:443
2019-09-22 12:33:0871feed7758a2a214220cb8adc7041e56Virustotal results 5 / 71 (7.04%) IcedID 81.16.141.25:443
2019-09-22 12:26:36976b1f404ffd1033c3434da829ee6d2dVirustotal results 19 / 69 (27.54%) IcedID 81.16.141.25:443

# of entries: 6 (max: 100)