SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint d1a2e7ae91821e3ebac461a08dc0ddcf6b3ca5ae.

Database Entry


SHA1 Fingerprint:d1a2e7ae91821e3ebac461a08dc0ddcf6b3ca5ae
Certificate Common Name (CN):southnorth.org
Issuer Distinguished Name (DN):southnorth.org
TLS Version:TLS 1.2
First seen:2015-06-13 01:41:17 UTC
Last seen:2015-06-13 08:57:27 UTC
Status:Blacklisted
Listing reason:Dridex C&C
Listing date:2015-06-13 08:19:49
Malware samples:3
Botnet C&Cs:1

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2015-06-13 08:57:278fd9723d1152613c2296cb5d1871f426Virustotal results 23/55 (41.82%) Dridex 71.14.1.139:8443
2015-06-13 08:57:278fd9723d1152613c2296cb5d1871f426Virustotal results 23/55 (41.82%) Dridex 71.14.1.139:8443
2015-06-13 05:45:3228b38de927c357184b3e105fe0c229eeVirustotal results 31/56 (55.36%) Dridex 71.14.1.139:8443
2015-06-13 05:45:3228b38de927c357184b3e105fe0c229eeVirustotal results 31/56 (55.36%) Dridex 71.14.1.139:8443
2015-06-13 01:41:17fa47e5b7244b193cd41baf33e8492e0aVirustotal results 17/57 (29.82%) Dridex 71.14.1.139:8443
2015-06-13 01:41:17fa47e5b7244b193cd41baf33e8492e0aVirustotal results 17/57 (29.82%) Dridex 71.14.1.139:8443

# of entries: 6 (max: 100)