SSL Certificates
The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint de6420f691749b275dee88469a088209359cef29.
Database Entry
| SHA1 Fingerprint: | de6420f691749b275dee88469a088209359cef29 |
|---|---|
| Certificate Common Name (CN): | onc.ichentiv.mp |
| Issuer Distinguished Name (DN): | onc.ichentiv.mp |
| TLS Version: | TLSv1 |
| First seen: | 2016-05-08 02:09:12 UTC |
| Last seen: | 2016-05-26 04:27:44 UTC |
| Status: | Blacklisted |
| Listing reason: | Dridex C&C |
| Listing date: | 2016-05-08 08:38:14 |
| Malware samples: | 4 |
| Botnet C&Cs: | 1 |
Malware Samples
The table below documents all malware samples associated with this SSL certificate.
| Timestamp (UTC) | Malware Sample (MD5 hash) | VT | Signature | Botnet C&C (IP:port) |
|---|---|---|---|---|
| 2016-05-26 04:27:44 | fc5e52f876c7970e81e9426544461b41 | Dridex | 210.245.92.63:4043 | |
| 2016-05-26 04:27:44 | fc5e52f876c7970e81e9426544461b41 | Dridex | 210.245.92.63:4043 | |
| 2016-05-09 16:28:55 | 79b4fe558c52a7c61df5369c6fb6b98e | Dridex | 210.245.92.63:4043 | |
| 2016-05-09 16:28:55 | 79b4fe558c52a7c61df5369c6fb6b98e | Dridex | 210.245.92.63:4043 | |
| 2016-05-08 02:12:36 | 3a3a47933a5683a09df812094d659bf6 | n/a | Dridex | 210.245.92.63:4043 |
| 2016-05-08 02:12:36 | 3a3a47933a5683a09df812094d659bf6 | n/a | Dridex | 210.245.92.63:4043 |
| 2016-05-08 02:09:12 | 9a6750215046dc1e0b338781257a3bd2 | 210.245.92.63:4043 | ||
| 2016-05-08 02:09:12 | 9a6750215046dc1e0b338781257a3bd2 | 210.245.92.63:4043 |
# of entries: 8 (max: 100)