SSL Certificates
The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint de6420f691749b275dee88469a088209359cef29.
Database Entry
SHA1 Fingerprint: | de6420f691749b275dee88469a088209359cef29 |
---|---|
Certificate Common Name (CN): | onc.ichentiv.mp |
Issuer Distinguished Name (DN): | onc.ichentiv.mp |
TLS Version: | TLSv1 |
First seen: | 2016-05-08 02:09:12 UTC |
Last seen: | 2016-05-26 04:27:44 UTC |
Status: | Blacklisted |
Listing reason: | Dridex C&C |
Listing date: | 2016-05-08 08:38:14 |
Malware samples: | 4 |
Botnet C&Cs: | 1 |
Malware Samples
The table below documents all malware samples associated with this SSL certificate.
Timestamp (UTC) | Malware Sample (MD5 hash) | VT | Signature | Botnet C&C (IP:port) |
---|---|---|---|---|
2016-05-26 04:27:44 | fc5e52f876c7970e81e9426544461b41 | 32/57 (56.14%) | Dridex | 210.245.92.63:4043 |
2016-05-26 04:27:44 | fc5e52f876c7970e81e9426544461b41 | 32/57 (56.14%) | Dridex | 210.245.92.63:4043 |
2016-05-09 16:28:55 | 79b4fe558c52a7c61df5369c6fb6b98e | 23/57 (40.35%) | Dridex | 210.245.92.63:4043 |
2016-05-09 16:28:55 | 79b4fe558c52a7c61df5369c6fb6b98e | 23/57 (40.35%) | Dridex | 210.245.92.63:4043 |
2016-05-08 02:12:36 | 3a3a47933a5683a09df812094d659bf6 | n/a | Dridex | 210.245.92.63:4043 |
2016-05-08 02:12:36 | 3a3a47933a5683a09df812094d659bf6 | n/a | Dridex | 210.245.92.63:4043 |
2016-05-08 02:09:12 | 9a6750215046dc1e0b338781257a3bd2 | 7/56 (12.50%) | 210.245.92.63:4043 | |
2016-05-08 02:09:12 | 9a6750215046dc1e0b338781257a3bd2 | 7/56 (12.50%) | 210.245.92.63:4043 |
# of entries: 8 (max: 100)