SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint e02dcdbdafbdc836dcb35fd1c61ff7dbf6886865.

Database Entry


SHA1 Fingerprint:e02dcdbdafbdc836dcb35fd1c61ff7dbf6886865
Certificate Common Name (CN):castles.info
Issuer Distinguished Name (DN):castles.info
TLS Version:TLS 1.2
First seen:2019-02-20 11:34:43 UTC
Last seen:2019-03-01 06:05:30 UTC
Status:Blacklisted
Listing reason:IcedID C&C
Listing date:2019-02-20 17:10:58
Malware samples:84
Botnet C&Cs:4

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2019-03-01 06:05:3012fd2d130e4769ecbd63a464709a3974Virustotal results 15/61 (24.59%) 188.127.239.51:443
2019-03-01 03:54:396f2e2a4208211efbaaa0f439ad7086f0Virustotal results 35/70 (50.00%) IcedID 188.127.239.51:443
2019-03-01 02:45:3660dce0e6cd90713189e0f5bac6e3d896Virustotal results 36/69 (52.17%) IcedID 188.127.239.51:443
2019-03-01 01:20:1293adc4751d5b1e7dd8d4390c824b2bddVirustotal results 33/68 (48.53%) IcedID 188.127.239.51:443
2019-02-28 18:47:09297c19189d862e12c3327dd0f2aa8cfaVirustotal results 34/69 (49.28%) IcedID 188.127.239.51:443
2019-02-28 17:17:02be70438b56f108ceae7f918f4ceb766eVirustotal results 35/70 (50.00%) IcedID 188.127.239.51:443
2019-02-28 13:26:456cfbc04d8fdd119948a6c9d98533df0aVirustotal results 43/68 (63.24%) IcedID 188.127.239.51:443
2019-02-28 12:55:28198e795e22929a111d470c3ac6e5fef1Virustotal results 22/66 (33.33%) IcedID 188.127.239.51:443
2019-02-28 11:35:17a78f1981622d2472dd18d8ead6137bb1Virustotal results 34/70 (48.57%) IcedID 188.127.239.51:443
2019-02-28 03:14:41448307610250c284e152edce17546443Virustotal results 35/69 (50.72%) IcedID 188.127.239.51:443
2019-02-27 21:55:366d7162c41bb4ced3e05ea1aae2cde13cVirustotal results 34/69 (49.28%) IcedID 188.127.239.51:443
2019-02-27 08:02:0228c5bf5244c03ba6153eea5dc060c152Virustotal results 38/65 (58.46%) IcedID 188.127.239.51:443
2019-02-27 05:57:33097e1b591b86ad67c5258a4b1d3f1ce1Virustotal results 35/66 (53.03%) IcedID 188.127.239.51:443
2019-02-27 03:58:09f2815c7ee4a77328bbd04b4eabec2013Virustotal results 33/65 (50.77%) IcedID 188.127.239.51:443
2019-02-26 17:32:566b71683738f1f88b1fdd42e9e5466573Virustotal results 11/66 (16.67%) IcedID 188.127.239.51:443
2019-02-26 15:14:54a7c71266513a6b8bb78002b6208b8cebVirustotal results 40/69 (57.97%) IcedID 188.127.239.51:443
2019-02-26 14:18:29596744dd3b4c3589518c17a3af113c37Virustotal results 41/70 (58.57%) IcedID 188.127.239.51:443
2019-02-26 13:31:505380faeb351447faddc3811ee2927cd0Virustotal results 22/65 (33.85%) IcedID 188.127.239.51:443
2019-02-26 12:55:50542e0fcc10cf62a87a7ebffc71790c09Virustotal results 33/65 (50.77%) IcedID 188.127.239.51:443
2019-02-26 12:51:44a9159ca352bccdae1312d937b13d4de6Virustotal results 23/70 (32.86%) IcedID 188.127.239.51:443
2019-02-26 10:09:195215d29202ad22a42e9565881d5bc191Virustotal results 23/71 (32.39%) IcedID 188.127.239.51:443
2019-02-26 08:42:4150806303f287c5b4e12127c964ac3587Virustotal results 18/71 (25.35%) IcedID 188.127.239.51:443
2019-02-26 06:25:500e9126a703ed07b034f6eaf831c279d8Virustotal results 24/65 (36.92%) IcedID 188.127.239.51:443
2019-02-26 05:24:16e81415cd5ff7b06fff4a706bb6a2e9c4Virustotal results 35/65 (53.85%) IcedID 188.127.239.51:443
2019-02-26 04:35:19b444260fe51dd45c6299e493facb5a50Virustotal results 33/65 (50.77%) IcedID 188.127.239.51:443
2019-02-26 04:33:14324ae8a9d9a0a6efd2bdc43ea552fb90Virustotal results 34/65 (52.31%) IcedID 188.127.239.51:443
2019-02-26 03:04:5602f8ba3abc5d5284710a22e0ad6d75bdVirustotal results 29/66 (43.94%) IcedID 188.127.239.51:443
2019-02-26 02:12:591001f6b46ddcc4a96076c5755b81cbc9Virustotal results 23/64 (35.94%) IcedID 188.127.239.51:443
2019-02-26 00:26:36cdcd7fcb30be0c891fb745c290a9a807Virustotal results 32/65 (49.23%) IcedID 188.127.239.51:443
2019-02-25 23:36:49ca29cfc26edefc1d9a6bc8bc07071640Virustotal results 22/66 (33.33%) IcedID 188.127.239.51:443
2019-02-25 21:48:3617c2875cbcd029e8996003d1bcb55e62Virustotal results 31/65 (47.69%) IcedID 188.127.239.51:443
2019-02-25 20:46:59ede7886b892e585d8fb04f4dc3ffbcc6Virustotal results 33/65 (50.77%) IcedID 188.127.239.51:443
2019-02-25 20:18:392c62207e713ea34219fe4c383b298218Virustotal results 14/65 (21.54%) IcedID 188.127.239.51:443
2019-02-25 19:43:532a99d56202e9cb090f897706baba12c7Virustotal results 34/65 (52.31%) IcedID 188.127.239.51:443
2019-02-25 17:48:2531e6de4484f4cbbe1ae398a1bb98992aVirustotal results 19/65 (29.23%) IcedID 188.127.239.51:443
2019-02-25 17:18:140a4ee57774bf1034f2b12740865adee9Virustotal results 33/65 (50.77%) IcedID 188.127.239.51:443
2019-02-25 15:23:474db98ada67ca5801807b649e5437c65fVirustotal results 34/70 (48.57%) IcedID 185.246.116.239:443
2019-02-25 14:20:42960659447836bf3e28d58186134ce2f0Virustotal results 31/65 (47.69%) IcedID 185.246.116.239:443
2019-02-25 13:34:59747f6b27e6cc813a18e0604b54a65525Virustotal results 21/66 (31.82%) IcedID 185.246.116.239:443
2019-02-25 12:04:13515e96e4d69bd36c576bb70a0644da03Virustotal results 34/70 (48.57%) IcedID 185.246.116.239:443
2019-02-25 11:48:38405e702b555091e4fde6e6a670466db1Virustotal results 23/64 (35.94%) IcedID 185.246.116.239:443
2019-02-25 10:27:01e5fc2698f7054df1fece4a2c1b24a9e5Virustotal results 33/69 (47.83%) IcedID 185.246.116.239:443
2019-02-25 08:12:02c7cb6bed473f6d5ec2d15279a9379d87Virustotal results 34/65 (52.31%) IcedID 185.246.116.239:443
2019-02-25 06:55:34dd26a87365607c11c554368a14b4a8c4Virustotal results 23/64 (35.94%) IcedID 185.246.116.239:443
2019-02-25 05:30:44a3c9bfd8d61aaebcc6e95ee6f65e48a0Virustotal results 20/64 (31.25%) IcedID 185.246.116.239:443
2019-02-25 04:32:28da84a36c5992f8f5216fc71696b18790Virustotal results 30/64 (46.88%) IcedID 185.246.116.239:443
2019-02-25 00:56:31740a78e488543070f5681f73599a0135Virustotal results 32/65 (49.23%) IcedID 185.246.116.239:443
2019-02-24 23:38:3379d99d76ae53105d94f945c8b53e7990Virustotal results 20/64 (31.25%) IcedID 185.246.116.239:443
2019-02-24 23:18:45367d3a3cab4880e638fc416804a05fcaVirustotal results 31/66 (46.97%) IcedID 185.246.116.239:443
2019-02-24 20:39:30269971f7d216e6510f04b57fe00dfe40Virustotal results 14/66 (21.21%) IcedID 185.246.116.239:443
2019-02-24 20:25:401b6bea2f6789e9e892b5aaf0c13aa166Virustotal results 31/65 (47.69%) IcedID 185.246.116.239:443
2019-02-24 19:17:05a0fe85bb433f102f204987fcf66fc865Virustotal results 11/65 (16.92%) IcedID 185.246.116.239:443
2019-02-24 18:56:40af5f782382a439a07f88831fb28f58beVirustotal results 22/65 (33.85%) IcedID 185.246.116.239:443
2019-02-24 17:52:31ee4c027862aadfce5c9c2c360ea51412Virustotal results 32/66 (48.48%) IcedID 185.246.116.239:443
2019-02-24 17:37:23ed0b87823a021305acd8256646109d2aVirustotal results 23/65 (35.38%) IcedID 185.246.116.239:443
2019-02-24 14:44:478341d2c7f7c56029009302345755bcb2Virustotal results 19/65 (29.23%) IcedID 185.246.116.239:443
2019-02-24 14:07:30261e4a388bdf2056c2b46a4eb20a697bVirustotal results 15/65 (23.08%) IcedID 185.246.116.239:443
2019-02-24 11:13:2894757d9ec7ead8bf1009775835de3e50Virustotal results 16/65 (24.62%) IcedID 185.246.116.239:443
2019-02-24 06:15:488cf5562c045af67fa5e22b22c2ec5f9eVirustotal results 28/70 (40.00%) IcedID 185.246.116.239:443
2019-02-24 04:47:07e5b88dd753d6abe39c0a315061d69c3cVirustotal results 11/65 (16.92%) IcedID 185.246.116.239:443
2019-02-24 02:07:34f140d3361e18aa643e935997a0ec0664Virustotal results 24/66 (36.36%) IcedID 185.246.116.239:443
2019-02-24 00:34:47873397a42a184e327c631c7b1140ca96Virustotal results 32/65 (49.23%) IcedID 185.246.116.239:443
2019-02-23 19:11:17ec4addaf3643afab0094cd2c4cc43400Virustotal results 28/65 (43.08%) IcedID 185.246.116.239:443
2019-02-23 18:45:549d282e4bc7a2fce12aa011460f83feceVirustotal results 34/65 (52.31%) IcedID 185.246.116.239:443
2019-02-23 18:16:0126727476405b48ef015a0ed24595ae0dVirustotal results 27/69 (39.13%) IcedID 185.246.116.239:443
2019-02-23 16:09:176cf87cd0cdeb6052113706ddf3730783Virustotal results 15/65 (23.08%) IcedID 185.246.116.239:443
2019-02-23 15:56:47b03cc0fb998dc3ed23b5ebfa7fa6d7f7Virustotal results 24/69 (34.78%) IcedID 185.246.116.239:443
2019-02-23 13:15:5117c9e202bce89a849f5542d7e103b8a5Virustotal results 32/66 (48.48%) IcedID 185.246.116.239:443
2019-02-23 10:49:2305d098c2ed94b008bfcad5dcd46583ddVirustotal results 21/63 (33.33%) IcedID 185.246.116.239:443
2019-02-23 09:28:2337fa4ac08d37445659874c9189e4cf77n/aIcedID 185.246.116.239:443
2019-02-23 09:20:234264806709a92cc5d464c5668455f675n/aIcedID 185.246.116.239:443
2019-02-23 09:18:5734c47a47891f3e1676937cc3951b8291n/aIcedID 185.246.116.239:443
2019-02-23 09:18:4741107e7efeb00e6c7524ad2747fbce03n/aIcedID 185.246.116.239:443
2019-02-23 09:16:4371cbabe95aa5a0627e395ec31b1a250fn/aIcedID 185.246.116.239:443
2019-02-23 09:15:09654dbd295d568d60feca1d4d24ca4d86n/aIcedID 185.246.116.239:443
2019-02-23 09:05:57fad9fb5f1a3e71c53b62c81823d7f86bn/aIcedID 185.246.116.239:443
2019-02-21 21:34:386a0447284ec60e5db2a26dbce854f1f4Virustotal results 20/64 (31.25%) IcedID 195.54.162.197:443
2019-02-21 19:21:58aa444a250ab46aff3413fd223d957b30Virustotal results 28/69 (40.58%) IcedID 195.54.162.197:443
2019-02-20 23:31:18baa2ba1a16159424549d014ff19c9106Virustotal results 16/65 (24.62%) IcedID 46.148.26.88:443
2019-02-20 22:58:493f026b7c7a94d9d6fec76b5c5c110ffbVirustotal results 27/71 (38.03%) IcedID 46.148.26.88:443
2019-02-20 19:30:273db31b726d26632b3f775a0ebc86e83bVirustotal results 28/69 (40.58%) IcedID 46.148.26.88:443
2019-02-20 15:21:4501937bde56254f1d0014afdd14f769c9Virustotal results 25/65 (38.46%) IcedID 46.148.26.88:443
2019-02-20 15:03:55bbd52cba24f25ff8c6b6c55faed1e527Virustotal results 33/70 (47.14%) IcedID 46.148.26.88:443
2019-02-20 11:34:4353b8068de1f5862cdc494f04a4d73106Virustotal results 8/70 (11.43%) IcedID 46.148.26.88:443

# of entries: 84 (max: 100)