SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint e28dd9914a5a18e5c083dbf8291f018faba09fc0.

Database Entry


SHA1 Fingerprint:e28dd9914a5a18e5c083dbf8291f018faba09fc0
Certificate Common Name (CN):C=aa, L=Default City, O=Default Company Ltd
Issuer Distinguished Name (DN):C=aa, L=Default City, O=Default Company Ltd
TLS Version:TLS 1.2
First seen:2016-11-16 16:24:02 UTC
Last seen:2016-11-17 08:26:47 UTC
Status:Blacklisted
Listing reason:Vawtrak C&C
Listing date:2016-11-17 17:05:42
Malware samples:2
Botnet C&Cs:1

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2016-11-17 08:26:475486123dad3ee374c93dabe7e855ca60Virustotal results 39/57 (68.42%) Vawtrak 62.109.13.69:443
2016-11-17 08:26:475486123dad3ee374c93dabe7e855ca60Virustotal results 39/57 (68.42%) Vawtrak 62.109.13.69:443
2016-11-16 16:24:02e9d0a37ce15720f92a59cabfbe6c984bVirustotal results 10/56 (17.86%) Vawtrak 62.109.13.69:443
2016-11-16 16:24:02e9d0a37ce15720f92a59cabfbe6c984bVirustotal results 10/56 (17.86%) Vawtrak 62.109.13.69:443

# of entries: 4 (max: 100)