SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint e4bba16c2aa6563e30a7eafccbcb5f43e4b72f68.

Database Entry


SHA1 Fingerprint:e4bba16c2aa6563e30a7eafccbcb5f43e4b72f68
Certificate Common Name (CN):Flmwrsdpl Rtlcxdfstfglmd, OU=Jbeeyn, ST=mpw, O=Ixulfkredin, C=SD, L=Uqlkndjdpos Ejjx
Issuer Distinguished Name (DN):Flmwrsdpl Rtlcxdfstfglmd, OU=Jbeeyn, ST=mpw, O=Ixulfkredin, C=SD, L=Uqlkndjdpos Ejjx
TLS Version:TLS 1.2
First seen:2022-12-12 20:24:12 UTC
Last seen:2022-12-13 16:13:37 UTC
Status:Blacklisted
Listing reason:DanaBot C&C
Listing date:2022-12-13 16:10:07
Malware samples:20
Botnet C&Cs:1

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2022-12-13 16:13:371c00eef6a97909723a0c7afa94cc3a77Virustotal results 32 / 69 (46.38%) 152.89.247.44:443
2022-12-13 14:50:039ab9692fcb18683990b631eea9d73ad4Virustotal results 27 / 72 (37.50%) Smoke Loader 152.89.247.44:443
2022-12-13 12:42:080fb20d6db0fafb6ec7beb8df61ac3423Virustotal results 35 / 72 (48.61%) 152.89.247.44:443
2022-12-13 12:41:443115f30d3c2963c22b8dba5bc075a63cVirustotal results 26 / 61 (42.62%) 152.89.247.44:443
2022-12-13 12:18:1048e86de7ab081ac388170b4cc43160deVirustotal results 26 / 71 (36.62%) Smoke Loader 152.89.247.44:443
2022-12-13 10:39:0841c450a5a4b21b9112cc6f6b2847200aVirustotal results 26 / 71 (36.62%) DanaBot152.89.247.44:443
2022-12-13 08:23:009e7d8e11bbe26788853ab6cc8d008506Virustotal results 30 / 71 (42.25%) 152.89.247.44:443
2022-12-13 08:21:539ca8273249ba756231f36ca7c7496148Virustotal results 28 / 71 (39.44%) Smoke Loader 152.89.247.44:443
2022-12-13 08:20:216456e3af7985dfa611e6e0ae1b65193bVirustotal results 33 / 70 (47.14%) 152.89.247.44:443
2022-12-13 08:20:17e9cb09dc5c78990bc165a306c97c26a4Virustotal results 27 / 71 (38.03%) Smoke Loader 152.89.247.44:443
2022-12-13 08:19:20eaf92bca63e448749ac805744b505cdaVirustotal results 31 / 71 (43.66%) 152.89.247.44:443
2022-12-13 08:19:042577d9c2fd3517e9d257230ba992b69eVirustotal results 33 / 70 (47.14%) 152.89.247.44:443
2022-12-13 08:17:458f711b66ec1c536ae191bbfab4de6faaVirustotal results 36 / 71 (50.70%) 152.89.247.44:443
2022-12-13 08:17:378a35066cdbb9183d89b52a68fb5a0401Virustotal results 29 / 71 (40.85%) Smoke Loader 152.89.247.44:443
2022-12-13 08:17:0156488cf7294830ca2eb515b925d6bb3bVirustotal results 25 / 68 (36.76%) Smoke Loader 152.89.247.44:443
2022-12-13 08:16:13395519c18c94ebd4e0ae335f6da0b04bVirustotal results 36 / 70 (51.43%) 152.89.247.44:443
2022-12-13 08:15:57b44d7cff8528d56fac2766fec4e3af13Virustotal results 36 / 72 (50.00%) 152.89.247.44:443
2022-12-13 08:15:252461aab453c7a6db54960484bbc546edVirustotal results 35 / 70 (50.00%) 152.89.247.44:443
2022-12-13 08:02:15dc21494964595252832285107c6edff1Virustotal results 27 / 71 (38.03%) Smoke Loader 152.89.247.44:443
2022-12-12 20:24:12f3b54e24459543e105886a9b77f35687Virustotal results 37 / 72 (51.39%) 152.89.247.44:443

# of entries: 20 (max: 100)