SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint e82c2cbeec954a6d47bcaae8fd23b9a80995e450.

Database Entry


SHA1 Fingerprint:e82c2cbeec954a6d47bcaae8fd23b9a80995e450
Certificate Common Name (CN):iominelian.bt
Issuer Distinguished Name (DN):iominelian.bt
TLS Version:TLSv1
First seen:2015-11-27 08:38:44 UTC
Last seen:2015-12-03 20:20:09 UTC
Status:Blacklisted
Listing reason:Dridex C&C
Listing date:2015-11-27 14:23:56
Malware samples:11
Botnet C&Cs:3

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2015-12-03 20:20:09d8bb901746d91b65ade376b9c340e8cfVirustotal results 6/56 (10.71%) Dridex 159.253.3.233:448
2015-12-03 10:14:5528db91c1b577b5db79196480a17a6bb3n/aDridex 159.253.3.233:448
2015-12-03 02:25:51cfffb94c9c65ca9a53456c450ba3283bn/aDridex 188.167.160.26:444
2015-12-02 23:37:312045e00346a42e0f7987b11a2b50d4dan/aDridex 188.167.160.26:444
2015-12-01 16:51:14588f8765ba6d4739ba17831b2f801926Virustotal results 3/56 (5.36%) Dridex 159.253.3.233:448
2015-12-01 15:10:412d7c9e97b103800f0d35094c1116f1e0n/aDridex 159.253.3.233:448
2015-12-01 15:03:570983ffa855d8ab95854d7ecb616f02e1Virustotal results 4/56 (7.14%) Dridex 159.253.3.233:448
2015-12-01 10:31:34cdc9cedefc1c9fced547571001fd286cn/aDridex 159.253.3.233:448
2015-12-01 02:06:505b7b9d98b760ce269c6447442adcb7f6Virustotal results 3/56 (5.36%) Dridex 159.253.3.233:448
2015-11-30 23:49:411f1ce7b772f876f0d7298ec90f895983Virustotal results 3/56 (5.36%) Dridex 159.253.3.233:448
2015-11-27 08:38:4462327418f87349973314f5e6d447d49eVirustotal results 10/56 (17.86%) Dridex 89.46.65.44:443

# of entries: 11 (max: 100)