SSL Certificates
The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint eff92af923295b894bf7b9a665784932bd73e81c.
Database Entry
SHA1 Fingerprint: | eff92af923295b894bf7b9a665784932bd73e81c |
---|---|
Certificate Common Name (CN): | niciesadfondu.ht |
Issuer Distinguished Name (DN): | niciesadfondu.ht |
TLS Version: | TLSv1 |
First seen: | 2016-02-04 06:50:36 UTC |
Last seen: | 2016-02-09 12:55:30 UTC |
Status: | Blacklisted |
Listing reason: | Dridex C&C |
Listing date: | 2016-02-04 08:08:27 |
Malware samples: | 3 |
Botnet C&Cs: | 2 |
Malware Samples
The table below documents all malware samples associated with this SSL certificate.
Timestamp (UTC) | Malware Sample (MD5 hash) | VT | Signature | Botnet C&C (IP:port) |
---|---|---|---|---|
2016-02-09 12:55:30 | 58858caf4971fb89aaa7e84a385d975e | 2/54 (3.70%) | Dridex | 212.126.59.41:443 |
2016-02-09 12:55:30 | 58858caf4971fb89aaa7e84a385d975e | 2/54 (3.70%) | Dridex | 212.126.59.41:443 |
2016-02-05 23:46:11 | b4706d536e339b6fae9c5b1e835d5ef1 | 11/53 (20.75%) | Dridex | 212.126.59.41:443 |
2016-02-05 23:46:11 | b4706d536e339b6fae9c5b1e835d5ef1 | 11/53 (20.75%) | Dridex | 212.126.59.41:443 |
2016-02-04 06:50:36 | a9a6d0f6e1266dafd869ce61daedf2a6 | 6/53 (11.32%) | Dridex | 181.177.231.245:443 |
2016-02-04 06:50:36 | a9a6d0f6e1266dafd869ce61daedf2a6 | 6/53 (11.32%) | Dridex | 181.177.231.245:443 |
# of entries: 6 (max: 100)