SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint f93cc7c5582ba57a77a8d429962898f2d08d82b7.

Database Entry


SHA1 Fingerprint:f93cc7c5582ba57a77a8d429962898f2d08d82b7
Certificate Common Name (CN):Tatar's.org
Issuer Distinguished Name (DN):Tatar's.org
TLS Version:TLS 1.2
First seen:2019-09-22 12:26:36 UTC
Last seen:2019-10-01 17:59:14 UTC
Status:Blacklisted
Listing reason:IcedID C&C
Listing date:2019-09-25 11:22:20
Malware samples:6
Botnet C&Cs:4

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2019-10-01 17:59:1404372810ca4c7dc25cdbfa1292e2d6aen/aIcedID 185.253.218.26:443
2019-10-01 17:59:1404372810ca4c7dc25cdbfa1292e2d6aen/aIcedID 185.253.218.26:443
2019-09-30 20:48:021fd8e38f4772545349bec4586f42037fVirustotal results 13 / 70 (18.57%) IcedID 195.19.192.51:443
2019-09-30 20:48:021fd8e38f4772545349bec4586f42037fVirustotal results 13 / 70 (18.57%) IcedID 195.19.192.51:443
2019-09-25 08:27:48a6955f14b72221adb34c3ee3d25ed285n/aIcedID 31.41.44.65:443
2019-09-25 08:27:48a6955f14b72221adb34c3ee3d25ed285n/aIcedID 31.41.44.65:443
2019-09-24 20:34:06ff5d89daf691cfb9934e1d06721959afVirustotal results 22 / 70 (31.43%) IcedID 31.41.44.65:443
2019-09-24 20:34:06ff5d89daf691cfb9934e1d06721959afVirustotal results 22 / 70 (31.43%) IcedID 31.41.44.65:443
2019-09-22 12:33:0871feed7758a2a214220cb8adc7041e56Virustotal results 5 / 71 (7.04%) IcedID 51.83.78.85:443
2019-09-22 12:33:0871feed7758a2a214220cb8adc7041e56Virustotal results 5 / 71 (7.04%) IcedID 51.83.78.85:443
2019-09-22 12:26:36976b1f404ffd1033c3434da829ee6d2dVirustotal results 19 / 69 (27.54%) TrickBot 51.83.78.85:443
2019-09-22 12:26:36976b1f404ffd1033c3434da829ee6d2dVirustotal results 19 / 69 (27.54%) TrickBot 51.83.78.85:443
2019-09-22 12:26:36976b1f404ffd1033c3434da829ee6d2dVirustotal results 19 / 69 (27.54%) TrickBot 51.83.78.85:443
2019-09-22 12:26:36976b1f404ffd1033c3434da829ee6d2dVirustotal results 19 / 69 (27.54%) TrickBot 51.83.78.85:443

# of entries: 14 (max: 100)