{"id":42671,"date":"2021-09-03T00:00:00","date_gmt":"2021-09-03T00:00:00","guid":{"rendered":"https:\/\/www.trendmicro.com\/en_us\/research\/21\/i\/analyzing-ssl-tls-certificates-used-by-malware.html"},"modified":"2021-09-03T00:00:00","modified_gmt":"2021-09-03T00:00:00","slug":"analyzing-ssl-tls-certificates-used-by-malware-sr-security-researcher","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/analyzing-ssl-tls-certificates-used-by-malware-sr-security-researcher\/","title":{"rendered":"Analyzing SSL\/TLS Certificates Used by Malware Sr. Security Researcher"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/i\/ssl-tls-technical-brief\/tls-technical-brief-tb.jpg\"><\/p>\n<div><img decoding=\"async\" src=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/i\/ssl-tls-technical-brief\/tls-technical-brief-tb.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p>Malware has increasingly been making use of encryption to help hide their network traffic in recent years. This makes sense especially when one realizes that ordinary network traffic is increasingly encrypted as well. Google\u2019s own <a href=\"https:\/\/transparencyreport.google.com\/https\/overview?hl=en\">Transparency Report<\/a> notes that HTTPS traffic now makes up the vast majority of network traffic passed via the Google Chrome browser.<\/p>\n<p>In the past six years we\u2019ve seen both commodity and targeted attack malware make heavy use of encryption. This is done to evade detection as well as to blend in with normal encrypted traffic. Aside from malware, intrusion frameworks like Cobalt Strike, Metasploit, and Core Impact are making use of it as well. In many cases, this use of certificates extends to the use of X.509 certificates, which are normally used by SSL\/TLS.<\/p>\n<p>Our technical brief, titled <i><a href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/i\/ssl-tls-technical-brief\/ssl-tls-technical-brief.pdf\">The State of SSL\/TLS Certificate Usage in Malware C&amp;C Communications<\/a>,<\/i> goes over the certificates used by various malware families. We\u2019ll highlight certain interesting features and observations about the said certificates, along with detection techniques for quick recognition of these certificates. Detecting malware command-and-control (C&amp;C) traffic at the certificate level is crucial in order to stop malware at the earliest possible stage, especially if proxy-based decryption is not available.<\/p>\n<p>This blog will go over some of the unusual characteristics seen in the certificates used by malware, and how they can be used to detect malicious activity. We were able to examine 1,767 certificates that had been used by various malware families, the details of which can be found in the technical brief.<\/p>\n<p><b><i>Signing of certificates<\/i><\/b><\/p>\n<p>The signs of potential malicious activity start with how the certificates in question are signed. Of the certificates we examined, 60% were self-signed. This in itself should be a significant red flag. The name of the organization in the certificate itself frequently provides warning signs as well: some malware families like AsyncRAT and BitRAT include their own malware names in this field, while other malware families use some permutation of \u201cdefault\u201d or the oddly named \u201cInternet Widgits Pty Ltd,\u201d which is the default organization name used when OpenSSL creates certificates.<\/p>\n<p>The validity of the certificates can also vary significantly. Currently, browsers generally accept certificates that are valid for a maximum of 13 months, and certificate authorities generally issue certificates that are valid for shorter durations.<\/p>\n<p>Malicious certificates generally obey this rule, although some do not. We encountered certificates with validity periods ranging from as short as one month, up to multiple years (including some samples valid for up to 99 years). For example, Gozi has consistently used a 10-year validity period in its certificates since 2018 up to the present.<\/p>\n<p><b><i>Certificate pinning<\/i><\/b><\/p>\n<p>Certificate pinning is a method where a client (either a browser or, in this case, malware) restricts the number of valid certificates for a specific website, as opposed to just accepting any certificate that is validated. This is a method that certain websites and browsers use to secure their traffic, but it should not be a surprise that malware had adopted it as well.<\/p>\n<p>The use is not yet particularly common, but some families are known to use it extensively. These include <a href=\"https:\/\/research.checkpoint.com\/2021\/melting-ice-tracking-icedid-servers-with-a-few-simple-steps\/\">IcedID<\/a>, <a href=\"https:\/\/github.com\/NYAN-x-CAT\/AsyncRAT-C-Sharp\">AsyncRAT<\/a>, <a href=\"https:\/\/github.com\/qwqdanchun\/DcRat\">DcRAT<\/a>, <a href=\"https:\/\/fidelissecurity.com\/threatgeek\/archive\/vawtrak-c2-pin-it\/\">Vawtrak<\/a> and <a href=\"https:\/\/www.welivesecurity.com\/2020\/12\/17\/operation-signsight-supply-chain-attack-southeast-asia\/\">PhantomNet<\/a>. It should be noted that currently, all these malware families use self-signed certificates, so they could be detected via that method. However, it is perfectly plausible that this technique could be adopted to use certificates from trusted CAs, which we will discuss below.<\/p>\n<p><b><i>Certificates from trusted CAs<\/i><\/b><\/p>\n<p>While we noted earlier that most malicious certificates are self-signed, a sizable number of these are issued by well-known certificate authorities, as seen in the table below. The table shows the number of malicious certificates signed by each certificate authority.<\/p>\n<table cellpadding=\"1\" cellspacing=\"0\" border=\"1\" width=\"100%\">\n<tbody readability=\"3.5\">\n<tr>\n<td><b><i>Certificate Authority<\/i><\/b><\/td>\n<td><b><i>Certificates Issued<\/i><\/b><\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>Let&#8217;s Encrypt Authority X3<\/td>\n<td>458<\/td>\n<\/tr>\n<tr readability=\"2\">\n<td>COMODO RSA Domain Validation Secure Server CA<\/td>\n<td>41<\/td>\n<\/tr>\n<tr>\n<td>RapidSSL CA<\/td>\n<td>19<\/td>\n<\/tr>\n<tr>\n<td>EssentialSSL CA<\/td>\n<td>18<\/td>\n<\/tr>\n<tr readability=\"3\">\n<td>cPanel, Inc. Certification Authority<\/td>\n<td>13<\/td>\n<\/tr>\n<tr>\n<td>Others<\/td>\n<td>26<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><i>Table 1. Trusted certificate authorities (CA) certificates used by different malware families<\/i><\/p>\n<p>Several malware families were noted to be frequent users of these certificates. Gozi used 150 of those certificates, followed by 61 for QNodeService, 29 for BazaLoader, and 28 for ZLoader. As far as validity for these certificates is concerned, we noted that no certificate for a malicious domain was renewed after the three-month validity period offered by Let\u2019s Encrypt. For a few domains, we did find different certificates for the same domain, however.<\/p>\n<p>Policies regarding malicious domains and certificate issuance vary from CA to CA. Let\u2019s Encrypt, notably, <a href=\"https:\/\/letsencrypt.org\/2015\/10\/29\/phishing-and-malware.html\">does not believe<\/a> that certificate authorities should police the contents of domains. With TLS enabled by default across all domains, encryption would be an essential feature of all network traffic. Setting aside one\u2019s opinion of this position, it does complicate network defense procedures.<\/p>\n<p><b><i>Conclusion<\/i><\/b><\/p>\n<p>Normally, encrypted SSL\/TLS traffic hinders detecting malware C&amp;C communication traffic. However, by examining the certificates in use we can still detect such traffic and create IDS\/IPS signatures\/filters that attempt to detect different malware families at the certificate handshake level. In addition, it provides new information that threat investigators can use to find potentially malicious traffic.<\/p>\n<p>Full information about these techniques can be found in the <a href=\"https:\/\/www.trendmicro.com\/content\/dam\/trendmicro\/global\/en\/research\/21\/i\/ssl-tls-technical-brief\/ssl-tls-technical-brief.pdf\">technical brief<\/a>.<\/p>\n<p> Read More <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/21\/i\/analyzing-ssl-tls-certificates-used-by-malware.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>We take a closer look at the SSL\/TLS certificates used by malware. Read More HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":42672,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[61],"tags":[9510,9513,9509,9535],"class_list":["post-42671","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-trendmicro","tag-trend-micro-research-articles-news-reports","tag-trend-micro-research-malware","tag-trend-micro-research-research","tag-trend-micro-research-web"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Analyzing SSL\/TLS Certificates Used by Malware Sr. Security Researcher 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/analyzing-ssl-tls-certificates-used-by-malware-sr-security-researcher\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Analyzing SSL\/TLS Certificates Used by Malware Sr. Security Researcher 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/analyzing-ssl-tls-certificates-used-by-malware-sr-security-researcher\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2021-09-03T00:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/09\/analyzing-ssl-tls-certificates-used-by-malware-sr-security-researcher.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"641\" \/>\n\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/analyzing-ssl-tls-certificates-used-by-malware-sr-security-researcher\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/analyzing-ssl-tls-certificates-used-by-malware-sr-security-researcher\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Analyzing SSL\\\/TLS Certificates Used by Malware Sr. Security Researcher\",\"datePublished\":\"2021-09-03T00:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/analyzing-ssl-tls-certificates-used-by-malware-sr-security-researcher\\\/\"},\"wordCount\":870,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/analyzing-ssl-tls-certificates-used-by-malware-sr-security-researcher\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/09\\\/analyzing-ssl-tls-certificates-used-by-malware-sr-security-researcher.jpg\",\"keywords\":[\"Trend Micro Research : Articles, News, Reports\",\"Trend Micro Research : Malware\",\"Trend Micro Research : Research\",\"Trend Micro Research : Web\"],\"articleSection\":[\"TrendMicro\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/analyzing-ssl-tls-certificates-used-by-malware-sr-security-researcher\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/analyzing-ssl-tls-certificates-used-by-malware-sr-security-researcher\\\/\",\"name\":\"Analyzing SSL\\\/TLS Certificates Used by Malware Sr. Security Researcher 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/analyzing-ssl-tls-certificates-used-by-malware-sr-security-researcher\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/analyzing-ssl-tls-certificates-used-by-malware-sr-security-researcher\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/09\\\/analyzing-ssl-tls-certificates-used-by-malware-sr-security-researcher.jpg\",\"datePublished\":\"2021-09-03T00:00:00+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/analyzing-ssl-tls-certificates-used-by-malware-sr-security-researcher\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/analyzing-ssl-tls-certificates-used-by-malware-sr-security-researcher\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/analyzing-ssl-tls-certificates-used-by-malware-sr-security-researcher\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/09\\\/analyzing-ssl-tls-certificates-used-by-malware-sr-security-researcher.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/09\\\/analyzing-ssl-tls-certificates-used-by-malware-sr-security-researcher.jpg\",\"width\":641,\"height\":350},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/analyzing-ssl-tls-certificates-used-by-malware-sr-security-researcher\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Trend Micro Research : Articles, News, Reports\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/trend-micro-research-articles-news-reports\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Analyzing SSL\\\/TLS Certificates Used by Malware Sr. Security Researcher\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Analyzing SSL\/TLS Certificates Used by Malware Sr. Security Researcher 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/analyzing-ssl-tls-certificates-used-by-malware-sr-security-researcher\/","og_locale":"en_US","og_type":"article","og_title":"Analyzing SSL\/TLS Certificates Used by Malware Sr. Security Researcher 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/analyzing-ssl-tls-certificates-used-by-malware-sr-security-researcher\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2021-09-03T00:00:00+00:00","og_image":[{"width":641,"height":350,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/09\/analyzing-ssl-tls-certificates-used-by-malware-sr-security-researcher.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/analyzing-ssl-tls-certificates-used-by-malware-sr-security-researcher\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/analyzing-ssl-tls-certificates-used-by-malware-sr-security-researcher\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Analyzing SSL\/TLS Certificates Used by Malware Sr. Security Researcher","datePublished":"2021-09-03T00:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/analyzing-ssl-tls-certificates-used-by-malware-sr-security-researcher\/"},"wordCount":870,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/analyzing-ssl-tls-certificates-used-by-malware-sr-security-researcher\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/09\/analyzing-ssl-tls-certificates-used-by-malware-sr-security-researcher.jpg","keywords":["Trend Micro Research : Articles, News, Reports","Trend Micro Research : Malware","Trend Micro Research : Research","Trend Micro Research : Web"],"articleSection":["TrendMicro"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/analyzing-ssl-tls-certificates-used-by-malware-sr-security-researcher\/","url":"https:\/\/www.threatshub.org\/blog\/analyzing-ssl-tls-certificates-used-by-malware-sr-security-researcher\/","name":"Analyzing SSL\/TLS Certificates Used by Malware Sr. Security Researcher 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/analyzing-ssl-tls-certificates-used-by-malware-sr-security-researcher\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/analyzing-ssl-tls-certificates-used-by-malware-sr-security-researcher\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/09\/analyzing-ssl-tls-certificates-used-by-malware-sr-security-researcher.jpg","datePublished":"2021-09-03T00:00:00+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/analyzing-ssl-tls-certificates-used-by-malware-sr-security-researcher\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/analyzing-ssl-tls-certificates-used-by-malware-sr-security-researcher\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/analyzing-ssl-tls-certificates-used-by-malware-sr-security-researcher\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/09\/analyzing-ssl-tls-certificates-used-by-malware-sr-security-researcher.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/09\/analyzing-ssl-tls-certificates-used-by-malware-sr-security-researcher.jpg","width":641,"height":350},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/analyzing-ssl-tls-certificates-used-by-malware-sr-security-researcher\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"Trend Micro Research : Articles, News, Reports","item":"https:\/\/www.threatshub.org\/blog\/tag\/trend-micro-research-articles-news-reports\/"},{"@type":"ListItem","position":3,"name":"Analyzing SSL\/TLS Certificates Used by Malware Sr. Security Researcher"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/42671","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=42671"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/42671\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/42672"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=42671"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=42671"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=42671"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}