SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 21a1c4b97d84ecd3eb6950c1b9f03135719e5dc0.

Database Entry


SHA1 Fingerprint:21a1c4b97d84ecd3eb6950c1b9f03135719e5dc0
Certificate Common Name (CN):test.com/emailAddress=web@test.com
Issuer Distinguished Name (DN):test.com/emailAddress=web@test.com
TLS Version:TLS 1.2
First seen:2017-01-19 17:14:39 UTC
Last seen:2017-01-20 18:52:23 UTC
Status:Blacklisted
Listing reason:Gootkit C&C
Listing date:2017-01-20 08:40:51
Malware samples:4
Botnet C&Cs:1

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2017-01-20 18:52:2343cd2b62768f911c2e5d76feac8fc781n/aGootkit 188.227.173.38:80
2017-01-20 18:52:2343cd2b62768f911c2e5d76feac8fc781n/aGootkit 188.227.173.38:80
2017-01-20 11:30:0219d8615700433a1727248fd22a7e2408Virustotal results 51/69 (73.91%) Gootkit 188.227.173.38:80
2017-01-20 11:30:0219d8615700433a1727248fd22a7e2408Virustotal results 51/69 (73.91%) Gootkit 188.227.173.38:80
2017-01-19 17:50:0063b05e25a17479bad73c2e84d6ea2276n/aGootkit 188.227.173.38:80
2017-01-19 17:50:0063b05e25a17479bad73c2e84d6ea2276n/aGootkit 188.227.173.38:80
2017-01-19 17:14:39587c565c9a269219c07191e69693a6ebn/aGootkit 188.227.173.38:80
2017-01-19 17:14:39587c565c9a269219c07191e69693a6ebn/aGootkit 188.227.173.38:80

# of entries: 8 (max: 100)