SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 776384c49cc893139b680fa92da82a11d754a25f.

Database Entry


SHA1 Fingerprint:776384c49cc893139b680fa92da82a11d754a25f
Certificate Common Name (CN):localhost
Issuer Distinguished Name (DN):localhost
TLS Version:TLSv1
First seen:2016-07-11 11:48:22 UTC
Last seen:2016-07-19 00:11:24 UTC
Status:Blacklisted
Listing reason:Gootkit C&C
Listing date:2016-07-12 06:56:59
Malware samples:14
Botnet C&Cs:1

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2016-07-19 00:11:247ce7ba6d88d146e7cd49f28d246781b4Virustotal results 27/53 (50.94%) Gootkit 112.20.178.110:80
2016-07-19 00:11:247ce7ba6d88d146e7cd49f28d246781b4Virustotal results 27/53 (50.94%) Gootkit 112.20.178.110:80
2016-07-18 21:14:08aee6f32fd236fd820535c4a4aef131c0Virustotal results 18/54 (33.33%) Shylock 112.20.178.110:80
2016-07-18 21:14:08aee6f32fd236fd820535c4a4aef131c0Virustotal results 18/54 (33.33%) Shylock 112.20.178.110:80
2016-07-18 15:17:026271a3455e1e2e65d312dcff2bea2048Virustotal results 34/57 (59.65%) Shylock 112.20.178.110:80
2016-07-18 15:17:026271a3455e1e2e65d312dcff2bea2048Virustotal results 34/57 (59.65%) Shylock 112.20.178.110:80
2016-07-18 04:35:424e16f5aeb8caf95fe2399e072b6df103Virustotal results 30/55 (54.55%) Gootkit 112.20.178.110:80
2016-07-18 04:35:424e16f5aeb8caf95fe2399e072b6df103Virustotal results 30/55 (54.55%) Gootkit 112.20.178.110:80
2016-07-18 02:46:445ddb9c4439a98e210c706cece4c9624fn/aShylock 112.20.178.110:80
2016-07-18 02:46:445ddb9c4439a98e210c706cece4c9624fn/aShylock 112.20.178.110:80
2016-07-18 01:05:47feeaefdfe1ceaf976e447be4e45d37e2Virustotal results 19/54 (35.19%) Shylock 112.20.178.110:80
2016-07-18 01:05:47feeaefdfe1ceaf976e447be4e45d37e2Virustotal results 19/54 (35.19%) Shylock 112.20.178.110:80
2016-07-16 18:56:520e67f3476b472e6c70f634aca7bb891cVirustotal results 41/57 (71.93%) Shylock 112.20.178.110:80
2016-07-16 18:56:520e67f3476b472e6c70f634aca7bb891cVirustotal results 41/57 (71.93%) Shylock 112.20.178.110:80
2016-07-16 18:20:32213e23f09801ad5deee69db524763d5bn/aShylock 112.20.178.110:80
2016-07-16 18:20:32213e23f09801ad5deee69db524763d5bn/aShylock 112.20.178.110:80
2016-07-16 18:15:35774e1d9f9e2b2a7bcbb921aced97937bn/aGootkit 112.20.178.110:80
2016-07-16 18:15:35774e1d9f9e2b2a7bcbb921aced97937bn/aGootkit 112.20.178.110:80
2016-07-15 09:49:158028430d6855109f64de7481143e3766Virustotal results 23/55 (41.82%) Gootkit 112.20.178.110:80
2016-07-15 09:49:158028430d6855109f64de7481143e3766Virustotal results 23/55 (41.82%) Gootkit 112.20.178.110:80
2016-07-12 09:42:17feb5553828a4a4da1490c8c95319388fn/aGootkit 112.20.178.110:80
2016-07-12 09:42:17feb5553828a4a4da1490c8c95319388fn/aGootkit 112.20.178.110:80
2016-07-12 08:51:419d29646b640057e598fa48335aa520f6Virustotal results 28/54 (51.85%) Gootkit 112.20.178.110:80
2016-07-12 08:51:419d29646b640057e598fa48335aa520f6Virustotal results 28/54 (51.85%) Gootkit 112.20.178.110:80
2016-07-11 14:43:3787a60d3b09619e6480175a33a77fad61Virustotal results 36/55 (65.45%) Gootkit 112.20.178.110:80
2016-07-11 14:43:3787a60d3b09619e6480175a33a77fad61Virustotal results 36/55 (65.45%) Gootkit 112.20.178.110:80
2016-07-11 11:48:220c3fd79f7565ae56ba2db92eeb8a4ed2Virustotal results 15/55 (27.27%) Gootkit 112.20.178.110:80
2016-07-11 11:48:220c3fd79f7565ae56ba2db92eeb8a4ed2Virustotal results 15/55 (27.27%) Gootkit 112.20.178.110:80

# of entries: 28 (max: 100)