SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 8df0d5165b66591597e7ac6889309132a06b1a21.

Database Entry


SHA1 Fingerprint:8df0d5165b66591597e7ac6889309132a06b1a21
Certificate Common Name (CN):localhost
Issuer Distinguished Name (DN):localhost
TLS Version:TLSv1
First seen:2016-05-26 15:52:30 UTC
Last seen:2016-06-04 17:16:07 UTC
Status:Blacklisted
Listing reason:Gootkit C&C
Listing date:2016-06-05 07:53:17
Malware samples:4
Botnet C&Cs:1

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2016-06-04 17:16:07c5b74f789cf9a8087a1ba0aad26dce24Virustotal results 29/57 (50.88%) Gootkit 162.246.61.100:80
2016-06-04 17:16:07c5b74f789cf9a8087a1ba0aad26dce24Virustotal results 29/57 (50.88%) Gootkit 162.246.61.100:80
2016-05-31 14:20:034c3b4986c39714def25ceb62c0466dddVirustotal results 33/57 (57.89%) Gootkit 162.246.61.100:80
2016-05-31 14:20:034c3b4986c39714def25ceb62c0466dddVirustotal results 33/57 (57.89%) Gootkit 162.246.61.100:80
2016-05-27 01:36:03c8d3cc5a089299128098d9a7b69f7b87Virustotal results 15/56 (26.79%) Gootkit 162.246.61.100:80
2016-05-27 01:36:03c8d3cc5a089299128098d9a7b69f7b87Virustotal results 15/56 (26.79%) Gootkit 162.246.61.100:80
2016-05-26 15:52:300515a23c899d5d112de0dfd04b7e46c1Virustotal results 14/57 (24.56%) Gootkit 162.246.61.100:80
2016-05-26 15:52:300515a23c899d5d112de0dfd04b7e46c1Virustotal results 14/57 (24.56%) Gootkit 162.246.61.100:80

# of entries: 8 (max: 100)