SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 2fc9afd5d4fb22ea31258424c2444af7c7a01139.

Database Entry


SHA1 Fingerprint:2fc9afd5d4fb22ea31258424c2444af7c7a01139
Certificate Common Name (CN):localhost
Issuer Distinguished Name (DN):localhost
TLS Version:TLSv1
First seen:2016-04-27 13:54:42 UTC
Last seen:2016-05-01 17:28:11 UTC
Status:Blacklisted
Listing reason:Gootkit C&C
Listing date:2016-04-30 07:39:38
Malware samples:9
Botnet C&Cs:1

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2016-05-01 17:28:11381728f1f3e2f2f96b9dd7733a3fdb9eVirustotal results 12/57 (21.05%) Shylock 198.105.117.128:80
2016-05-01 12:16:28ffaf5e512af219f5dd7b3df501e5d7d3Virustotal results 3/56 (5.36%) Matsnu198.105.117.128:80
2016-04-30 18:42:48d97252879ccba25006a481088b6386e4n/a198.105.117.128:80
2016-04-30 16:14:305be1c129ca67ddae1d51eed086435ba2Virustotal results 22/57 (38.60%) 198.105.117.128:80
2016-04-30 01:59:34e71650c43de429c13f1962fa9e5fe21bn/aGootkit 198.105.117.128:80
2016-04-29 21:16:16467c77b32192e7b2bfab341d973a9a44n/aGootkit 198.105.117.128:80
2016-04-29 03:53:4727d56b90f51a9b34f86fd4dbac0d6a20n/aGootkit 198.105.117.128:80
2016-04-28 18:32:53969a807c9763c9c0d5111a1e179be70dn/aShylock 198.105.117.128:80
2016-04-27 13:54:42fbabcf8af31430f1a69b2afbf8ae1872n/aGootkit 198.105.117.128:80

# of entries: 9 (max: 100)