SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 3732abdae5dfb059d920b51a4f99f654411ca6f7.

Database Entry


SHA1 Fingerprint:3732abdae5dfb059d920b51a4f99f654411ca6f7
Certificate Common Name (CN):localhost
Issuer Distinguished Name (DN):localhost
TLS Version:TLSv1
First seen:2016-10-25 08:41:36 UTC
Last seen:2016-11-17 19:44:05 UTC
Status:Blacklisted
Listing reason:Gootkit C&C
Listing date:2016-10-25 09:58:14
Malware samples:25
Botnet C&Cs:1

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2016-11-17 19:44:05ef3b008fa0edd184d12fb67fb8718d2bVirustotal results 30/56 (53.57%) Shylock 110.164.205.225:80
2016-11-16 12:51:55cab38d4411a5f3869e3c7edf5a02a657n/aShylock 110.164.205.225:80
2016-11-16 06:04:210e2c6a21858023e02f064c7b87a5108en/aShylock 110.164.205.225:80
2016-11-15 22:55:45eb208979574ac42ecfa730d4bcd30488Virustotal results 29/56 (51.79%) Shylock 110.164.205.225:80
2016-11-14 17:50:37b6449282de812fd9e44c06670653a331Virustotal results 36/57 (63.16%) Shylock 110.164.205.225:80
2016-11-14 17:39:14f10fbb59e164bd3b3872557b783e6cd4Virustotal results 34/62 (54.84%) Shylock 110.164.205.225:80
2016-11-14 13:00:552d77b595c5a3ee85b8fd571e427530a9n/aShylock 110.164.205.225:80
2016-11-14 08:54:2874e524da77b554bb5b847f3d618d1cdbn/aShylock 110.164.205.225:80
2016-11-04 22:55:2876b670c6907ce3d97a0bbb439d2c0838Virustotal results 39/57 (68.42%) Shylock 110.164.205.225:80
2016-11-04 22:07:040096706ae31e736ebf707288692b767fVirustotal results 10/56 (17.86%) Shylock 110.164.205.225:80
2016-11-04 20:34:58fb39ce078de3efcc499ab5da6b408cb4Virustotal results 19/55 (34.55%) Shylock 110.164.205.225:80
2016-11-04 13:00:02eb0519e31d1b1d082b9f75a47833a6bbVirustotal results 34/57 (59.65%) Shylock 110.164.205.225:80
2016-11-04 05:21:262f033a57e5ff66fd0fc26085e3d75afcVirustotal results 38/57 (66.67%) Shylock 110.164.205.225:80
2016-11-03 19:51:4293c0e2d86174b575a4881135346c752cVirustotal results 31/52 (59.62%) Shylock 110.164.205.225:80
2016-11-01 23:17:08b43f3a92de2d31dd99a243afa93d71b6n/aShylock 110.164.205.225:80
2016-11-01 20:19:049cc1ca962778c750af0b204c53573afdn/aShylock 110.164.205.225:80
2016-10-31 15:11:09a14eace2b6766c7893d3801c61187ab7n/aShylock 110.164.205.225:80
2016-10-31 00:28:296c40ecfe80d86188bea665f921263970n/aShylock 110.164.205.225:80
2016-10-30 15:22:55338cea20e0730bf02f3c2347345b880cn/aShylock 110.164.205.225:80
2016-10-28 12:19:24e9c493fa192d1494a774c49d7dcca6feVirustotal results 8/58 (13.79%) Gootkit 110.164.205.225:80
2016-10-28 09:29:206f24c2aef47fc19cf782f58e66c0f3baVirustotal results 26/57 (45.61%) Shylock 110.164.205.225:80
2016-10-28 07:48:231f201441dda58680f0879b445ba8337bVirustotal results 28/56 (50.00%) Gootkit 110.164.205.225:80
2016-10-27 13:04:49d8aadb6494f5736a48a51e3c02dc8d99Virustotal results 32/56 (57.14%) Gootkit 110.164.205.225:80
2016-10-26 22:41:2669188592c084d9dab8a8f41127ee5529Virustotal results 25/56 (44.64%) Gootkit 110.164.205.225:80
2016-10-25 08:41:36abc7cd5792aa41b76f1384ba09ab9fbbVirustotal results 34/57 (59.65%) Gootkit 110.164.205.225:80

# of entries: 25 (max: 100)