SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 42ea2a4de65640100d7223e9752d0783cf56ad58.

Database Entry


SHA1 Fingerprint:42ea2a4de65640100d7223e9752d0783cf56ad58
Certificate Common Name (CN):localhost
Issuer Distinguished Name (DN):localhost
TLS Version:TLSv1
First seen:2016-07-30 16:53:17 UTC
Last seen:2016-08-04 09:09:23 UTC
Status:Blacklisted
Listing reason:Gootkit C&C
Listing date:2016-08-01 08:15:31
Malware samples:15
Botnet C&Cs:1

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2016-08-04 09:09:232e30d634e34f8d0bedec52e102c2522cVirustotal results 39/63 (61.90%) Gootkit 217.125.140.215:80
2016-08-04 09:09:232e30d634e34f8d0bedec52e102c2522cVirustotal results 39/63 (61.90%) Gootkit 217.125.140.215:80
2016-08-04 02:52:24ab45002b32f16f8c122371ebbc1edfc6n/aGootkit 217.125.140.215:80
2016-08-04 02:52:24ab45002b32f16f8c122371ebbc1edfc6n/aGootkit 217.125.140.215:80
2016-08-03 20:24:34afb55425d9e557ef4a784e835a5c0372Virustotal results 40/57 (70.18%) Gootkit 217.125.140.215:80
2016-08-03 20:24:34afb55425d9e557ef4a784e835a5c0372Virustotal results 40/57 (70.18%) Gootkit 217.125.140.215:80
2016-08-03 20:06:011ff350a2a12d2e5e50dc30961afaa441n/aGootkit 217.125.140.215:80
2016-08-03 20:06:011ff350a2a12d2e5e50dc30961afaa441n/aGootkit 217.125.140.215:80
2016-08-02 21:38:020038f4d24fdad1047b5b7589377c7348n/aGootkit 217.125.140.215:80
2016-08-02 21:38:020038f4d24fdad1047b5b7589377c7348n/aGootkit 217.125.140.215:80
2016-08-02 15:13:38db8028b37de43586a0bec084cb0a10d4Virustotal results 41/70 (58.57%) Gootkit 217.125.140.215:80
2016-08-02 15:13:38db8028b37de43586a0bec084cb0a10d4Virustotal results 41/70 (58.57%) Gootkit 217.125.140.215:80
2016-08-02 12:31:562103b5af6cb464082e540d54426688e0Virustotal results 29/55 (52.73%) Gootkit 217.125.140.215:80
2016-08-02 12:31:562103b5af6cb464082e540d54426688e0Virustotal results 29/55 (52.73%) Gootkit 217.125.140.215:80
2016-08-01 12:14:42854e8cbe1ed48d8dd75392217fb601e8Virustotal results 29/55 (52.73%) Gootkit 217.125.140.215:80
2016-08-01 12:14:42854e8cbe1ed48d8dd75392217fb601e8Virustotal results 29/55 (52.73%) Gootkit 217.125.140.215:80
2016-07-31 22:27:22787378aa904ffe185de0e70daf5d392bn/aGootkit 217.125.140.215:80
2016-07-31 22:27:22787378aa904ffe185de0e70daf5d392bn/aGootkit 217.125.140.215:80
2016-07-31 16:11:130ec0962560a3e40c01b4120bafd73533n/aGootkit 217.125.140.215:80
2016-07-31 16:11:130ec0962560a3e40c01b4120bafd73533n/aGootkit 217.125.140.215:80
2016-07-31 13:52:488f1a2523a299a33ed0b380b49d48d128n/aGootkit 217.125.140.215:80
2016-07-31 13:52:488f1a2523a299a33ed0b380b49d48d128n/aGootkit 217.125.140.215:80
2016-07-31 11:53:107ef83fc30b8b923c8b4fb6144d5e9a2eVirustotal results 35/62 (56.45%) Gootkit 217.125.140.215:80
2016-07-31 11:53:107ef83fc30b8b923c8b4fb6144d5e9a2eVirustotal results 35/62 (56.45%) Gootkit 217.125.140.215:80
2016-07-30 23:18:11b3923a495137d23b5d0b61bc1c1505d3n/aGootkit 217.125.140.215:80
2016-07-30 23:18:11b3923a495137d23b5d0b61bc1c1505d3n/aGootkit 217.125.140.215:80
2016-07-30 19:08:084415342003f722759e8e656fdec34c45Virustotal results 41/68 (60.29%) Gootkit 217.125.140.215:80
2016-07-30 19:08:084415342003f722759e8e656fdec34c45Virustotal results 41/68 (60.29%) Gootkit 217.125.140.215:80
2016-07-30 16:53:174d499db32b75225b7543786ba0fc3b39n/aGootkit 217.125.140.215:80
2016-07-30 16:53:174d499db32b75225b7543786ba0fc3b39n/aGootkit 217.125.140.215:80

# of entries: 30 (max: 100)