SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 4a48decfeb6a4aea4410a77ad308f1b0108ceaa5.

Database Entry


SHA1 Fingerprint:4a48decfeb6a4aea4410a77ad308f1b0108ceaa5
Certificate Common Name (CN):localhost
Issuer Distinguished Name (DN):localhost
TLS Version:TLSv1
First seen:2016-04-28 15:53:06 UTC
Last seen:2016-05-19 13:45:15 UTC
Status:Blacklisted
Listing reason:Gootkit C&C
Listing date:2016-05-19 17:34:21
Malware samples:3
Botnet C&Cs:1

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2016-05-19 13:45:15b9741b15b1f2fdb3688c6a30e2e480a4Virustotal results 33/57 (57.89%) Gootkit 199.68.198.132:80
2016-05-19 13:45:15b9741b15b1f2fdb3688c6a30e2e480a4Virustotal results 33/57 (57.89%) Gootkit 199.68.198.132:80
2016-05-19 09:55:39b69a1640acdefcbb2dae0468b749ffb6Virustotal results 21/57 (36.84%) Gootkit 199.68.198.132:80
2016-05-19 09:55:39b69a1640acdefcbb2dae0468b749ffb6Virustotal results 21/57 (36.84%) Gootkit 199.68.198.132:80
2016-04-28 15:53:0601def4ea12d02a4b769f0e2003c37275Virustotal results 21/56 (37.50%) 199.68.198.132:80
2016-04-28 15:53:0601def4ea12d02a4b769f0e2003c37275Virustotal results 21/56 (37.50%) 199.68.198.132:80

# of entries: 6 (max: 100)