SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 562e7f2f7b3d5913a6ca64f25854d131e56c4ff7.

Database Entry


SHA1 Fingerprint:562e7f2f7b3d5913a6ca64f25854d131e56c4ff7
Certificate Common Name (CN):localhost.localdomain
Issuer Distinguished Name (DN):localhost.localdomain
TLS Version:TLSv1
First seen:2016-12-11 15:35:27 UTC
Last seen:2018-01-04 19:34:54 UTC
Status:Blacklisted
Listing reason:Quakbot C&C
Listing date:2017-02-27 13:10:32
Malware samples:70
Botnet C&Cs:70

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2018-01-04 19:34:54b22f8ed383dad8ec15a53ef9e9fe3a83Virustotal results 31/68 (45.59%) Kovter131.108.170.231:443
2017-09-19 04:35:14a53e6ca80419fbe5ecc57c1eeb918106Virustotal results 51/65 (78.46%) Kovter190.1.231.231:443
2017-07-11 14:16:23c9546e0754e694e1d5e2ec497546a1abVirustotal results 14/64 (21.88%) Kovter86.99.122.180:443
2017-07-08 22:56:3027973aae04345e00acc6835e0925e364Virustotal results 20/64 (31.25%) Kovter186.114.237.54:443
2017-06-26 12:16:0592a5a6158474442f59c891992f92eb6en/aKovter179.33.115.200:443
2017-06-26 05:40:37f3d98a87e69f79f204a2b4ddc1ae6215n/aKovter117.200.11.11:443
2017-06-26 03:22:0671641dc4268c2cac060eef70d6cda1a6n/aKovter161.10.39.218:443
2017-06-25 09:23:404da9ec2ea126bfc0248a11261311ca11n/aKovter200.28.113.178:443
2017-06-17 05:43:56059bbc232262fb517eac27961f7fa57bn/aKovter161.10.192.68:443
2017-06-12 23:09:397df9302d4adffb5d004b2c9153c01841Virustotal results 41/61 (67.21%) Kovter31.215.129.180:443
2017-06-03 19:10:5062c5e7138b56ae18e7c3168cc75a4265n/aKovter59.98.97.170:443
2017-05-28 14:14:32fe06c96613dde19573bbbf86477a373cVirustotal results 40/62 (64.52%) Kovter181.234.125.7:443
2017-05-23 11:27:557027cb4a812607815a534b3d02463b59Virustotal results 39/62 (62.90%) Kovter181.234.131.143:443
2017-05-19 21:53:382e136a4e258d2deedbaca0112b79e613n/aKovter181.234.110.59:443
2017-05-19 12:50:2729027a62ed7386ce79c76959dd2119cfn/aKovter217.164.82.62:443
2017-05-12 18:37:4991cd856a6beecb956f37bdafd4604a23Virustotal results 47/59 (79.66%) Kovter217.19.223.20:443
2017-05-10 21:27:16a07200fce4023ad614b059a0ee45c1e8Virustotal results 43/62 (69.35%) Kovter117.199.204.238:443
2017-04-26 13:40:5032cf8d7a52a315ea499d96df7808ad9cn/aKovter186.27.192.36:443
2017-04-22 11:16:20b4f0938b9d60e7db13ebbfc32a426d18Virustotal results 11/62 (17.74%) Kovter117.99.183.127:443
2017-04-09 04:44:303f4bf563be7cae20a30031b01c3f61c1n/aKovter186.107.17.157:443
2017-03-20 20:51:113cac6b2b65f5b8eea2bca5f763f7ff69n/aKovter117.204.131.25:443
2017-03-20 12:54:4471a9669c14b06d6d9f0297972f8db533Virustotal results 50/61 (81.97%) Kovter161.10.212.151:443
2017-03-17 14:54:175b55cbda68d32fd6a73771feec756b1cVirustotal results 39/62 (62.90%) Kovter5.237.63.68:443
2017-03-16 18:11:17bd4bc06fb3ba537d5a4f6d4297f3b6ccVirustotal results 47/62 (75.81%) Kovter190.99.203.251:443
2017-03-16 02:27:06aff1e831c0dc57d97e5459ac04f89319Virustotal results 46/61 (75.41%) Kovter186.112.78.150:443
2017-03-16 00:35:25d7a8b46838ac9e6715b5a0307a4944f8Virustotal results 39/61 (63.93%) Kovter190.68.87.97:443
2017-03-14 23:16:03cdf083422b66b0af0db46cbb118c8299Virustotal results 45/61 (73.77%) Kovter186.112.44.52:443
2017-03-13 09:24:554bde0d7a6723aaf3129fef741a1303ddVirustotal results 38/59 (64.41%) Kovter191.110.143.138:443
2017-03-12 21:55:3609bda4bc85a5de45484b69ae968ff720n/aKovter61.3.147.231:443
2017-03-11 12:52:294097d6da5a51a804299c9bde23abd533n/aKovter186.114.103.155:443
2017-03-09 23:01:057ec6de8d6ab7a9d703ace1df1e73117an/aKovter179.32.209.39:443
2017-03-09 14:47:25000b2562ba78d0d46bed03d0dc5cd7afVirustotal results 42/60 (70.00%) Kovter186.27.246.62:443
2017-03-07 12:53:31686a2949ecc8427cc1260699cea297c1Virustotal results 13/58 (22.41%) Kovter58.182.10.7:443
2017-03-06 19:27:0081753a028b09ab7c4b6bfe3b257136d1Virustotal results 31/60 (51.67%) Kovter190.67.98.69:443
2017-03-05 20:03:382b0b4381ab0734d63f730787a6bce051Virustotal results 39/59 (66.10%) Kovter190.66.212.225:443
2017-03-05 18:00:5093b913dcfe7d773bde40781c9e0d9b86Virustotal results 49/62 (79.03%) Kovter117.221.26.63:443
2017-03-05 00:52:054726e4b7e91db790c724d8c6a066de9dVirustotal results 40/59 (67.80%) Kovter161.18.100.218:443
2017-03-04 18:02:32db21d13a6684747a83b9e8dbf5b12774Virustotal results 38/59 (64.41%) Kovter186.27.233.210:443
2017-03-01 17:12:56a00aca94936621cf0904b2230f8b1756Virustotal results 25/58 (43.10%) Kovter190.238.62.69:443
2017-02-28 11:42:01b980be49d74cc53e4adc4e60a2f04c35Virustotal results 41/59 (69.49%) Kovter190.69.239.72:443
2017-02-27 12:22:55d9e3743274df3ce00fa99b5bf6270bf0n/aQuakbot59.96.182.66:443
2017-02-23 17:02:53a3a1d6e4cf9976155538e46e97d00db1Virustotal results 42/58 (72.41%) Kovter31.14.145.250:443
2017-02-20 18:04:551996ff4b9fa9a3d816f6d85b5be3c6b9n/aKovter122.174.13.63:443
2017-02-19 14:22:49aeae26ebdca0c23e7a33660b83080047n/aKovter190.99.143.23:443
2017-02-14 13:52:45829d3b2d9a5e2bbfc7425fd21e643c65n/aKovter5.107.46.130:443
2017-02-12 18:26:26a55ad868fc17b03f5f883e8a841a6333Virustotal results 35/59 (59.32%) Kovter186.119.35.127:443
2017-02-12 14:59:416fe666739603ed69072b16d09f3ba024Virustotal results 8/57 (14.04%) Kovter2.190.245.212:443
2017-02-11 17:53:42b071eb6ceaea15b77de95f6ec9c51af2n/aKovter190.99.183.77:443
2017-02-11 16:27:59bb3fd17680fabcded7e8e4f76effc9e6n/aKovter191.109.33.76:443
2017-02-10 07:27:3059874a3989253e560a80a82c2d5f9cc1Virustotal results 43/58 (74.14%) Kovter190.254.235.168:443
2017-02-07 15:51:0927d8176e2f1b2b9f2f46a83dde7bf82dn/aKovter117.220.210.235:443
2017-02-07 02:05:5161fb3b74921f733df0b1e4201e1ea3d8n/aKovter170.81.24.154:443
2017-02-04 18:42:5509dccacb527fcd88c90ae6504d71a7b5n/aKovter5.107.29.149:443
2017-02-02 18:49:49efb223116348b73802eb18b20793bc7an/aKovter186.115.225.54:443
2017-01-31 15:19:54f92a9ae0d52f1271398158be63719b5cn/aKovter186.27.132.164:443
2017-01-28 20:37:03a949542f0d1c30a0a4b46c2a377ff57cVirustotal results 35/57 (61.40%) Kovter191.113.180.68:443
2017-01-28 05:33:462307e644a8d87e499cbd3331ef235409Virustotal results 39/56 (69.64%) Kovter190.68.232.25:443
2017-01-20 15:41:28f6b6d6222c81b2e55419c626ed96f23an/aKovter186.115.48.68:443
2017-01-18 08:15:28f120c11d28085e40f211031aaed15c7fn/aKovter186.27.188.184:443
2017-01-15 23:16:10a090cecd7ddd49b6a65625a21c9b0a6fn/aKovter186.113.121.138:443
2017-01-14 13:48:19cd91e16508412564a1978b52d0a9c3edn/aKovter179.33.92.17:443
2017-01-13 22:47:01a75d691dd858983383112826ca69e157n/aKovter92.96.1.58:443
2017-01-12 15:19:39d78bb337465105338a64710c5f658f31Virustotal results 36/57 (63.16%) Kovter95.81.78.201:443
2017-01-08 14:04:3308ad75aab1faba67bbadcb3090e312een/aKovter186.118.237.18:443
2017-01-04 18:27:5018815b6a3fe1b5293afe137214d79338n/aKovter31.31.9.153:443
2016-12-31 07:13:5201656ad4331a926451ea0c2b5fd95098Virustotal results 38/56 (67.86%) Kovter179.32.98.86:443
2016-12-24 03:45:456acec12809bb259f08a8b06e3c3513aeVirustotal results 34/56 (60.71%) Kovter190.99.185.101:443
2016-12-22 22:07:453ffc015b3268c24e6ceec3b382621740n/aKovter186.170.104.105:443
2016-12-13 03:35:38908595cc7ffa5260b7bde37bfa867822n/aKovter179.33.157.217:443
2016-12-11 15:35:2726d8834d1effde022828c0cb30d07688n/aKovter161.18.42.190:443

# of entries: 70 (max: 100)