SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 5d47e102ad3ac8ff5910aa411ca5520482b4f05f.

Database Entry


SHA1 Fingerprint:5d47e102ad3ac8ff5910aa411ca5520482b4f05f
Certificate Common Name (CN):localhost
Issuer Distinguished Name (DN):localhost
TLS Version:TLSv1
First seen:2016-09-26 09:48:41 UTC
Last seen:2016-11-24 01:06:27 UTC
Status:Blacklisted
Listing reason:Gootkit C&C
Listing date:2016-10-28 13:41:38
Malware samples:106
Botnet C&Cs:1

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2016-11-24 01:06:27bf7863fe6f4ff9cb60ca6e1110fb4221Virustotal results 40/57 (70.18%) Gootkit 43.239.221.51:80
2016-11-23 20:32:123579852cc6d1bacf5021d83c6634ec51Virustotal results 36/57 (63.16%) Gootkit 43.239.221.51:80
2016-11-23 19:09:259226afb1fdffb9d866c6dffc78365ef9n/aGootkit 43.239.221.51:80
2016-11-23 18:48:30db7efadc8084ff4b5ddd94fd035d9577n/aGootkit 43.239.221.51:80
2016-11-22 14:16:28d21ab10e9779fa6f7d68b877fd01113cVirustotal results 38/66 (57.58%) Gootkit 43.239.221.51:80
2016-11-22 06:22:09ad8f6360f496002071ae6960ed2f5607n/aGootkit 43.239.221.51:80
2016-11-22 05:49:29415e5e2536677956a21cefc42bc290c2Virustotal results 41/57 (71.93%) Gootkit 43.239.221.51:80
2016-11-20 22:16:39dceb2b9102e7ad2ca4bc0b487040985en/aGootkit 43.239.221.51:80
2016-11-20 00:05:41f0d976d0990ddf5f28e26c976ed54980n/aGootkit 43.239.221.51:80
2016-11-19 23:11:19f4661e03ad109c299a6354bca6157e01n/aGootkit 43.239.221.51:80
2016-11-19 21:11:458efdeba44b411aa0afe773760af13d42Virustotal results 40/56 (71.43%) Gootkit 43.239.221.51:80
2016-11-18 20:23:379cb6a178fb186cb6808921bd81da9040Virustotal results 30/57 (52.63%) Gootkit 43.239.221.51:80
2016-11-17 11:30:04c4b9c199373385746b989f06b1f42142Virustotal results 37/57 (64.91%) Gootkit 43.239.221.51:80
2016-11-16 21:00:35a688b87620efc9b3d24a66845f0a86f4n/aGootkit 43.239.221.51:80
2016-11-16 12:51:30e70227fc921b6c00db264b7d7d0c4de3Virustotal results 43/57 (75.44%) Gootkit 43.239.221.51:80
2016-11-16 10:27:5062d97d5142e754857517888af12d0015Virustotal results 35/56 (62.50%) Gootkit 43.239.221.51:80
2016-11-16 09:45:36439f657965cef8c88558bd4020363010Virustotal results 44/60 (73.33%) Gootkit 43.239.221.51:80
2016-11-16 00:15:41eacfb3e0feb3234c42961618b4fef373Virustotal results 43/57 (75.44%) Gootkit 43.239.221.51:80
2016-11-15 11:56:407ee80e55f5c3fda028af29c4f7d5b889Virustotal results 42/57 (73.68%) Gootkit 43.239.221.51:80
2016-11-14 14:04:001f1505ffd91965c31fb4f02809a432b9n/aGootkit 43.239.221.51:80
2016-11-05 06:02:132416eea3e1f8ea24994f2a6067acdcf7n/aGootkit 43.239.221.51:80
2016-11-04 18:08:592018a776be49d3a85c588a64ec1fa3c1Virustotal results 42/67 (62.69%) Gootkit 43.239.221.51:80
2016-11-04 15:11:26c6574674350456cc5ee978c2a493a537n/aGootkit 43.239.221.51:80
2016-11-04 13:35:26edc2b1a8c359fb4a61ae7ba31d98b159Virustotal results 45/68 (66.18%) Gootkit 43.239.221.51:80
2016-11-04 11:37:546eed8860927b6e04301d8a2147091b23Virustotal results 35/55 (63.64%) Gootkit 43.239.221.51:80
2016-11-04 11:08:415c0be7bff7fd8546c86c648198905627n/aGootkit 43.239.221.51:80
2016-11-04 08:52:26d60093a98cc249bc028f2a89e41559c0n/aGootkit 43.239.221.51:80
2016-11-04 02:18:1518df97b814849ee92e464e3f352261c5n/aGootkit 43.239.221.51:80
2016-11-03 23:27:22d0d4621030267388a1dc35d7a80cf588n/aGootkit 43.239.221.51:80
2016-11-03 04:32:234737945a5410e642f9c87f94b28a9447Virustotal results 40/56 (71.43%) Gootkit 43.239.221.51:80
2016-11-02 20:40:36444d589ac136c75856b7d4ae8b24b84fVirustotal results 12/56 (21.43%) Gootkit 43.239.221.51:80
2016-11-01 10:54:541053301dc05904bef497a69166fe9643Virustotal results 41/57 (71.93%) Gootkit 43.239.221.51:80
2016-11-01 09:59:012f330019a1d637155b7ccf99ab126df8Virustotal results 37/57 (64.91%) Gootkit 43.239.221.51:80
2016-10-31 11:59:45b866e139c5d08977422203b3ff97af50Virustotal results 31/57 (54.39%) Gootkit 43.239.221.51:80
2016-10-30 23:03:44e813eeb707f13725bb881880df797a40n/aGootkit 43.239.221.51:80
2016-10-30 07:20:36f3e6c6c03c352b282b1fd4388a33e981Virustotal results 43/57 (75.44%) Gootkit 43.239.221.51:80
2016-10-28 15:52:232acb0e4daebd077e3e228bec6ae6b1feVirustotal results 42/64 (65.62%) Gootkit 43.239.221.51:80
2016-10-28 12:51:034d80be2d296101359bac4302fb507738Virustotal results 32/54 (59.26%) Gootkit 43.239.221.51:80
2016-10-28 09:47:416cade1c992f5c0bf36eb398be75e7bb2Virustotal results 29/57 (50.88%) Gootkit 43.239.221.51:80
2016-10-27 18:12:31000e9d57443e37b285efe175bdc92fadVirustotal results 25/57 (43.86%) Gootkit 43.239.221.51:80
2016-10-27 11:18:57b14433591a43b650983ce08d11f6b58fVirustotal results 39/57 (68.42%) Gootkit 43.239.221.51:80
2016-10-26 22:40:43d22077c4b1bde37ea419387be922b7f0n/aGootkit 43.239.221.51:80
2016-10-26 13:07:329454e1f0c44e424c0a09dcbee75fea31Virustotal results 35/57 (61.40%) Gootkit 43.239.221.51:80
2016-10-26 10:39:30093f1611a1c238ffc4ff770f08426626Virustotal results 41/57 (71.93%) Gootkit 43.239.221.51:80
2016-10-25 18:42:08ac3059902c011e9d0a29229880fe2717Virustotal results 35/57 (61.40%) Shylock 43.239.221.51:80
2016-10-25 18:14:0327fd7bda3b006c671bf78bfde4e87c5fVirustotal results 32/56 (57.14%) Shylock 43.239.221.51:80
2016-10-25 14:20:5711d8cfea37cd341acb6518bdfccaaaeeVirustotal results 32/56 (57.14%) Gootkit 43.239.221.51:80
2016-10-24 19:13:16bd2bc96b7f3c5c3828532bddce72cbd4Virustotal results 34/55 (61.82%) Shylock 43.239.221.51:80
2016-10-24 13:08:36e9ff9825c7e4241da51625a5f038a400n/aGootkit 43.239.221.51:80
2016-10-24 02:13:264dd2be3ee3b147263e9e27422b2b0cc1n/aGootkit 43.239.221.51:80
2016-10-23 08:54:51c8cb810f5f4ffef9b4ba4a733a721f1dn/aGootkit 43.239.221.51:80
2016-10-23 01:29:439952145114717bbbaac95e3f2bce3afen/aGootkit 43.239.221.51:80
2016-10-23 00:36:50f752bd3ece31368663bf11621f96f4b0Virustotal results 32/57 (56.14%) Gootkit 43.239.221.51:80
2016-10-22 21:09:227325ab9ad5634c719a09355628a7c032Virustotal results 21/56 (37.50%) Gootkit 43.239.221.51:80
2016-10-20 20:35:37772f326649b5397ea1ad24e18fbcfd93Virustotal results 40/56 (71.43%) Shylock 43.239.221.51:80
2016-10-20 15:13:06b21d144898f35b1c6a520fda5c729296n/aGootkit 43.239.221.51:80
2016-10-19 16:12:100391838927ebb58e3648c1b64e98bd95Virustotal results 27/57 (47.37%) Gootkit 43.239.221.51:80
2016-10-19 12:37:13390cb47955e8a7e26a1d47783f6009cbn/aGootkit 43.239.221.51:80
2016-10-19 10:19:2886ae2130c3fd24f5991cb1f1e4d0a269Virustotal results 38/56 (67.86%) Shylock 43.239.221.51:80
2016-10-19 06:43:231ba21ad8b54fc2d0e59c5e4e4750e58dVirustotal results 34/56 (60.71%) Shylock 43.239.221.51:80
2016-10-19 03:49:539f16a3f7db099e16359c69ffc6d4e068n/aGootkit 43.239.221.51:80
2016-10-18 13:16:331a81b8ee537ed60665e7e52dbde6aba5n/aGootkit 43.239.221.51:80
2016-10-18 01:06:3616a4a718d01f2ed13494e4c5051487caVirustotal results 39/56 (69.64%) Shylock 43.239.221.51:80
2016-10-17 21:35:219fca7e2a4b5aceb50238cc62137b17b3Virustotal results 34/56 (60.71%) Shylock 43.239.221.51:80
2016-10-17 21:30:002313518ad5051873020b6653b6714f6bVirustotal results 33/57 (57.89%) Gootkit 43.239.221.51:80
2016-10-17 12:46:228badf651204735bed6ea302bbb86d59bn/aGootkit 43.239.221.51:80
2016-10-17 09:54:48ffa1d605aab55f7154399b4804b6e7e6n/aGootkit 43.239.221.51:80
2016-10-17 09:33:53f760f7cb847651f10f702bb8970c9688Virustotal results 30/57 (52.63%) Gootkit 43.239.221.51:80
2016-10-17 08:06:17daf4eb8b50ba5ddda000fea36fd2b1fcVirustotal results 36/56 (64.29%) 43.239.221.51:80
2016-10-16 21:22:0221f3b2ec4753d15248947f03986ed5a9Virustotal results 37/56 (66.07%) Gootkit 43.239.221.51:80
2016-10-16 18:44:08c63ad944c92ecf7b4dcc979df2a2c41aVirustotal results 32/57 (56.14%) Gootkit 43.239.221.51:80
2016-10-16 15:14:18c3cc57b1c11dc0ba43248402b4534980Virustotal results 30/56 (53.57%) Gootkit 43.239.221.51:80
2016-10-16 11:33:52562e8d177f16efaac3565689958a602en/aGootkit 43.239.221.51:80
2016-10-16 03:17:380286f1209cec72ea85cdd44fd63f8faan/aGootkit 43.239.221.51:80
2016-10-16 01:47:08b4921cd42669d1d066e3df5e5cb91505n/aGootkit 43.239.221.51:80
2016-10-15 13:30:31d4dcb7d70c195569ba584db5523e48e3Virustotal results 39/56 (69.64%) Shylock 43.239.221.51:80
2016-10-15 12:16:37cedb9c99053c3b72d8e121e232bf0d84Virustotal results 35/57 (61.40%) Gootkit 43.239.221.51:80
2016-10-15 07:32:05a3e9449a2661dcec68ed0adc86e720acVirustotal results 38/56 (67.86%) Gootkit 43.239.221.51:80
2016-10-13 06:28:3806ddfc185d80a5dcfe77bec50de298a7n/aGootkit 43.239.221.51:80
2016-10-13 02:14:042f06b56b97ede4c332db48b3b81ca3ecVirustotal results 34/56 (60.71%) Shylock 43.239.221.51:80
2016-10-12 16:51:059b8ffec2eb899a6d7b15750e7f4489een/aGootkit 43.239.221.51:80
2016-10-12 16:42:101a773428bfe1ce4c6475a21ea112ef40n/aGootkit 43.239.221.51:80
2016-10-12 12:54:210d1d0dbfb138ebd3f303747aed2e7aa7Virustotal results 36/56 (64.29%) Gootkit 43.239.221.51:80
2016-10-12 05:24:469eec81aa6282121177debfacf2b997c0n/aGootkit 43.239.221.51:80
2016-10-12 00:03:52140c4185b3df378c43af15b8b0bb6fceVirustotal results 36/56 (64.29%) 43.239.221.51:80
2016-10-11 09:19:33c217c79eaed59aa85a5c8ec50bf77312Virustotal results 31/56 (55.36%) Gootkit 43.239.221.51:80
2016-10-10 21:52:051fc96ee45979d396769a16692f624592Virustotal results 32/57 (56.14%) Gootkit 43.239.221.51:80
2016-10-10 20:29:4769558c602511ec2088548687b72b4e44Virustotal results 30/56 (53.57%) Shylock 43.239.221.51:80
2016-10-10 18:11:03822868f0e289dea0a1a911292268b26aVirustotal results 38/57 (66.67%) Gootkit 43.239.221.51:80
2016-10-10 17:31:1036d3070b7273b79dc161ace8a5150fbaVirustotal results 41/57 (71.93%) Shylock 43.239.221.51:80
2016-10-10 16:18:227e7cedbe4929a816f5069591be5577d6n/aShylock 43.239.221.51:80
2016-10-08 12:13:46b54c6c8ba2e64f88525f327acd85c44fVirustotal results 27/57 (47.37%) Gootkit 43.239.221.51:80
2016-10-08 02:18:589143f01d9b913add071962090a888b24Virustotal results 37/56 (66.07%) Shylock 43.239.221.51:80
2016-10-07 11:04:07b1ce7be178c2d91e41d997e0b21a5846Virustotal results 34/55 (61.82%) Shylock 43.239.221.51:80
2016-10-05 12:56:34de15305010152ca5a773eaf3b845a28cVirustotal results 29/56 (51.79%) Shylock 43.239.221.51:80
2016-10-05 09:11:4691d6435fe45835e093c21df7dd1b5fa3Virustotal results 38/57 (66.67%) Shylock 43.239.221.51:80
2016-10-04 16:36:37d143e2a62b2e5b3a8e5fda78a9f40dd9n/aShylock 43.239.221.51:80
2016-10-04 02:36:31605be4923fb8772a9a98cd61c62a3b34n/aShylock 43.239.221.51:80
2016-10-03 16:18:425f7f745af08c7da479bf46a99c133d93Virustotal results 37/57 (64.91%) Shylock 43.239.221.51:80
2016-10-03 04:28:35d0115166aa65e77d7a8422be09b36533n/aShylock 43.239.221.51:80

# of entries: 100 (max: 100)