SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 5f66d8e91102fc2e03d55f90bd6f598b123d0aa7.

Database Entry


SHA1 Fingerprint:5f66d8e91102fc2e03d55f90bd6f598b123d0aa7
Certificate Common Name (CN):localhost
Issuer Distinguished Name (DN):localhost
TLS Version:TLSv1
First seen:2015-09-01 09:31:49 UTC
Last seen:2015-09-09 05:54:22 UTC
Status:Blacklisted
Listing reason:KINS C&C
Listing date:2015-09-01 10:09:48
Malware samples:5
Botnet C&Cs:1

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2015-09-09 05:54:2277a29d639b15e5b47d0ff23c40f81c5bVirustotal results 16/57 (28.07%) ZeuS 111.118.187.81:443
2015-09-08 18:26:5657c470cfaff4349a080580bd95d1b221Virustotal results 36/57 (63.16%) ZeuS 111.118.187.81:443
2015-09-08 11:35:39037f1de70058317a959be7bee0beefc8Virustotal results 8/55 (14.55%) ZeuS 111.118.187.81:443
2015-09-04 06:57:53303ef467ddc88e419dfe924f649b870bVirustotal results 16/56 (28.57%) VMZeuS111.118.187.81:443
2015-09-01 09:31:497b8cb5f4197785991fdc968d75b51f77Virustotal results 35/57 (61.40%) ZeuS 111.118.187.81:443

# of entries: 5 (max: 100)