SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 9a044753daa1d6856d7dcc1d2942a114921b6c74.

Database Entry


SHA1 Fingerprint:9a044753daa1d6856d7dcc1d2942a114921b6c74
Certificate Common Name (CN):localhost
Issuer Distinguished Name (DN):localhost
TLS Version:SSLv3
First seen:2014-05-23 07:00:30 UTC
Last seen:2014-05-26 03:43:46 UTC
Status:Blacklisted
Listing reason:Shylock C&C
Listing date:2014-05-24 17:25:35
Malware samples:3
Botnet C&Cs:1

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2014-05-26 03:43:46ee5ece1e524749261c24c4cc13f50fa8Virustotal results 21/51 (41.18%) 91.210.189.118:443
2014-05-26 03:43:46ee5ece1e524749261c24c4cc13f50fa8Virustotal results 21/51 (41.18%) 91.210.189.118:443
2014-05-24 13:02:2518e81e59b71cb2de95cdaac68802f5acVirustotal results 31/53 (58.49%) 91.210.189.118:443
2014-05-24 13:02:2518e81e59b71cb2de95cdaac68802f5acVirustotal results 31/53 (58.49%) 91.210.189.118:443
2014-05-23 07:00:3092fe02e7ca059f70a0d29396146364bdVirustotal results 14/51 (27.45%) 91.210.189.118:443
2014-05-23 07:00:3092fe02e7ca059f70a0d29396146364bdVirustotal results 14/51 (27.45%) 91.210.189.118:443

# of entries: 6 (max: 100)