SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 9d283f393effdcaffb1a651fd1bbdc3c43b544eb.

Database Entry


SHA1 Fingerprint:9d283f393effdcaffb1a651fd1bbdc3c43b544eb
Certificate Common Name (CN):localhost
Issuer Distinguished Name (DN):localhost
TLS Version:SSLv3
First seen:2014-05-30 08:56:04 UTC
Last seen:2014-06-07 15:18:41 UTC
Status:Blacklisted
Listing reason:Shylock C&C
Listing date:2014-05-30 08:56:46
Malware samples:5
Botnet C&Cs:1

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2014-06-07 15:18:411f171885e14e6a99bf32c499e1fad6dfVirustotal results 28/51 (54.90%) 89.39.83.153:443
2014-06-07 15:18:411f171885e14e6a99bf32c499e1fad6dfVirustotal results 28/51 (54.90%) 89.39.83.153:443
2014-05-30 15:31:42bea88203e16bb5b91b9c9312a2ff1fe9Virustotal results 33/51 (64.71%) Shylock 89.39.83.153:443
2014-05-30 15:31:42bea88203e16bb5b91b9c9312a2ff1fe9Virustotal results 33/51 (64.71%) Shylock 89.39.83.153:443
2014-05-30 11:32:2082895acda7101d5e8d083f7accf16396Virustotal results 2/51 (3.92%) Shylock 89.39.83.153:443
2014-05-30 11:32:2082895acda7101d5e8d083f7accf16396Virustotal results 2/51 (3.92%) Shylock 89.39.83.153:443
2014-05-30 11:30:1132c425097454b3f897f761069d73ab70Virustotal results 30/53 (56.60%) Shylock 89.39.83.153:443
2014-05-30 11:30:1132c425097454b3f897f761069d73ab70Virustotal results 30/53 (56.60%) Shylock 89.39.83.153:443
2014-05-30 08:56:045482528b08131ca6d5dc2d63dcf42714Virustotal results 28/53 (52.83%) Shylock 89.39.83.153:443
2014-05-30 08:56:045482528b08131ca6d5dc2d63dcf42714Virustotal results 28/53 (52.83%) Shylock 89.39.83.153:443

# of entries: 10 (max: 100)