SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint b0238c547a905bfa119c4e8baccaeacf36491ff6.

Database Entry


SHA1 Fingerprint:b0238c547a905bfa119c4e8baccaeacf36491ff6
Certificate Common Name (CN):localhost
Issuer Distinguished Name (DN):localhost
TLS Version:TLS 1.2
First seen:2016-07-04 19:13:58 UTC
Last seen:2021-06-17 15:45:37 UTC
Status:Blacklisted
Listing reason:Ransomware C&C
Listing date:2016-10-26 14:33:52
Malware samples:103
Botnet C&Cs:42

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2021-06-17 15:45:37165df5dfd7f64e69df2b7edc556317dbVirustotal results 5 / 62 (8.06%) 103.140.251.225:443
2021-06-17 15:45:37165df5dfd7f64e69df2b7edc556317dbVirustotal results 5 / 62 (8.06%) 103.140.251.225:443
2021-04-26 08:11:340de7b538585d05e895aa4f15cc83f874Virustotal results 21 / 71 (29.58%) TrickBot 149.56.80.31:443
2021-04-26 08:11:340de7b538585d05e895aa4f15cc83f874Virustotal results 21 / 71 (29.58%) TrickBot 149.56.80.31:443
2021-04-26 08:11:340de7b538585d05e895aa4f15cc83f874Virustotal results 21 / 71 (29.58%) TrickBot 149.56.80.31:443
2021-04-26 08:11:340de7b538585d05e895aa4f15cc83f874Virustotal results 21 / 71 (29.58%) TrickBot 149.56.80.31:443
2021-04-22 17:09:200247222caf3b70431bb17ed46bf2cf94Virustotal results 47 / 66 (71.21%) 149.56.80.31:443
2021-04-22 17:09:200247222caf3b70431bb17ed46bf2cf94Virustotal results 47 / 66 (71.21%) 149.56.80.31:443
2021-03-20 23:10:4353220b6a8f6519ef3c69dcfda29edf65Virustotal results 35 / 71 (49.30%) 103.233.195.64:443
2021-03-20 23:10:4353220b6a8f6519ef3c69dcfda29edf65Virustotal results 35 / 71 (49.30%) 103.233.195.64:443
2021-03-08 06:04:36cb0fed54e34f1602e3c14f5bfc02bf8eVirustotal results 44 / 70 (62.86%) 149.56.80.31:443
2021-03-08 06:04:36cb0fed54e34f1602e3c14f5bfc02bf8eVirustotal results 44 / 70 (62.86%) 149.56.80.31:443
2021-02-14 21:31:1096875c53a3ec4ddbe5a37febcc8a75caVirustotal results 54 / 70 (77.14%) TrickBot 54.39.167.242:443
2021-02-14 21:31:1096875c53a3ec4ddbe5a37febcc8a75caVirustotal results 54 / 70 (77.14%) TrickBot 54.39.167.242:443
2021-02-14 21:31:1096875c53a3ec4ddbe5a37febcc8a75caVirustotal results 54 / 70 (77.14%) TrickBot 54.39.167.242:443
2021-02-14 21:31:1096875c53a3ec4ddbe5a37febcc8a75caVirustotal results 54 / 70 (77.14%) TrickBot 54.39.167.242:443
2021-02-11 01:38:0280c2b23fd18283960097322d145537caVirustotal results 2 / 68 (2.94%) 145.239.145.114:443
2021-02-11 01:38:0280c2b23fd18283960097322d145537caVirustotal results 2 / 68 (2.94%) 145.239.145.114:443
2021-01-27 16:00:00c08e3f082b40fee8f50a5de73f85ccf7Virustotal results 32 / 71 (45.07%) 5.189.166.237:443
2021-01-27 16:00:00c08e3f082b40fee8f50a5de73f85ccf7Virustotal results 32 / 71 (45.07%) 5.189.166.237:443
2020-11-14 17:31:33f127d3fdc71bf788886e77cfa293311bVirustotal results 10 / 72 (13.89%) 37.59.47.123:443
2020-11-14 17:31:33f127d3fdc71bf788886e77cfa293311bVirustotal results 10 / 72 (13.89%) 37.59.47.123:443
2020-11-10 13:23:19ea2f8a2e81f7ae986be9f2d76923ec7bVirustotal results 15 / 66 (22.73%) 172.245.26.140:443
2020-11-10 13:23:19ea2f8a2e81f7ae986be9f2d76923ec7bVirustotal results 15 / 66 (22.73%) 172.245.26.140:443
2020-11-06 14:46:02ff259efa41b897626ccc4f3f21091a84Virustotal results 41 / 70 (58.57%) BazaLoader185.118.167.189:443
2020-11-06 14:46:02ff259efa41b897626ccc4f3f21091a84Virustotal results 41 / 70 (58.57%) BazaLoader185.118.167.189:443
2020-11-03 06:46:42d8593a2bdba4e643f50b9bf425cc5bd8Virustotal results 54 / 71 (76.06%) BazaLoader185.118.167.189:443
2020-11-03 06:46:42d8593a2bdba4e643f50b9bf425cc5bd8Virustotal results 54 / 71 (76.06%) BazaLoader185.118.167.189:443
2020-11-03 05:34:29c86d167eba34f2e3dc1e29aeea07d100Virustotal results 47 / 70 (67.14%) BazaLoader185.118.167.189:443
2020-11-03 05:34:29c86d167eba34f2e3dc1e29aeea07d100Virustotal results 47 / 70 (67.14%) BazaLoader185.118.167.189:443
2020-11-02 04:39:300cd3b3d01cd19eae7c28bff2cce4d96cVirustotal results 48 / 70 (68.57%) BazaLoader185.118.167.189:443
2020-11-02 04:39:300cd3b3d01cd19eae7c28bff2cce4d96cVirustotal results 48 / 70 (68.57%) BazaLoader185.118.167.189:443
2020-11-02 02:46:3823845d9ac32b37f56081a549905dc973Virustotal results 41 / 70 (58.57%) BazaLoader185.118.167.189:443
2020-11-02 02:46:3823845d9ac32b37f56081a549905dc973Virustotal results 41 / 70 (58.57%) BazaLoader185.118.167.189:443
2020-11-01 23:01:488065bb65d7a7a02726666c8184b5d091Virustotal results 47 / 70 (67.14%) BazaLoader185.118.167.189:443
2020-11-01 23:01:488065bb65d7a7a02726666c8184b5d091Virustotal results 47 / 70 (67.14%) BazaLoader185.118.167.189:443
2020-11-01 22:30:3174b2e8a039ec4f91ee2a55e82bbb2999Virustotal results 52 / 69 (75.36%) BazaLoader185.118.167.189:443
2020-11-01 22:30:3174b2e8a039ec4f91ee2a55e82bbb2999Virustotal results 52 / 69 (75.36%) BazaLoader185.118.167.189:443
2020-11-01 22:22:1477255c49333da1cbef5670e98ce7be29Virustotal results 46 / 70 (65.71%) BazaLoader185.118.167.189:443
2020-11-01 22:22:1477255c49333da1cbef5670e98ce7be29Virustotal results 46 / 70 (65.71%) BazaLoader185.118.167.189:443
2020-11-01 21:30:173b6e0e6381f67918db203d313c3430e5Virustotal results 49 / 70 (70.00%) BazaLoader185.118.167.189:443
2020-11-01 21:30:173b6e0e6381f67918db203d313c3430e5Virustotal results 49 / 70 (70.00%) BazaLoader185.118.167.189:443
2020-11-01 20:44:404094c6694c86a9738a70d4f2a0d6e1aeVirustotal results 52 / 71 (73.24%) BazaLoader185.118.167.189:443
2020-11-01 20:44:404094c6694c86a9738a70d4f2a0d6e1aeVirustotal results 52 / 71 (73.24%) BazaLoader185.118.167.189:443
2020-11-01 20:35:493d1e41ee43a9f7e31819fce0007c2963Virustotal results 44 / 62 (70.97%) BazaLoader185.118.167.189:443
2020-11-01 20:35:493d1e41ee43a9f7e31819fce0007c2963Virustotal results 44 / 62 (70.97%) BazaLoader185.118.167.189:443
2020-10-26 14:55:08df89baf262a62664f8b58ef26e39a062Virustotal results 52 / 69 (75.36%) BazaLoader185.118.167.189:443
2020-10-26 14:55:08df89baf262a62664f8b58ef26e39a062Virustotal results 52 / 69 (75.36%) BazaLoader185.118.167.189:443
2020-10-26 10:01:58bcbb5e2efd96ccde7757acaf4f2a31c9Virustotal results 45 / 70 (64.29%) BazaLoader185.118.167.189:443
2020-10-26 10:01:58bcbb5e2efd96ccde7757acaf4f2a31c9Virustotal results 45 / 70 (64.29%) BazaLoader185.118.167.189:443
2020-10-25 00:37:16995260b6786c52f5a93fc2fecdaa3e1bVirustotal results 41 / 70 (58.57%) BazaLoader185.118.167.189:443
2020-10-25 00:37:16995260b6786c52f5a93fc2fecdaa3e1bVirustotal results 41 / 70 (58.57%) BazaLoader185.118.167.189:443
2020-10-24 22:26:47686577abca2d4aa59205c2d5ad189580Virustotal results 45 / 71 (63.38%) BazaLoader185.118.167.189:443
2020-10-24 22:26:47686577abca2d4aa59205c2d5ad189580Virustotal results 45 / 71 (63.38%) BazaLoader185.118.167.189:443
2020-10-23 11:53:24671d14fd2812cb1fa7fab098ae758e85Virustotal results 1 / 69 (1.45%) 207.148.116.8:443
2020-10-23 11:53:24671d14fd2812cb1fa7fab098ae758e85Virustotal results 1 / 69 (1.45%) 207.148.116.8:443
2020-10-23 08:40:010e386eb69c39e6c51f51ab89961d563eVirustotal results 1 / 68 (1.47%) 207.148.116.8:443
2020-10-23 08:40:010e386eb69c39e6c51f51ab89961d563eVirustotal results 1 / 68 (1.47%) 207.148.116.8:443
2020-10-14 02:05:533c402d47c180c611bac1965a10330477Virustotal results 43 / 69 (62.32%) 103.27.237.75:443
2020-10-14 02:05:533c402d47c180c611bac1965a10330477Virustotal results 43 / 69 (62.32%) 103.27.237.75:443
2020-03-29 23:22:03789ee1e30169a35d0018f07323e694c4Virustotal results 45 / 73 (61.64%) Heodo78.108.185.203:443
2020-03-29 23:22:03789ee1e30169a35d0018f07323e694c4Virustotal results 45 / 73 (61.64%) Heodo78.108.185.203:443
2020-03-26 05:32:39b507995924c8df6ed515ebc1bb80dd00Virustotal results 45 / 72 (62.50%) 5.188.9.76:443
2020-03-26 05:32:39b507995924c8df6ed515ebc1bb80dd00Virustotal results 45 / 72 (62.50%) 5.188.9.76:443
2020-03-04 19:09:22291dd7d9a2062d07976b14f7d9683d35Virustotal results 32 / 72 (44.44%) 176.31.88.148:443
2020-03-04 19:09:22291dd7d9a2062d07976b14f7d9683d35Virustotal results 32 / 72 (44.44%) 176.31.88.148:443
2019-11-15 04:40:51efb5e2ad402a867e458bc693b854547bVirustotal results 51/69 (73.91%) Kovter185.113.141.120:443
2019-11-15 04:40:51efb5e2ad402a867e458bc693b854547bVirustotal results 51/69 (73.91%) Kovter185.113.141.120:443
2019-05-11 13:35:392642a25208ab587aca2b2b4166229b61Virustotal results 25/72 (34.72%) 202.95.13.9:443
2019-05-11 13:35:392642a25208ab587aca2b2b4166229b61Virustotal results 25/72 (34.72%) 202.95.13.9:443
2017-07-25 19:07:27a2c5517ee2de9010ec1983f15c9e17d5Virustotal results 23/64 (35.94%) 94.74.81.176:443
2017-07-25 19:07:27a2c5517ee2de9010ec1983f15c9e17d5Virustotal results 23/64 (35.94%) 94.74.81.176:443
2017-07-24 10:01:58c98b1036e27dbe03432e1000308be37fVirustotal results 41/63 (65.08%) 94.74.81.176:443
2017-07-24 10:01:58c98b1036e27dbe03432e1000308be37fVirustotal results 41/63 (65.08%) 94.74.81.176:443
2017-07-22 13:36:59a0547d978195c98c5f2d170d63da3d22Virustotal results 29/63 (46.03%) 94.74.81.176:443
2017-07-22 13:36:59a0547d978195c98c5f2d170d63da3d22Virustotal results 29/63 (46.03%) 94.74.81.176:443
2017-07-22 04:49:36a041dbe602909fb8c3f3c51ddad133d1Virustotal results 33/64 (51.56%) 94.74.81.176:443
2017-07-22 04:49:36a041dbe602909fb8c3f3c51ddad133d1Virustotal results 33/64 (51.56%) 94.74.81.176:443
2017-07-21 20:19:59a268eea61e62d3b9b3608acde690dad7Virustotal results 30/63 (47.62%) 94.74.81.176:443
2017-07-21 20:19:59a268eea61e62d3b9b3608acde690dad7Virustotal results 30/63 (47.62%) 94.74.81.176:443
2017-07-21 10:31:20889ae2230ecdeae7a317d078129b6b26Virustotal results 22/63 (34.92%) 94.74.81.176:443
2017-07-21 10:31:20889ae2230ecdeae7a317d078129b6b26Virustotal results 22/63 (34.92%) 94.74.81.176:443
2017-07-21 09:44:0287db5b35f84cd5ff12d2aa66de5d4ec2Virustotal results 19/64 (29.69%) 94.74.81.176:443
2017-07-21 09:44:0287db5b35f84cd5ff12d2aa66de5d4ec2Virustotal results 19/64 (29.69%) 94.74.81.176:443
2017-07-21 09:01:249c16de2e6d44e4d211b575dafc54dea5Virustotal results 24/64 (37.50%) 94.74.81.176:443
2017-07-21 09:01:249c16de2e6d44e4d211b575dafc54dea5Virustotal results 24/64 (37.50%) 94.74.81.176:443
2017-07-21 06:02:13030430533c5df422a6844b38088d530aVirustotal results 30/63 (47.62%) 94.74.81.176:443
2017-07-21 06:02:13030430533c5df422a6844b38088d530aVirustotal results 30/63 (47.62%) 94.74.81.176:443
2017-07-21 04:12:06d985ac474cb3e74c36dbb72832414820Virustotal results 17/63 (26.98%) 94.74.81.176:443
2017-07-21 04:12:06d985ac474cb3e74c36dbb72832414820Virustotal results 17/63 (26.98%) 94.74.81.176:443
2017-07-21 03:11:54c9e0b83a0614feb7c9920577e0ae5003Virustotal results 21/64 (32.81%) 94.74.81.176:443
2017-07-21 03:11:54c9e0b83a0614feb7c9920577e0ae5003Virustotal results 21/64 (32.81%) 94.74.81.176:443
2017-07-20 22:56:165a1454fec57ab855a88b7ee79d6c07b9Virustotal results 22/64 (34.38%) 94.74.81.176:443
2017-07-20 22:56:165a1454fec57ab855a88b7ee79d6c07b9Virustotal results 22/64 (34.38%) 94.74.81.176:443
2017-07-20 22:55:23cfa4088a6328ee705d140729e86942f4Virustotal results 21/64 (32.81%) 94.74.81.176:443
2017-07-20 22:55:23cfa4088a6328ee705d140729e86942f4Virustotal results 21/64 (32.81%) 94.74.81.176:443
2017-07-20 20:16:50e9fc83a24000229c0e603d0df288abebVirustotal results 30/64 (46.88%) 94.74.81.176:443
2017-07-20 20:16:50e9fc83a24000229c0e603d0df288abebVirustotal results 30/64 (46.88%) 94.74.81.176:443
2017-07-20 20:08:23cd3b3c01b5905a0c537663ea0c73044fVirustotal results 22/64 (34.38%) 94.74.81.176:443
2017-07-20 20:08:23cd3b3c01b5905a0c537663ea0c73044fVirustotal results 22/64 (34.38%) 94.74.81.176:443

# of entries: 100 (max: 100)