SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint b0238c547a905bfa119c4e8baccaeacf36491ff6.

Database Entry


SHA1 Fingerprint:b0238c547a905bfa119c4e8baccaeacf36491ff6
Certificate Common Name (CN):localhost
Issuer Distinguished Name (DN):localhost
TLS Version:TLS 1.2
First seen:2016-07-04 19:13:58 UTC
Last seen:2017-07-25 19:07:27 UTC
Status:Blacklisted
Listing reason:Ransomware C&C
Listing date:2016-10-26 14:33:52
Malware samples:70
Botnet C&Cs:26

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2017-07-25 19:07:27a2c5517ee2de9010ec1983f15c9e17d5Virustotal results 23/64 (35.94%) 94.74.81.176:443
2017-07-24 10:01:58c98b1036e27dbe03432e1000308be37fVirustotal results 41/63 (65.08%) 94.74.81.176:443
2017-07-22 13:36:59a0547d978195c98c5f2d170d63da3d22Virustotal results 29/63 (46.03%) 94.74.81.176:443
2017-07-22 04:49:36a041dbe602909fb8c3f3c51ddad133d1Virustotal results 33/64 (51.56%) 94.74.81.176:443
2017-07-21 20:19:59a268eea61e62d3b9b3608acde690dad7Virustotal results 30/63 (47.62%) 94.74.81.176:443
2017-07-21 10:31:20889ae2230ecdeae7a317d078129b6b26Virustotal results 22/63 (34.92%) 94.74.81.176:443
2017-07-21 09:44:0287db5b35f84cd5ff12d2aa66de5d4ec2Virustotal results 19/64 (29.69%) 94.74.81.176:443
2017-07-21 09:01:249c16de2e6d44e4d211b575dafc54dea5Virustotal results 24/64 (37.50%) 94.74.81.176:443
2017-07-21 06:02:13030430533c5df422a6844b38088d530aVirustotal results 30/63 (47.62%) 94.74.81.176:443
2017-07-21 04:12:06d985ac474cb3e74c36dbb72832414820Virustotal results 17/63 (26.98%) 94.74.81.176:443
2017-07-21 03:11:54c9e0b83a0614feb7c9920577e0ae5003Virustotal results 21/64 (32.81%) 94.74.81.176:443
2017-07-20 22:56:165a1454fec57ab855a88b7ee79d6c07b9Virustotal results 22/64 (34.38%) 94.74.81.176:443
2017-07-20 22:55:23cfa4088a6328ee705d140729e86942f4Virustotal results 21/64 (32.81%) 94.74.81.176:443
2017-07-20 20:16:50e9fc83a24000229c0e603d0df288abebVirustotal results 30/64 (46.88%) 94.74.81.176:443
2017-07-20 20:08:23cd3b3c01b5905a0c537663ea0c73044fVirustotal results 22/64 (34.38%) 94.74.81.176:443
2017-07-20 19:27:50e6fbb44a375a2a7f8ea89c6d09f41522Virustotal results 22/61 (36.07%) 94.74.81.176:443
2017-07-20 18:23:04f9564741945f25bb3597ee82ebbdb656Virustotal results 22/64 (34.38%) 94.74.81.176:443
2017-07-20 18:11:158ac2ad7245f75c7d48545c66335e142eVirustotal results 10/64 (15.62%) 94.74.81.176:443
2017-07-20 09:50:513973264c3f3169c015603be2c0800326Virustotal results 15/64 (23.44%) 94.74.81.176:443
2017-07-20 09:10:5157d067e01f318e13b4447b7b68e7ecd9Virustotal results 22/64 (34.38%) 94.74.81.176:443
2017-07-20 08:41:28577a1ae25a5883195384a05c423b22e4Virustotal results 25/64 (39.06%) 94.74.81.176:443
2017-07-20 06:19:0584e50fcf8e86381a3ff49e43eb4e6171Virustotal results 23/64 (35.94%) 94.74.81.176:443
2017-07-19 20:49:44b6c3c9089807dc6d4e0ea2cad96c3e6bVirustotal results 28/63 (44.44%) 94.74.81.176:443
2017-07-19 19:42:05ad3e5bc7432efee11a81d4455f462653Virustotal results 25/64 (39.06%) 94.74.81.176:443
2017-07-19 19:28:484626321d56b8722ac5ab4af641cc084fVirustotal results 21/64 (32.81%) 94.74.81.176:443
2017-06-11 03:13:1487e990bdf077ec0c241ac71f326e1be0n/aKovter121.41.25.162:443
2017-03-31 01:02:3577cc4864cc8331ca37becac10fff0cben/aKovter202.195.246.3:443
2017-03-17 06:38:5407aeb4d8a227b93e08edb59deca57c1aVirustotal results 40/61 (65.57%) Kovter104.207.153.107:443
2017-03-06 01:03:257b5fc10a51f50d06bdea8eb1fc4b71b2Virustotal results 41/59 (69.49%) Kovter89.242.200.242:443
2017-03-05 15:52:121377a2f31c7717a2aa608b955c911b25n/aKovter139.129.250.122:443
2017-03-05 04:26:382100c2ab4673d51efea1ee47ec79c61eVirustotal results 39/59 (66.10%) Kovter45.74.41.34:443
2017-03-04 12:00:486ea8a503955419736b7f350aa653598cVirustotal results 39/59 (66.10%) Kovter120.24.84.63:443
2017-03-03 07:11:47e0251579455094942d182c8e25c25b2eVirustotal results 39/59 (66.10%) Kovter150.31.38.94:443
2017-03-03 00:12:57ab13d084345aab0e499d62fef82affa0Virustotal results 39/59 (66.10%) Kovter182.18.152.103:443
2017-03-01 17:12:56a00aca94936621cf0904b2230f8b1756Virustotal results 25/58 (43.10%) Kovter104.207.153.107:443
2017-02-22 06:40:09324400516828d170ddc774f1dd06ab25Virustotal results 38/58 (65.52%) Kovter217.13.119.81:443
2017-02-22 05:12:1057dcaa977ee40ade0f5cab4d86972234Virustotal results 43/59 (72.88%) Kovter179.49.120.5:443
2017-02-13 19:49:51099795b905c7249fa7a5335360afd129Virustotal results 5/57 (8.77%) 136.243.87.113:443
2017-02-09 09:22:20aa169698c650e49a3e30065380f1af15n/aKovter101.201.67.82:443
2017-02-07 02:05:5161fb3b74921f733df0b1e4201e1ea3d8n/aKovter103.17.72.238:443
2017-01-29 02:31:11f06e11bf639790610da880a38f83c356Virustotal results 39/57 (68.42%) Kovter144.76.2.182:443
2017-01-26 08:34:4717ec2a5489fbb1ead4b6e6174af794f4n/aKovter114.215.223.85:443
2017-01-21 13:36:564970e871b794bbe69ad3c90dc8af22b5n/aKovter46.72.12.164:443
2017-01-16 14:57:19f8e5e92f8b35546dfd87e79ea67f4d49n/aKovter81.147.99.122:443
2016-12-25 18:28:457fbd3a25c57964ab22a558ffb8bdd333n/aKovter93.132.4.208:443
2016-12-16 09:45:55d8112ccf8dfd9e486dd6e42a709215a1Virustotal results 36/57 (63.16%) Kovter83.54.108.164:443
2016-12-14 18:46:54f55ff034c5a3e53086143eb842c42e07Virustotal results 42/55 (76.36%) Kovter90.63.214.213:443
2016-12-05 11:52:33fc8ff575b95be170026fdf1bc01bfcc1n/aKovter144.217.47.3:443
2016-11-24 21:41:02c9ff989e953a10f94c67004b329d95ebVirustotal results 7/57 (12.28%) 185.62.189.83:443
2016-10-12 17:15:11ce8b53fd521b9135afd8f1f156a3fc1dVirustotal results 33/56 (58.93%) 141.10.91.35:443
2016-10-07 12:33:4684bb84c1dbdaab383947ce2ede0c8154Virustotal results 25/57 (43.86%) Ransomware95.46.99.21:443
2016-10-01 14:12:5759c79a399dfabacc293a197dca48c1e4Virustotal results 20/57 (35.09%) Ransomware95.46.99.21:443
2016-09-27 20:49:2630a5b061329c3e8760d7309299a011bcVirustotal results 19/57 (33.33%) Ransomware95.46.99.21:443
2016-09-26 17:14:5760dfd08f82dee2a33604271f08f62734Virustotal results 30/57 (52.63%) Ransomware95.46.99.21:443
2016-09-24 12:14:1122d2aa61aa9eb859d10708703ddb8353Virustotal results 23/57 (40.35%) Ransomware95.46.99.21:443
2016-09-24 01:59:39c641e71562634c9fc95e7e9af20aa8c4Virustotal results 22/57 (38.60%) Ransomware95.46.99.21:443
2016-09-23 15:25:34f50a639b41e6a6bd838e0d9d62e760bfVirustotal results 32/57 (56.14%) Ransomware95.46.99.21:443
2016-09-23 13:19:4815caa32d2460262a5a204572f97b551fVirustotal results 24/57 (42.11%) Ransomware95.46.99.21:443
2016-09-21 14:31:229eebb265f952b710042b211eb080e342Virustotal results 34/57 (59.65%) Ransomware95.46.99.21:443
2016-09-20 23:58:3334e03f9094e72ca9e02c941495e8717fVirustotal results 31/57 (54.39%) Ransomware95.46.99.21:443
2016-09-20 22:40:05600d6ca170a56515e68f6552f141ed45Virustotal results 12/58 (20.69%) Ransomware95.46.99.21:443
2016-09-20 05:13:58bbbf7c20eeea79b164264658c52b5b02Virustotal results 9/57 (15.79%) Ransomware95.46.99.21:443
2016-09-19 19:04:03d0b3db501c70e42a771c42927c2a5850Virustotal results 9/57 (15.79%) Ransomware95.46.99.21:443
2016-09-15 14:47:21e50740c2a10e4f5334ecbd44b08054f6Virustotal results 14/58 (24.14%) Ransomware95.46.99.21:443
2016-09-15 02:02:43a927896b1763065cfd7a2d01b8f9b6cdVirustotal results 28/57 (49.12%) Ransomware95.46.99.21:443
2016-09-14 00:28:3870a3228c561b658b7f77113d0db7126fVirustotal results 24/57 (42.11%) Ransomware95.46.99.21:443
2016-09-10 11:23:430010a8a93f0074262227a16dc0d7b7ebVirustotal results 35/54 (64.81%) 141.10.91.35:443
2016-09-08 19:13:1053ca6c89af8103268d0b7a7f559e555cVirustotal results 12/57 (21.05%) Ransomware95.46.99.21:443
2016-07-05 19:05:10fdd88f4316bf2e9cd8cada5098e0f3c7Virustotal results 34/56 (60.71%) Ixeshe141.10.91.35:443
2016-07-04 19:13:58e58d61194388d2f467f3e47d71ffb364Virustotal results 30/56 (53.57%) Ixeshe141.10.91.35:443

# of entries: 70 (max: 100)