SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint b11e5db4da0a1eb419ec3d14443b10616daa0233.

Database Entry


SHA1 Fingerprint:b11e5db4da0a1eb419ec3d14443b10616daa0233
Certificate Common Name (CN):localhost
Issuer Distinguished Name (DN):localhost
TLS Version:TLSv1
First seen:2016-05-06 10:29:06 UTC
Last seen:2016-07-17 14:03:01 UTC
Status:Blacklisted
Listing reason:Shylock C&C
Listing date:2016-05-17 14:48:39
Malware samples:107
Botnet C&Cs:1

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2016-07-17 14:03:01a82f8c331c146be1204ec3d6559559ffn/aShylock 182.23.64.182:80
2016-07-17 14:03:01a82f8c331c146be1204ec3d6559559ffn/aShylock 182.23.64.182:80
2016-07-17 07:16:33a12589aa541276920df09c8412d05a49Virustotal results 45/64 (70.31%) Shylock 182.23.64.182:80
2016-07-17 07:16:33a12589aa541276920df09c8412d05a49Virustotal results 45/64 (70.31%) Shylock 182.23.64.182:80
2016-07-16 08:04:00fcd1d5b9ffdaa5d07d3c742237e3dd9en/aShylock 182.23.64.182:80
2016-07-16 08:04:00fcd1d5b9ffdaa5d07d3c742237e3dd9en/aShylock 182.23.64.182:80
2016-07-16 07:34:287d1c89b6defff9956972379d0e2c57ean/aShylock 182.23.64.182:80
2016-07-16 07:34:287d1c89b6defff9956972379d0e2c57ean/aShylock 182.23.64.182:80
2016-07-15 23:50:03798853ead9bb0d5be4e277fbf8b20bf0n/aShylock 182.23.64.182:80
2016-07-15 23:50:03798853ead9bb0d5be4e277fbf8b20bf0n/aShylock 182.23.64.182:80
2016-07-15 18:16:5253592b6ca2d1d21075ba6795aef758d4n/aShylock 182.23.64.182:80
2016-07-15 18:16:5253592b6ca2d1d21075ba6795aef758d4n/aShylock 182.23.64.182:80
2016-07-15 18:12:2415366699c1ed224dc223d81d416cf6a2n/aShylock 182.23.64.182:80
2016-07-15 18:12:2415366699c1ed224dc223d81d416cf6a2n/aShylock 182.23.64.182:80
2016-07-15 17:58:16cc5a3bb6e6f22fa91418ad5c32daa787n/aShylock 182.23.64.182:80
2016-07-15 17:58:16cc5a3bb6e6f22fa91418ad5c32daa787n/aShylock 182.23.64.182:80
2016-07-15 16:56:30d9537e8bdfa2cea8858ff0d9a231258cn/aShylock 182.23.64.182:80
2016-07-15 16:56:30d9537e8bdfa2cea8858ff0d9a231258cn/aShylock 182.23.64.182:80
2016-07-15 15:49:0526fe94ee5424cf264b6b3b71147c22b7n/aShylock 182.23.64.182:80
2016-07-15 15:49:0526fe94ee5424cf264b6b3b71147c22b7n/aShylock 182.23.64.182:80
2016-07-15 09:50:59d13f10754ac9f0d1cef40063262898c1n/aGootkit 182.23.64.182:80
2016-07-15 09:50:59d13f10754ac9f0d1cef40063262898c1n/aGootkit 182.23.64.182:80
2016-07-15 03:11:16d9fb4cb2ca5a854f9aa49659922ae5f8n/aShylock 182.23.64.182:80
2016-07-15 03:11:16d9fb4cb2ca5a854f9aa49659922ae5f8n/aShylock 182.23.64.182:80
2016-07-15 03:06:3029e0c558b756f37fe5ffff687e8e80ebn/aShylock 182.23.64.182:80
2016-07-15 03:06:3029e0c558b756f37fe5ffff687e8e80ebn/aShylock 182.23.64.182:80
2016-07-15 01:44:4175bc09583b34920678a5021591afd848n/aGootkit 182.23.64.182:80
2016-07-15 01:44:4175bc09583b34920678a5021591afd848n/aGootkit 182.23.64.182:80
2016-07-13 20:47:05fda721d70b43dc8097a54a1f87dfc905n/aShylock 182.23.64.182:80
2016-07-13 20:47:05fda721d70b43dc8097a54a1f87dfc905n/aShylock 182.23.64.182:80
2016-07-12 20:05:364c053a3ae1561744c8502b99a250e9fcn/aGootkit 182.23.64.182:80
2016-07-12 20:05:364c053a3ae1561744c8502b99a250e9fcn/aGootkit 182.23.64.182:80
2016-07-11 17:30:46ac5c12e98f318f06641d08de56c03c80n/aShylock 182.23.64.182:80
2016-07-11 17:30:46ac5c12e98f318f06641d08de56c03c80n/aShylock 182.23.64.182:80
2016-07-11 16:10:34428438e6ef97c37c864e24d9a201f0c9n/aShylock 182.23.64.182:80
2016-07-11 16:10:34428438e6ef97c37c864e24d9a201f0c9n/aShylock 182.23.64.182:80
2016-07-11 00:00:257ca306d0bba6989d146dddecdba37cd4n/aShylock 182.23.64.182:80
2016-07-11 00:00:257ca306d0bba6989d146dddecdba37cd4n/aShylock 182.23.64.182:80
2016-07-10 18:44:071ef90a9093339e367ee047f22094c5een/aGootkit 182.23.64.182:80
2016-07-10 18:44:071ef90a9093339e367ee047f22094c5een/aGootkit 182.23.64.182:80
2016-07-09 21:13:29666136fbce0ae9f7900bf8c2325bdeb5Virustotal results 13/55 (23.64%) Shylock 182.23.64.182:80
2016-07-09 21:13:29666136fbce0ae9f7900bf8c2325bdeb5Virustotal results 13/55 (23.64%) Shylock 182.23.64.182:80
2016-07-09 20:35:22f307789a3f3d47137fffcb52b9fb78c3Virustotal results 5/54 (9.26%) Shylock 182.23.64.182:80
2016-07-09 20:35:22f307789a3f3d47137fffcb52b9fb78c3Virustotal results 5/54 (9.26%) Shylock 182.23.64.182:80
2016-07-09 18:56:0163551adfadf030e8685694008a6cb4ean/aShylock 182.23.64.182:80
2016-07-09 18:56:0163551adfadf030e8685694008a6cb4ean/aShylock 182.23.64.182:80
2016-07-09 00:47:377d3f194c36c2e0a8445686e60e3890fbn/aShylock 182.23.64.182:80
2016-07-09 00:47:377d3f194c36c2e0a8445686e60e3890fbn/aShylock 182.23.64.182:80
2016-07-09 00:24:3295cd84cc0b8789751a831ac0b38e34e4Virustotal results 39/56 (69.64%) Gootkit 182.23.64.182:80
2016-07-09 00:24:3295cd84cc0b8789751a831ac0b38e34e4Virustotal results 39/56 (69.64%) Gootkit 182.23.64.182:80
2016-07-08 17:24:37b85a700a096afd0e3628070f63df53b9Virustotal results 42/56 (75.00%) Shylock 182.23.64.182:80
2016-07-08 17:24:37b85a700a096afd0e3628070f63df53b9Virustotal results 42/56 (75.00%) Shylock 182.23.64.182:80
2016-07-08 08:55:3527b5116c41c96fc2fc19117ba3fcc6c1Virustotal results 33/56 (58.93%) Shylock 182.23.64.182:80
2016-07-08 08:55:3527b5116c41c96fc2fc19117ba3fcc6c1Virustotal results 33/56 (58.93%) Shylock 182.23.64.182:80
2016-07-08 08:32:09e5310634668be867cb9ecc11c386ceban/aShylock 182.23.64.182:80
2016-07-08 08:32:09e5310634668be867cb9ecc11c386ceban/aShylock 182.23.64.182:80
2016-07-07 11:14:39990f804a7123334f127093054082f0b4Virustotal results 41/57 (71.93%) Shylock 182.23.64.182:80
2016-07-07 11:14:39990f804a7123334f127093054082f0b4Virustotal results 41/57 (71.93%) Shylock 182.23.64.182:80
2016-07-07 01:18:1200fbc0d113685e97b08a329fbb24a3e0n/aShylock 182.23.64.182:80
2016-07-07 01:18:1200fbc0d113685e97b08a329fbb24a3e0n/aShylock 182.23.64.182:80
2016-07-06 23:48:149b595e6485f36c3c1029bcd42d53b2a6n/aShylock 182.23.64.182:80
2016-07-06 23:48:149b595e6485f36c3c1029bcd42d53b2a6n/aShylock 182.23.64.182:80
2016-07-05 22:41:08727cb6523af2d1513700a4cee03f353en/aShylock 182.23.64.182:80
2016-07-05 22:41:08727cb6523af2d1513700a4cee03f353en/aShylock 182.23.64.182:80
2016-07-05 14:38:1753235a9f206d07c12bd99f04fd4f0948Virustotal results 36/56 (64.29%) Shylock 182.23.64.182:80
2016-07-05 14:38:1753235a9f206d07c12bd99f04fd4f0948Virustotal results 36/56 (64.29%) Shylock 182.23.64.182:80
2016-07-05 09:29:41865edcca33631fa14d1e47ac0c2e8478Virustotal results 34/54 (62.96%) Shylock 182.23.64.182:80
2016-07-05 09:29:41865edcca33631fa14d1e47ac0c2e8478Virustotal results 34/54 (62.96%) Shylock 182.23.64.182:80
2016-07-05 01:34:53e40c8c6f38328bcb1572e8fdd4e7aeban/aShylock 182.23.64.182:80
2016-07-05 01:34:53e40c8c6f38328bcb1572e8fdd4e7aeban/aShylock 182.23.64.182:80
2016-07-04 19:30:390722628771a9503675cf73eb5cc444b0Virustotal results 53/67 (79.10%) Shylock 182.23.64.182:80
2016-07-04 19:30:390722628771a9503675cf73eb5cc444b0Virustotal results 53/67 (79.10%) Shylock 182.23.64.182:80
2016-07-04 06:27:19cb1221fe5b0d8a058d4753eb286a5770n/aShylock 182.23.64.182:80
2016-07-04 06:27:19cb1221fe5b0d8a058d4753eb286a5770n/aShylock 182.23.64.182:80
2016-07-04 06:24:113721cab949ecbe42dd41000c19e36289n/aShylock 182.23.64.182:80
2016-07-04 06:24:113721cab949ecbe42dd41000c19e36289n/aShylock 182.23.64.182:80
2016-07-04 04:22:454a1503211611a82e7083f981a442ab4fVirustotal results 4/53 (7.55%) Shylock 182.23.64.182:80
2016-07-04 04:22:454a1503211611a82e7083f981a442ab4fVirustotal results 4/53 (7.55%) Shylock 182.23.64.182:80
2016-07-04 02:08:563b271465d19c92384a666f7bddf2be4an/aShylock 182.23.64.182:80
2016-07-04 02:08:563b271465d19c92384a666f7bddf2be4an/aShylock 182.23.64.182:80
2016-07-03 12:55:27150b9737af6dca8c437d2b058b9ed09dn/aShylock 182.23.64.182:80
2016-07-03 12:55:27150b9737af6dca8c437d2b058b9ed09dn/aShylock 182.23.64.182:80
2016-07-03 00:00:055ec1f9739a273367ecf404f7b5889acan/aShylock 182.23.64.182:80
2016-07-03 00:00:055ec1f9739a273367ecf404f7b5889acan/aShylock 182.23.64.182:80
2016-06-28 16:27:078226a0b961a4d65de33c68697ef24d87n/aShylock 182.23.64.182:80
2016-06-28 16:27:078226a0b961a4d65de33c68697ef24d87n/aShylock 182.23.64.182:80
2016-06-28 13:50:04d2d9015f3b1bcd7f017b8d5f25c407ban/aShylock 182.23.64.182:80
2016-06-28 13:50:04d2d9015f3b1bcd7f017b8d5f25c407ban/aShylock 182.23.64.182:80
2016-06-27 20:42:51b92365b87c43e43242ea53aa40766642Virustotal results 33/56 (58.93%) Shylock 182.23.64.182:80
2016-06-27 20:42:51b92365b87c43e43242ea53aa40766642Virustotal results 33/56 (58.93%) Shylock 182.23.64.182:80
2016-06-21 05:45:595b93871b00699f51a41d2875d06e1abcVirustotal results 36/56 (64.29%) Shylock 182.23.64.182:80
2016-06-21 05:45:595b93871b00699f51a41d2875d06e1abcVirustotal results 36/56 (64.29%) Shylock 182.23.64.182:80
2016-06-19 17:09:19a4dd32575301699387c0032a0c0a7bafVirustotal results 38/68 (55.88%) Shylock 182.23.64.182:80
2016-06-19 17:09:19a4dd32575301699387c0032a0c0a7bafVirustotal results 38/68 (55.88%) Shylock 182.23.64.182:80
2016-06-19 11:57:2143ac343f254ea6832155167bbf7c32b2n/aShylock 182.23.64.182:80
2016-06-19 11:57:2143ac343f254ea6832155167bbf7c32b2n/aShylock 182.23.64.182:80
2016-06-17 19:44:12806a8388ec1c11f0ca7af275ee77d3f5n/aShylock 182.23.64.182:80
2016-06-17 19:44:12806a8388ec1c11f0ca7af275ee77d3f5n/aShylock 182.23.64.182:80
2016-06-17 13:09:180a4163bfd01ec76858f9c5b26a449207n/aGootkit 182.23.64.182:80
2016-06-17 13:09:180a4163bfd01ec76858f9c5b26a449207n/aGootkit 182.23.64.182:80

# of entries: 100 (max: 100)