SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint c426793f8b0433559e10396d3769e4c206cf10d3.

Database Entry


SHA1 Fingerprint:c426793f8b0433559e10396d3769e4c206cf10d3
Certificate Common Name (CN):www.XF0VTbKz.com/O=3pcwtEZb7TlnCKlV./C=US
Issuer Distinguished Name (DN):www.XF0VTbKz.com/O=3pcwtEZb7TlnCKlV./C=US
TLS Version:TLSv1
First seen:2016-01-29 15:21:36 UTC
Last seen:2016-02-01 05:49:48 UTC
Status:Blacklisted
Listing reason:Gootkit C&C
Listing date:2016-01-29 15:53:08
Malware samples:3
Botnet C&Cs:2

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2016-02-01 05:49:4842db8444febcc7eb54534de00696657fVirustotal results 1/55 (1.82%) Gootkit 89.248.171.237:443
2016-02-01 05:49:4842db8444febcc7eb54534de00696657fVirustotal results 1/55 (1.82%) Gootkit 89.248.171.237:443
2016-01-31 17:03:239712d76a950c0333d3da4c387ef3a0baVirustotal results 10/52 (19.23%) Gootkit 89.248.171.237:443
2016-01-31 17:03:239712d76a950c0333d3da4c387ef3a0baVirustotal results 10/52 (19.23%) Gootkit 89.248.171.237:443
2016-01-29 15:21:362a4d62ec2629fc9dd57ac47b46a0671cVirustotal results 4/55 (7.27%) Gootkit 192.157.239.137:443
2016-01-29 15:21:362a4d62ec2629fc9dd57ac47b46a0671cVirustotal results 4/55 (7.27%) Gootkit 192.157.239.137:443

# of entries: 6 (max: 100)