SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 2569e55f5f42541942dacd2016db43aa39187d1e.

Database Entry


SHA1 Fingerprint:2569e55f5f42541942dacd2016db43aa39187d1e
Certificate Common Name (CN):*
Issuer Distinguished Name (DN):*
TLS Version:TLS 1.2' NOTBEF
First seen:2021-03-29 18:09:25 UTC
Last seen:2021-03-30 03:56:31 UTC
Status:Blacklisted
Listing reason:Gozi C&C
Listing date:2021-03-30 07:02:44
Malware samples:15
Botnet C&Cs:1

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2021-03-30 03:56:315508c927230f3b857e792d6d6bdad1f2n/aGozi 5.34.182.123:443
2021-03-30 03:27:424cfb80370ca9b5577b966bf22228d344n/aGozi 5.34.182.123:443
2021-03-29 23:59:22dbf1c2b828e21feb48dc1cff4116a661n/aGozi 5.34.182.123:443
2021-03-29 23:45:1373d1b2c4d3bd8e5350c312f61bb3b1f9n/aGozi 5.34.182.123:443
2021-03-29 23:24:059d96be2261629d5f4d2659c173b36655n/aGozi 5.34.182.123:443
2021-03-29 22:58:139ae9eef843fd45c98ae5808e527de9f5n/aGozi 5.34.182.123:443
2021-03-29 21:05:12160fa0b9f7c505c3a156ff17123eb98fn/aGozi 5.34.182.123:443
2021-03-29 20:25:35ee3942b590be4220fcec1cfff0f3487fn/aGozi 5.34.182.123:443
2021-03-29 20:05:568a3d8c943723dbbd37272f37f8ac491en/aGozi 5.34.182.123:443
2021-03-29 20:05:35fbc57e72a8b7fa9a7667794f021daa16n/aGozi 5.34.182.123:443
2021-03-29 19:43:160fe9b7511f0a93f2987457edcb855596n/aGozi 5.34.182.123:443
2021-03-29 19:39:012b47ed93465642bce23a1ab4f5a1b7acn/aIcedID 5.34.182.123:443
2021-03-29 19:14:259110e88c7a4bc5ceb726cfb083abcd75n/aGozi 5.34.182.123:443
2021-03-29 18:33:52243822c10061a46c796d903f91828b3en/aGozi 5.34.182.123:443
2021-03-29 18:09:25cc2310780c97a0240e27600d1dadd7cen/aGozi 5.34.182.123:443

# of entries: 15 (max: 100)