SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 378344803525c82d3e134dcd2222cf2cfab0c338.

Database Entry


SHA1 Fingerprint:378344803525c82d3e134dcd2222cf2cfab0c338
Certificate Common Name (CN):*
Issuer Distinguished Name (DN):*
TLS Version:TLS 1.2
First seen:2018-12-24 13:15:39 UTC
Last seen:2018-12-31 13:29:31 UTC
Status:Blacklisted
Listing reason:Gozi C&C
Listing date:2018-12-24 15:00:54
Malware samples:55
Botnet C&Cs:1

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2018-12-31 13:29:311b95d56adeae3ef9ed099f8c3ddd0eb4n/aGozi 185.189.149.252:443
2018-12-31 12:18:077aebd77676af0ff08d51cdb2ce0e58b2n/aGozi 185.189.149.252:443
2018-12-31 11:46:48f5beb98beada57e6e48acf8f493804c3n/aGozi 185.189.149.252:443
2018-12-31 11:42:48b56e0e6b0b38258f59e09b1c99704f5eVirustotal results 32/71 (45.07%) Gozi 185.189.149.252:443
2018-12-31 11:01:374dff0b111cdc1224751c8422718672aen/aGozi 185.189.149.252:443
2018-12-31 10:33:581087d0587940bbb42b3946cbd31aa49cn/aGozi 185.189.149.252:443
2018-12-31 09:26:09e834d4de441057c430a43076aa1c9a8bn/aGozi 185.189.149.252:443
2018-12-31 09:05:453d9232b02e0d6be1f719d6746e493026n/aGozi 185.189.149.252:443
2018-12-31 08:49:05fc5849feb1c5ca18b30050ac762780fcn/aGozi 185.189.149.252:443
2018-12-31 08:41:1967386308ef8f0693cd62d3957a3e7e24n/aGozi 185.189.149.252:443
2018-12-31 08:30:540c9afb4ef7e30c7c148b9524aa5eca47n/aGozi 185.189.149.252:443
2018-12-31 08:01:453bcb5c82650b1eb335d682109f0a2cc7Virustotal results 29/71 (40.85%) Gozi 185.189.149.252:443
2018-12-31 07:33:5522152304bbe41d63b0e5304185735c6fn/aGozi 185.189.149.252:443
2018-12-31 07:20:00a6f09bfd00cf619f77a22050cacd493en/aGozi 185.189.149.252:443
2018-12-31 05:48:453e81c5c662bdf1a81c72ee3c5a470a12Virustotal results 28/72 (38.89%) Gozi 185.189.149.252:443
2018-12-31 02:53:598718298e28aa435ea97aca676ad8acbfVirustotal results 31/71 (43.66%) Gozi 185.189.149.252:443
2018-12-31 00:55:20aecdb162f1e35d33af4fb8a02c94dbd4n/aGozi 185.189.149.252:443
2018-12-30 23:51:17ab0112cdbecd649ce1032559f6929f7dn/aGozi 185.189.149.252:443
2018-12-30 23:01:32b214316422d48748c6a90b045ed9c314n/aGozi 185.189.149.252:443
2018-12-30 22:35:04d34b61a36ed53603f8cb5ae326d32885n/aGozi 185.189.149.252:443
2018-12-30 21:19:20e025040d5d4170e807c1378888bf0a5an/aGozi 185.189.149.252:443
2018-12-30 19:51:11fb71e6c457e2615114cb398395c6ff0en/aGozi 185.189.149.252:443
2018-12-30 19:26:06e96cf37956a3b3ba63ccb6442de1c534n/aGozi 185.189.149.252:443
2018-12-30 19:14:53421cd561d29cbffd4b10ed84cc06d3fcn/aGozi 185.189.149.252:443
2018-12-30 17:56:290bc36ba54b1a6eade1b5e6b14b86a678n/aGozi 185.189.149.252:443
2018-12-30 17:19:157c5ea1feddcdb1bf86b49bb8ec712527n/aGozi 185.189.149.252:443
2018-12-30 13:49:35938c10599104de7bd01b54c0c65e1b91n/aGozi 185.189.149.252:443
2018-12-30 12:15:426a5a9490ab802a796bcf8b188b424107n/aGozi 185.189.149.252:443
2018-12-30 10:45:320a1fb5c896f11eec4f47a0ebeca3f317n/aGozi 185.189.149.252:443
2018-12-30 07:33:58a917d65e22335a215cab6fe76d1ad39cn/aGozi 185.189.149.252:443
2018-12-30 03:29:240e7b7fcaed6a81e8971c13bdcd60a06cn/aGozi 185.189.149.252:443
2018-12-30 03:05:187acd305cddb1009c11a0f4892a84b63fn/a185.189.149.252:443
2018-12-30 02:48:394ad9e980ee598bbbcbf02d77d684aa5en/aGozi 185.189.149.252:443
2018-12-30 02:29:5277e98db216f9e041e60edd871d8e4305n/a185.189.149.252:443
2018-12-30 01:01:109f844727602efa691f9a30f904b2de5an/aGozi 185.189.149.252:443
2018-12-30 00:18:0644ba0174ef6edd81cebd605f22fde000n/aGozi 185.189.149.252:443
2018-12-30 00:00:254970e90bf21a6063e0c6338e123b5fe7n/aGozi 185.189.149.252:443
2018-12-29 21:55:1604f30281123337304e36142681b979c0n/aGozi 185.189.149.252:443
2018-12-29 20:41:22012787fc95939b418770b6cd8dea7f99n/a185.189.149.252:443
2018-12-29 17:25:13e5efe3074bf201a82d235ad4accb3051n/aGozi 185.189.149.252:443
2018-12-29 17:06:5051926d5b32d5e4bf9adadd8d675205a7n/a185.189.149.252:443
2018-12-29 13:14:252cd9f800e3c100639522af60b134c9d6n/aGozi 185.189.149.252:443
2018-12-29 11:25:57103b62618f547e1bf1729ec96bf688can/aGozi 185.189.149.252:443
2018-12-29 10:02:44aa1fdf00e882128f9ba6d0d03846d4e2n/a185.189.149.252:443
2018-12-29 09:42:516c3c2dd90e6495e1ab2fe814a53fddcbn/aGozi 185.189.149.252:443
2018-12-29 07:33:51f894ecda876ac7bada1da1927815b0fcn/aGozi 185.189.149.252:443
2018-12-29 05:00:566f8413b7051f72e01ca5c8737cb09574n/aGozi 185.189.149.252:443
2018-12-29 04:56:457b367d1003daefd0d26599568a469609n/aGozi 185.189.149.252:443
2018-12-29 04:51:412b5ba0f819512e7d45cccca70dedf451Virustotal results 12/70 (17.14%) Gozi 185.189.149.252:443
2018-12-28 19:21:070d0376c7915b13d3cc1d5c93a2d7946fn/a185.189.149.252:443
2018-12-28 15:11:52e970bf4263beb95cc221d6abfc766758n/a185.189.149.252:443
2018-12-28 12:23:147fc3ec8f10078fa1c5b9f8d9cfc43c49n/aGozi 185.189.149.252:443
2018-12-28 06:07:346b3c68e6e56ddd1504f642ac8e1c2d92Virustotal results 32/70 (45.71%) Gozi 185.189.149.252:443
2018-12-25 08:21:03e6d51f22b0e5e472b81a49f2e8f9547fVirustotal results 29/70 (41.43%) Gozi 185.189.149.252:443
2018-12-24 13:15:39c91814ca2f1a0295cdf315a133167f3fn/aGozi 185.189.149.252:443

# of entries: 55 (max: 100)