SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 455d8e384d214c17d34522413a98dc002352b78e.

Database Entry


SHA1 Fingerprint:455d8e384d214c17d34522413a98dc002352b78e
Certificate Common Name (CN):sontonecchidtt.Titheefrovorh.cologne
Issuer Distinguished Name (DN):sontonecchidtt.Titheefrovorh.cologne
TLS Version:TLSv1' NOTBEFOR
First seen:2018-10-17 13:07:26 UTC
Last seen:2018-10-18 03:49:50 UTC
Status:Blacklisted
Listing reason:Gozi C&C
Listing date:2018-10-18 06:07:43
Malware samples:21
Botnet C&Cs:1

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2018-10-18 03:49:503de4ad9bb19d2f48113e9313438d97d6n/aGozi 95.215.44.192:443
2018-10-18 03:49:503de4ad9bb19d2f48113e9313438d97d6n/aGozi 95.215.44.192:443
2018-10-18 03:47:297a9bc149c30e22051fbf9c4932f0c60fn/aGozi 95.215.44.192:443
2018-10-18 03:47:297a9bc149c30e22051fbf9c4932f0c60fn/aGozi 95.215.44.192:443
2018-10-18 03:43:37a4a8a8b421102f4bc785162cb3e349e5Virustotal results 46/67 (68.66%) Gozi 95.215.44.192:443
2018-10-18 03:43:37a4a8a8b421102f4bc785162cb3e349e5Virustotal results 46/67 (68.66%) Gozi 95.215.44.192:443
2018-10-18 02:03:0904dce81c430f10a4e74fd639d2f37782Virustotal results 46/67 (68.66%) Gozi 95.215.44.192:443
2018-10-18 02:03:0904dce81c430f10a4e74fd639d2f37782Virustotal results 46/67 (68.66%) Gozi 95.215.44.192:443
2018-10-18 02:03:07088293f1dfc62b09d530bb8842a2a0e5Virustotal results 48/68 (70.59%) Gozi 95.215.44.192:443
2018-10-18 02:03:07088293f1dfc62b09d530bb8842a2a0e5Virustotal results 48/68 (70.59%) Gozi 95.215.44.192:443
2018-10-18 02:02:22350adfefcb5fb74de8d5c766a897eddfn/aGozi 95.215.44.192:443
2018-10-18 02:02:22350adfefcb5fb74de8d5c766a897eddfn/aGozi 95.215.44.192:443
2018-10-18 00:19:35ea278947dd91f83a0e2fb02f773f96deVirustotal results 45/67 (67.16%) Gozi 95.215.44.192:443
2018-10-18 00:19:35ea278947dd91f83a0e2fb02f773f96deVirustotal results 45/67 (67.16%) Gozi 95.215.44.192:443
2018-10-18 00:13:08ec626b689d380973cf0290800c0449d6Virustotal results 46/67 (68.66%) Gozi 95.215.44.192:443
2018-10-18 00:13:08ec626b689d380973cf0290800c0449d6Virustotal results 46/67 (68.66%) Gozi 95.215.44.192:443
2018-10-18 00:09:10f31b118269e179bbfa84d0db9991f7d8Virustotal results 46/67 (68.66%) Gozi 95.215.44.192:443
2018-10-18 00:09:10f31b118269e179bbfa84d0db9991f7d8Virustotal results 46/67 (68.66%) Gozi 95.215.44.192:443
2018-10-18 00:05:375b386cf667bc8ed97f58c80c91ec0566n/aGozi 95.215.44.192:443
2018-10-18 00:05:375b386cf667bc8ed97f58c80c91ec0566n/aGozi 95.215.44.192:443
2018-10-17 23:22:35ee1079bc2cea886c02ad52db59f6eda4Virustotal results 45/67 (67.16%) Gozi 95.215.44.192:443
2018-10-17 23:22:35ee1079bc2cea886c02ad52db59f6eda4Virustotal results 45/67 (67.16%) Gozi 95.215.44.192:443
2018-10-17 23:08:5286149a56a0945082f78ead37fb445fc9n/aGozi 95.215.44.192:443
2018-10-17 23:08:5286149a56a0945082f78ead37fb445fc9n/aGozi 95.215.44.192:443
2018-10-17 22:22:5702d7c44f8a60b53abc9dc13542a1eb90Virustotal results 43/66 (65.15%) Gozi 95.215.44.192:443
2018-10-17 22:22:5702d7c44f8a60b53abc9dc13542a1eb90Virustotal results 43/66 (65.15%) Gozi 95.215.44.192:443
2018-10-17 22:18:13071690f5b59e3c77d2f1a33f88045096Virustotal results 37/67 (55.22%) Gozi 95.215.44.192:443
2018-10-17 22:18:13071690f5b59e3c77d2f1a33f88045096Virustotal results 37/67 (55.22%) Gozi 95.215.44.192:443
2018-10-17 22:09:483cc1539e5dfa66d554011762dacdeb47n/aGozi 95.215.44.192:443
2018-10-17 22:09:483cc1539e5dfa66d554011762dacdeb47n/aGozi 95.215.44.192:443
2018-10-17 20:53:41174ab453c3301a11bb622d6b3bcf8967Virustotal results 37/67 (55.22%) Gozi 95.215.44.192:443
2018-10-17 20:53:41174ab453c3301a11bb622d6b3bcf8967Virustotal results 37/67 (55.22%) Gozi 95.215.44.192:443
2018-10-17 13:55:58e13a9c779139e72493a168590aaf658dVirustotal results 46/67 (68.66%) Gozi 95.215.44.192:443
2018-10-17 13:55:58e13a9c779139e72493a168590aaf658dVirustotal results 46/67 (68.66%) Gozi 95.215.44.192:443
2018-10-17 13:53:4419c4f1cb5955d741522a4f982aed1c10Virustotal results 47/67 (70.15%) Gozi 95.215.44.192:443
2018-10-17 13:53:4419c4f1cb5955d741522a4f982aed1c10Virustotal results 47/67 (70.15%) Gozi 95.215.44.192:443
2018-10-17 13:52:538d4ae907f320fb01b7ea122166bea377n/aGozi 95.215.44.192:443
2018-10-17 13:52:538d4ae907f320fb01b7ea122166bea377n/aGozi 95.215.44.192:443
2018-10-17 13:51:39fd2df80a02ed880700e75c521e716f8fVirustotal results 46/67 (68.66%) Gozi 95.215.44.192:443
2018-10-17 13:51:39fd2df80a02ed880700e75c521e716f8fVirustotal results 46/67 (68.66%) Gozi 95.215.44.192:443
2018-10-17 13:07:26be4bac9556a30c6b4a8850cf3e616f74Virustotal results 19/58 (32.76%) Gozi 95.215.44.192:443
2018-10-17 13:07:26be4bac9556a30c6b4a8850cf3e616f74Virustotal results 19/58 (32.76%) Gozi 95.215.44.192:443

# of entries: 42 (max: 100)