SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 4ef2cce6edaecb12652259cdf9815b656d1da27a.

Database Entry


SHA1 Fingerprint:4ef2cce6edaecb12652259cdf9815b656d1da27a
Certificate Common Name (CN):*
Issuer Distinguished Name (DN):*
TLS Version:TLS 1.2
First seen:2018-10-18 11:50:25 UTC
Last seen:2018-10-28 11:21:30 UTC
Status:Blacklisted
Listing reason:Gozi C&C
Listing date:2018-10-28 12:43:48
Malware samples:74
Botnet C&Cs:1

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2018-10-28 11:21:305f6c89bd17765daf9a6902a9063348afn/aGozi 54.39.81.123:443
2018-10-19 06:28:0071fe52bfc6a1f08cc09fe6765d854817n/aGozi 54.39.81.123:443
2018-10-19 06:24:1427c52caecb2b22d95d0e843f6759f984n/aGozi 54.39.81.123:443
2018-10-19 06:22:53b0b0c679f20a4278445c48fa05f4dc86n/aGozi 54.39.81.123:443
2018-10-19 06:22:42246c3f8c4fe7267d57e8096ada338e8bn/aGozi 54.39.81.123:443
2018-10-19 06:21:372c469037935323775fe2c59f96beedabn/aGozi 54.39.81.123:443
2018-10-19 06:21:3728af8831d6dc4266b74f7571e4da2ce9n/aGozi 54.39.81.123:443
2018-10-19 06:17:469af648654ca02b53f62979a2fddb195en/aGozi 54.39.81.123:443
2018-10-19 06:17:113a8bc6488f480ca670ae1a2497df6e6an/aGozi 54.39.81.123:443
2018-10-19 06:16:50f38b80b5eb766ac37513777970fa52beVirustotal results 33/68 (48.53%) Gozi 54.39.81.123:443
2018-10-19 06:09:22146ebf50aa47b6f1594641dce7556d5dn/aGozi 54.39.81.123:443
2018-10-19 06:07:512c46d737e4b5b8470f166a222c45bc77n/aGozi 54.39.81.123:443
2018-10-19 06:03:087a28fd5242cddd9b782d9234ed44f78an/aGozi 54.39.81.123:443
2018-10-19 06:02:2891fcdf224ee443911081509425a23e68n/aGozi 54.39.81.123:443
2018-10-19 06:02:057514dc1ef01c49c5d2e79aea312719bcn/aGozi 54.39.81.123:443
2018-10-19 05:58:17ff2457e8ceafe0abe9853620fa3120eeVirustotal results 35/68 (51.47%) Gozi 54.39.81.123:443
2018-10-19 04:38:5627bb32fc386be17fd7a328949f601897n/aGozi 54.39.81.123:443
2018-10-19 04:38:07562e4ceca15b6d147d73d3deb5e5e6dfn/aGozi 54.39.81.123:443
2018-10-19 04:32:22620215b0c467d3976d5f1af6598ad7c0n/aGozi 54.39.81.123:443
2018-10-19 04:32:01a005f84b374a748313a9b251a6a32748Virustotal results 33/68 (48.53%) Gozi 54.39.81.123:443
2018-10-19 04:30:44d5ea5e71dbf8647ec15edf5fb40a94c0Virustotal results 32/67 (47.76%) Gozi 54.39.81.123:443
2018-10-19 04:25:29229e68e15417c328550b343e1a4bf203n/aGozi 54.39.81.123:443
2018-10-19 04:14:25208dfd3f9877f4e657a7ee93d0598460n/aGozi 54.39.81.123:443
2018-10-19 04:14:23a3bd683e5701928d55b13eec7c9fc3e8Virustotal results 31/67 (46.27%) Gozi 54.39.81.123:443
2018-10-19 04:11:3665b3ac51e3e0d93dc9b357bb539343f4n/aGozi 54.39.81.123:443
2018-10-19 04:07:39e89fc3f6d6a7b3176294e92071499e01Virustotal results 35/67 (52.24%) Gozi 54.39.81.123:443
2018-10-19 02:47:281df077638e68b8fbb49c2defe05ddcfdn/aGozi 54.39.81.123:443
2018-10-19 02:43:4444cb79fa50d5a90630bba13a08319c3cn/aGozi 54.39.81.123:443
2018-10-19 02:40:5947a3377b861c89b157b85762ca1da8b2n/aGozi 54.39.81.123:443
2018-10-19 02:31:5579c62fcd827ba4dae5c16e7379d0cd9en/aGozi 54.39.81.123:443
2018-10-19 02:29:57746d6830521610127645f7e7c1a126edn/aGozi 54.39.81.123:443
2018-10-19 02:29:346c4b7fbbf0afa308f43b38ddf19d6598n/aGozi 54.39.81.123:443
2018-10-19 02:26:5592d835dde038bd5f8fcfa3f36619dfb3n/aGozi 54.39.81.123:443
2018-10-19 02:22:15d674360efac0d9a670d0accaca8281beVirustotal results 33/67 (49.25%) Gozi 54.39.81.123:443
2018-10-19 02:02:17bfa5ee0be84e61f432d6d6367b632ca3n/a54.39.81.123:443
2018-10-19 02:00:047d17ab3184c0b6ef04ca613f3060eaa3n/aGozi 54.39.81.123:443
2018-10-19 00:11:11819c2384edace44d7ac1acf1b8ae2a42n/aGozi 54.39.81.123:443
2018-10-19 00:03:391f11eefa0dc1516f4c94b5659d215378n/aGozi 54.39.81.123:443
2018-10-19 00:02:553ff08338d11b348ac11f4f04d4506a1cn/aGozi 54.39.81.123:443
2018-10-19 00:01:55a036d8092aac7dde91ce1fa323fdcdfaVirustotal results 32/67 (47.76%) Gozi 54.39.81.123:443
2018-10-18 23:51:13ac1b627b41b9341dba98cb209dc39c46Virustotal results 32/67 (47.76%) Gozi 54.39.81.123:443
2018-10-18 23:50:02ce74837888e299d2489e3f1ae921729dVirustotal results 34/68 (50.00%) Gozi 54.39.81.123:443
2018-10-18 23:49:49622597650fdea1990e30ec5fb65ff1bcn/aGozi 54.39.81.123:443
2018-10-18 23:45:483a4f89fde8598e87598e5b2b8dce6747n/a54.39.81.123:443
2018-10-18 23:45:449803c2f9c8a26f78790065673656b028n/aGozi 54.39.81.123:443
2018-10-18 22:10:30086b5adf0e5bb619331189bb34b1b31dn/a54.39.81.123:443
2018-10-18 22:02:59597d9c66bdecebaed2cf88de9101132dn/aGozi 54.39.81.123:443
2018-10-18 22:02:0760b1addfd673bb5694ef90ab170121b3n/aGozi 54.39.81.123:443
2018-10-18 22:02:0543b427461bea91127430e72c6b3b95a7n/aGozi 54.39.81.123:443
2018-10-18 22:00:415ea197d038ba8a10aadd7e2e1951512an/aGozi 54.39.81.123:443
2018-10-18 21:49:57d9805cadac6fdcdbdfff964f7f4091a2Virustotal results 33/68 (48.53%) Gozi 54.39.81.123:443
2018-10-18 21:49:18aa6cd21a07bc118e7b6586129f97f953Virustotal results 34/68 (50.00%) Gozi 54.39.81.123:443
2018-10-18 19:57:084dd70d95ab2eafd573d551373deedd7fn/aGozi 54.39.81.123:443
2018-10-18 19:54:0530094c4792c4e98b1ffc349f402e23c2n/aGozi 54.39.81.123:443
2018-10-18 19:51:484c9a196a8942104fcdd5f30427f017d4n/a54.39.81.123:443
2018-10-18 19:51:27842e4b8220d5b2544f24658a35d20b12n/aGozi 54.39.81.123:443
2018-10-18 19:41:26cd3556340070e9c4ae6c9f0073f9a3ecVirustotal results 31/68 (45.59%) Gozi 54.39.81.123:443
2018-10-18 19:40:412b9ed2e55326cf8cc3c999fa775fbab7n/aGozi 54.39.81.123:443
2018-10-18 19:37:42d1c68261b44cd539d3e933355fec7422Virustotal results 33/68 (48.53%) Gozi 54.39.81.123:443
2018-10-18 17:10:197591c9e232258ef27beb2d52f474ab2bVirustotal results 8/64 (12.50%) Gozi 54.39.81.123:443
2018-10-18 17:06:276496a0920a081e7310a1cc9fc79d9b54n/aGozi 54.39.81.123:443
2018-10-18 17:02:38e94f260c29caea8c326f1e865d523671Virustotal results 37/66 (56.06%) Gozi 54.39.81.123:443
2018-10-18 15:54:1115dcb369e285aeab6ea40f32ff4bd3eaVirustotal results 41/68 (60.29%) Gozi 54.39.81.123:443
2018-10-18 15:53:473decbf091d35d6cbf86690f1464ff3f1n/aGozi 54.39.81.123:443
2018-10-18 15:52:25917ec182d3d638b8af20e69b437d37c5n/aGozi 54.39.81.123:443
2018-10-18 15:49:46c9181568928628caf8dd99d6e60d3d3fVirustotal results 34/66 (51.52%) Gozi 54.39.81.123:443
2018-10-18 15:49:323e07341ea95d779d1e4282032f6b5c52n/aGozi 54.39.81.123:443
2018-10-18 15:40:14ac5b76a1023e440a890c6ad0f64987dcVirustotal results 45/67 (67.16%) Gozi 54.39.81.123:443
2018-10-18 14:54:44bc127f2cb33daa1a5872b2840d4564f9Virustotal results 39/67 (58.21%) Gozi 54.39.81.123:443
2018-10-18 14:53:145b60ca2f87bd8423e81d93ed0c272575n/aGozi 54.39.81.123:443
2018-10-18 14:51:09d05e751f02c472b4cbea6daef45195f0Virustotal results 43/68 (63.24%) Gozi 54.39.81.123:443
2018-10-18 13:25:38981ae9cdf9be1cd45e4a033d1edf06e2Virustotal results 42/59 (71.19%) Gozi 54.39.81.123:443
2018-10-18 12:18:56f236eb81f3856592fef5e75416b1c55bVirustotal results 15/57 (26.32%) Gozi 54.39.81.123:443
2018-10-18 11:50:2941cc543ae91c56fadbe4f72f91630ed2Virustotal results 15/57 (26.32%) Gozi 54.39.81.123:443

# of entries: 74 (max: 100)