SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 552b287c36d53f9d00c26151090ec6d9482ea341.

Database Entry


SHA1 Fingerprint:552b287c36d53f9d00c26151090ec6d9482ea341
Certificate Common Name (CN):*
Issuer Distinguished Name (DN):*
TLS Version:TLS 1.2
First seen:2021-05-04 09:24:56 UTC
Last seen:2021-06-13 20:26:57 UTC
Status:Blacklisted
Listing reason:Gozi C&C
Listing date:2021-06-02 11:13:06
Malware samples:27
Botnet C&Cs:6

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2021-06-13 20:26:577a59e057339853fb7dc390e1cb1af1fen/aGozi 216.128.183.103:443
2021-06-09 12:35:13bb50b3753b86d28d5af417d5bb7981bbn/aGozi 82.118.22.204:443
2021-06-09 12:04:539f07670d0192eb4c2fa2dbafb6b3dddfn/aGozi 82.118.22.247:443
2021-06-05 21:43:282b7435026bfca8662678c4d40ede70e0n/aGozi 82.118.22.247:443
2021-06-01 06:48:19ef0d49f39f8e308fcb03a7a4b4022235n/aGozi 46.21.153.207:443
2021-05-31 16:18:384c07b9afbe0f15a6891202fa6deac6ccn/aGozi 46.21.153.207:443
2021-05-31 15:40:06ec6b8978abbc9abd34b746c9a956104dn/aGozi 46.21.153.207:443
2021-05-31 14:36:46b936ff099a85d68cdb40cd5750ad8163n/aGozi 46.21.153.207:443
2021-05-31 13:37:5282357d8ca22b46ad2eab396c97fe70f3n/aGozi 46.21.153.207:443
2021-05-31 10:50:59d4ee2facf9c4554768ccb6911a9d3f62n/aGozi 46.21.153.207:443
2021-05-31 08:39:4182319fa42f3cee876324384e7c456332n/aGozi 46.21.153.207:443
2021-05-31 08:30:53aacd8dc735e3522ba4ac1aa4e20b3cadn/aGozi 46.21.153.207:443
2021-05-16 15:10:35fdca743ac7b556bfdc3e946df96cb135n/aGozi 193.239.84.195:443
2021-05-12 09:27:23b9b732dbc6f94c79b5767eb98ebd899an/aGozi 193.239.84.195:443
2021-05-12 00:54:5146f2f8121981809dd19679b9b09ce47cn/aGozi 193.239.84.195:443
2021-05-11 15:54:2037b5ca4ecd0227a0f2bb4af2f5b661f2n/aGozi 193.239.84.195:443
2021-05-11 14:13:10fdd86254414df0c2a9da24dd5c3761a8Virustotal results 6 / 67 (8.96%) Gozi 193.239.85.9:443
2021-05-11 10:23:38bf7c960a18a0ec4d88b11bd06a5d3053n/aGozi 193.239.85.9:443
2021-05-11 09:48:39c4c0b19091c6edd5fd46867caf99026dVirustotal results 33 / 68 (48.53%) Gozi 193.239.84.195:443
2021-05-09 04:14:2464030e5b8541e2f391b3e4bdafe6fde2Virustotal results 46 / 69 (66.67%) Gozi 193.239.84.195:443
2021-05-08 23:27:454fa642db91f4cf4d3a2059826ad3f36aVirustotal results 27 / 69 (39.13%) Gozi 193.239.84.195:443
2021-05-07 04:34:38b06c14fbd0f484e3df0a91ac5037b49fVirustotal results 45 / 69 (65.22%) Gozi 193.239.84.195:443
2021-05-05 09:54:13bd5dce0b8de9f3a3ca64676eb3331a93n/aGozi 193.239.84.195:443
2021-05-04 17:17:395c7671985ee7bcee5dd06d0169d554f3n/aGozi 193.239.84.195:443
2021-05-04 15:18:451bd283efd2f8b87471ebd90adc112da2n/aGozi 193.239.84.195:443
2021-05-04 13:46:0780e55a5459125d0e9212ab31b61854b2n/aGozi 193.239.85.9:443
2021-05-04 09:24:564ea47e933317499aecc740bfd9adcbb8n/aGozi 193.239.84.195:443

# of entries: 27 (max: 100)