SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 7220d8f55a6baeaab5c6432001708ce109babba4.

Database Entry


SHA1 Fingerprint:7220d8f55a6baeaab5c6432001708ce109babba4
Certificate Common Name (CN):*
Issuer Distinguished Name (DN):*
TLS Version:TLS 1.2
First seen:2019-08-15 10:08:33 UTC
Last seen:2019-08-19 06:48:08 UTC
Status:Blacklisted
Listing reason:Gozi C&C
Listing date:2019-08-17 07:40:16
Malware samples:5
Botnet C&Cs:1

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2019-08-19 06:48:08c5b1b9d594b0815be75201ef04995beeVirustotal results 29/66 (43.94%) Gozi 185.193.141.166:443
2019-08-19 06:48:08c5b1b9d594b0815be75201ef04995beeVirustotal results 29/66 (43.94%) Gozi 185.193.141.166:443
2019-08-17 10:23:26b3c3d1da4facb12dded644b39c082c27Virustotal results 15/69 (21.74%) Gozi 185.193.141.166:443
2019-08-17 10:23:26b3c3d1da4facb12dded644b39c082c27Virustotal results 15/69 (21.74%) Gozi 185.193.141.166:443
2019-08-17 03:46:4954ffe3a2c17633e9db10acebe08ebe47Virustotal results 14/71 (19.72%) Gozi 185.193.141.166:443
2019-08-17 03:46:4954ffe3a2c17633e9db10acebe08ebe47Virustotal results 14/71 (19.72%) Gozi 185.193.141.166:443
2019-08-16 08:05:059e17561d1bb91eb3e0af1199d8cd0835Virustotal results 29/65 (44.62%) Gozi 185.193.141.166:443
2019-08-16 08:05:059e17561d1bb91eb3e0af1199d8cd0835Virustotal results 29/65 (44.62%) Gozi 185.193.141.166:443
2019-08-15 10:08:334866f2b503be4ca975f4870dd1fda342n/aGozi 185.193.141.166:443
2019-08-15 10:08:334866f2b503be4ca975f4870dd1fda342n/aGozi 185.193.141.166:443

# of entries: 10 (max: 100)