SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 7efff09f97443114ea57e5cf3409476afc63064c.

Database Entry


SHA1 Fingerprint:7efff09f97443114ea57e5cf3409476afc63064c
Certificate Common Name (CN):win-awards-here.life
Issuer Distinguished Name (DN):R3
TLS Version:TLS 1.2
First seen:2021-05-14 02:31:39 UTC
Last seen:2021-05-15 10:42:50 UTC
Status:Blacklisted
Listing reason:Gozi C&C
Listing date:2021-05-14 18:14:53
Malware samples:90
Botnet C&Cs:2

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2021-05-15 10:42:50a0254128094d5b4b36e9c7508bfabc3fn/aGozi 45.141.84.112:443
2021-05-15 10:42:50a0254128094d5b4b36e9c7508bfabc3fn/aGozi 45.141.84.112:443
2021-05-15 10:20:02c93493b65145a88473dedb4ca25c2da2n/aGozi 45.141.84.112:443
2021-05-15 10:20:02c93493b65145a88473dedb4ca25c2da2n/aGozi 45.141.84.112:443
2021-05-15 10:17:579f77d61586f838b8a3f1ae6dbd18368en/aGozi 45.141.84.112:443
2021-05-15 10:17:579f77d61586f838b8a3f1ae6dbd18368en/aGozi 45.141.84.112:443
2021-05-15 09:55:33d6c88a8195d47201b5f7f5b83d5d76bfn/aGozi 45.141.84.112:443
2021-05-15 09:55:33d6c88a8195d47201b5f7f5b83d5d76bfn/aGozi 45.141.84.112:443
2021-05-15 09:49:56574aaab55686e1777ab061c32e649fa3n/aGozi 45.141.84.112:443
2021-05-15 09:49:56574aaab55686e1777ab061c32e649fa3n/aGozi 45.141.84.112:443
2021-05-15 09:26:46b66036ddd430e0de7444ab5853bc5562Virustotal results 36 / 69 (52.17%) Gozi 45.141.84.112:443
2021-05-15 09:26:46b66036ddd430e0de7444ab5853bc5562Virustotal results 36 / 69 (52.17%) Gozi 45.141.84.112:443
2021-05-15 09:24:13ac668145776e21309cd953e8307db2e5Virustotal results 37 / 69 (53.62%) Gozi 45.141.84.112:443
2021-05-15 09:24:13ac668145776e21309cd953e8307db2e5Virustotal results 37 / 69 (53.62%) Gozi 45.141.84.112:443
2021-05-15 09:23:18ebe4398a79b677ed72d549435175f6bdVirustotal results 37 / 69 (53.62%) Gozi 45.141.84.112:443
2021-05-15 09:23:18ebe4398a79b677ed72d549435175f6bdVirustotal results 37 / 69 (53.62%) Gozi 45.141.84.112:443
2021-05-15 09:17:17f17e6f2b1a88f5f53464c46941aa13b7Virustotal results 37 / 69 (53.62%) Gozi 45.141.84.112:443
2021-05-15 09:17:17f17e6f2b1a88f5f53464c46941aa13b7Virustotal results 37 / 69 (53.62%) Gozi 45.141.84.112:443
2021-05-15 09:15:46f1a9a1ea5999305df435c2d07297a0deVirustotal results 37 / 69 (53.62%) Gozi 45.141.84.112:443
2021-05-15 09:15:46f1a9a1ea5999305df435c2d07297a0deVirustotal results 37 / 69 (53.62%) Gozi 45.141.84.112:443
2021-05-15 09:14:59f37793cc547a90c35c24fbc1a9b4c32aVirustotal results 37 / 68 (54.41%) Gozi 45.141.84.112:443
2021-05-15 09:14:59f37793cc547a90c35c24fbc1a9b4c32aVirustotal results 37 / 68 (54.41%) Gozi 45.141.84.112:443
2021-05-15 09:14:06efd10b78e2e4057cf285f7024e7fcd9cVirustotal results 35 / 70 (50.00%) Gozi 45.141.84.112:443
2021-05-15 09:14:06efd10b78e2e4057cf285f7024e7fcd9cVirustotal results 35 / 70 (50.00%) Gozi 45.141.84.112:443
2021-05-15 09:13:23c6a7d08172434796c322e597497fabaen/aGozi 45.141.84.112:443
2021-05-15 09:13:23c6a7d08172434796c322e597497fabaen/aGozi 45.141.84.112:443
2021-05-15 09:11:30e0f630f75c90c920a015e2c14148b64dn/aGozi 45.141.84.112:443
2021-05-15 09:11:30e0f630f75c90c920a015e2c14148b64dn/aGozi 45.141.84.112:443
2021-05-15 09:08:50ca5e74d9f28e8a033df7ab09be2d4b01Virustotal results 37 / 69 (53.62%) Gozi 45.141.84.112:443
2021-05-15 09:08:50ca5e74d9f28e8a033df7ab09be2d4b01Virustotal results 37 / 69 (53.62%) Gozi 45.141.84.112:443
2021-05-15 09:08:41c992a712c6991d970c10fe58f1a41726Virustotal results 38 / 68 (55.88%) Gozi 45.141.84.112:443
2021-05-15 09:08:41c992a712c6991d970c10fe58f1a41726Virustotal results 38 / 68 (55.88%) Gozi 45.141.84.112:443
2021-05-15 09:06:45c9c231ae1546a93aa2b1d222d852ed64Virustotal results 37 / 68 (54.41%) Gozi 45.141.84.112:443
2021-05-15 09:06:45c9c231ae1546a93aa2b1d222d852ed64Virustotal results 37 / 68 (54.41%) Gozi 45.141.84.112:443
2021-05-15 09:05:5772306de3f7f23c52007163365ef9aa86Virustotal results 38 / 68 (55.88%) Gozi 45.141.84.112:443
2021-05-15 09:05:5772306de3f7f23c52007163365ef9aa86Virustotal results 38 / 68 (55.88%) Gozi 45.141.84.112:443
2021-05-15 09:04:399b705fbec50547f93adbdd7fddc5a2d6n/aGozi 45.141.84.112:443
2021-05-15 09:04:399b705fbec50547f93adbdd7fddc5a2d6n/aGozi 45.141.84.112:443
2021-05-15 09:03:359dcd0e433ec00ae0d8e5e04b68180c81Virustotal results 37 / 69 (53.62%) Gozi 45.141.84.112:443
2021-05-15 09:03:359dcd0e433ec00ae0d8e5e04b68180c81Virustotal results 37 / 69 (53.62%) Gozi 45.141.84.112:443
2021-05-15 09:03:299f712e3d29a210cefe1e1d2149756faeVirustotal results 37 / 69 (53.62%) Gozi 45.141.84.112:443
2021-05-15 09:03:299f712e3d29a210cefe1e1d2149756faeVirustotal results 37 / 69 (53.62%) Gozi 45.141.84.112:443
2021-05-15 09:03:0424911c3bc0ce532222a652307b8cdebcVirustotal results 31 / 62 (50.00%) Gozi 45.141.84.112:443
2021-05-15 09:03:0424911c3bc0ce532222a652307b8cdebcVirustotal results 31 / 62 (50.00%) Gozi 45.141.84.112:443
2021-05-15 09:01:46984a195109fd8924cc3658c14310efc7Virustotal results 36 / 69 (52.17%) Gozi 45.141.84.112:443
2021-05-15 09:01:46984a195109fd8924cc3658c14310efc7Virustotal results 36 / 69 (52.17%) Gozi 45.141.84.112:443
2021-05-15 09:01:35488906f4ae3f1073a5a1815262cec80cVirustotal results 39 / 69 (56.52%) Gozi 45.141.84.112:443
2021-05-15 09:01:35488906f4ae3f1073a5a1815262cec80cVirustotal results 39 / 69 (56.52%) Gozi 45.141.84.112:443
2021-05-15 08:57:431003a6eff9648dadcaccbdd37be8638dVirustotal results 36 / 67 (53.73%) Gozi 45.141.84.112:443
2021-05-15 08:57:431003a6eff9648dadcaccbdd37be8638dVirustotal results 36 / 67 (53.73%) Gozi 45.141.84.112:443
2021-05-15 08:56:3646ab4787e0f881f7c1fc70882d9e8617Virustotal results 37 / 68 (54.41%) Gozi 45.141.84.112:443
2021-05-15 08:56:3646ab4787e0f881f7c1fc70882d9e8617Virustotal results 37 / 68 (54.41%) Gozi 45.141.84.112:443
2021-05-15 08:56:225c318880684273a587e020fdd45defd4Virustotal results 38 / 69 (55.07%) Gozi 45.141.84.112:443
2021-05-15 08:56:225c318880684273a587e020fdd45defd4Virustotal results 38 / 69 (55.07%) Gozi 45.141.84.112:443
2021-05-15 08:56:0925ddc5d21ce7320e1e1e0838a7bb3eaeVirustotal results 36 / 67 (53.73%) Gozi 45.141.84.112:443
2021-05-15 08:56:0925ddc5d21ce7320e1e1e0838a7bb3eaeVirustotal results 36 / 67 (53.73%) Gozi 45.141.84.112:443
2021-05-15 08:54:101371526e34ac7fe9053f6c375eb68f3eVirustotal results 38 / 66 (57.58%) Gozi 45.141.84.112:443
2021-05-15 08:54:101371526e34ac7fe9053f6c375eb68f3eVirustotal results 38 / 66 (57.58%) Gozi 45.141.84.112:443
2021-05-15 08:52:531740e96d778779d9d3840a93dcfbda53Virustotal results 37 / 69 (53.62%) Gozi 45.141.84.112:443
2021-05-15 08:52:531740e96d778779d9d3840a93dcfbda53Virustotal results 37 / 69 (53.62%) Gozi 45.141.84.112:443
2021-05-15 07:23:5990b27464ba15a0317a9bc5156aa9080dVirustotal results 38 / 69 (55.07%) Gozi 45.141.84.112:443
2021-05-15 07:23:5990b27464ba15a0317a9bc5156aa9080dVirustotal results 38 / 69 (55.07%) Gozi 45.141.84.112:443
2021-05-15 06:31:4952064516f3e18c2fdba2d0d76d95729fVirustotal results 37 / 68 (54.41%) Gozi 45.141.84.112:443
2021-05-15 06:31:4952064516f3e18c2fdba2d0d76d95729fVirustotal results 37 / 68 (54.41%) Gozi 45.141.84.112:443
2021-05-15 01:35:00e405b993fe4096c3c201ecdd6d1d318aVirustotal results 38 / 69 (55.07%) Gozi 45.141.84.112:443
2021-05-15 01:35:00e405b993fe4096c3c201ecdd6d1d318aVirustotal results 38 / 69 (55.07%) Gozi 45.141.84.112:443
2021-05-15 01:30:26e7709694102815b6e88053afeee57b94Virustotal results 37 / 69 (53.62%) Gozi 45.141.84.112:443
2021-05-15 01:30:26e7709694102815b6e88053afeee57b94Virustotal results 37 / 69 (53.62%) Gozi 45.141.84.112:443
2021-05-14 21:59:4314a63597eb32dac8e40c2d1db21307c9Virustotal results 37 / 69 (53.62%) Gozi 88.214.24.56:443
2021-05-14 21:59:4314a63597eb32dac8e40c2d1db21307c9Virustotal results 37 / 69 (53.62%) Gozi 88.214.24.56:443
2021-05-14 20:52:105ee7cd467bb03ca9ee57baa56c578b81n/aGozi 88.214.24.56:443
2021-05-14 20:52:105ee7cd467bb03ca9ee57baa56c578b81n/aGozi 88.214.24.56:443
2021-05-14 20:15:24159c929d6ecfb94b8f2d5425e6289108n/aGozi 88.214.24.56:443
2021-05-14 20:15:24159c929d6ecfb94b8f2d5425e6289108n/aGozi 88.214.24.56:443
2021-05-14 19:59:0673dc59baa33ecd3e821baf2230234f01n/aGozi 88.214.24.56:443
2021-05-14 19:59:0673dc59baa33ecd3e821baf2230234f01n/aGozi 88.214.24.56:443
2021-05-14 19:54:014068b39c4a681542c1362d2e4f45cf41n/aGozi 88.214.24.56:443
2021-05-14 19:54:014068b39c4a681542c1362d2e4f45cf41n/aGozi 88.214.24.56:443
2021-05-14 19:52:138355bc5369865faf0c302e0fb0bcfb9en/aGozi 88.214.24.56:443
2021-05-14 19:52:138355bc5369865faf0c302e0fb0bcfb9en/aGozi 88.214.24.56:443
2021-05-14 18:29:362a46f4e58b78cdd35ca106c7d869d0c5n/aGozi 88.214.24.56:443
2021-05-14 18:29:362a46f4e58b78cdd35ca106c7d869d0c5n/aGozi 88.214.24.56:443
2021-05-14 18:18:308c90a3c1b2424b55719d02c36db8be1en/aGozi 88.214.24.56:443
2021-05-14 18:18:308c90a3c1b2424b55719d02c36db8be1en/aGozi 88.214.24.56:443
2021-05-14 17:46:08265b1b126ed78e4870fa32de1878dd1dn/aGozi 88.214.24.56:443
2021-05-14 17:46:08265b1b126ed78e4870fa32de1878dd1dn/aGozi 88.214.24.56:443
2021-05-14 17:44:0446e839e363bf9f83db7f716719237bf9n/aGozi 88.214.24.56:443
2021-05-14 17:44:0446e839e363bf9f83db7f716719237bf9n/aGozi 88.214.24.56:443
2021-05-14 16:42:0497d98db0f3664394d2e0fb58c56a869cn/aGozi 88.214.24.56:443
2021-05-14 16:42:0497d98db0f3664394d2e0fb58c56a869cn/aGozi 88.214.24.56:443
2021-05-14 16:34:139cb9d5713f1541b327869b06dee62ca7n/aGozi 88.214.24.56:443
2021-05-14 16:34:139cb9d5713f1541b327869b06dee62ca7n/aGozi 88.214.24.56:443
2021-05-14 16:15:234d1b1fe49b26b4d432d0b875bff2cd81n/aGozi 88.214.24.56:443
2021-05-14 16:15:234d1b1fe49b26b4d432d0b875bff2cd81n/aGozi 88.214.24.56:443
2021-05-14 15:51:37c38fde621bcd2f9ee747f2d5d84fe403n/aGozi 88.214.24.56:443
2021-05-14 15:51:37c38fde621bcd2f9ee747f2d5d84fe403n/aGozi 88.214.24.56:443
2021-05-14 15:45:40d00805faa8f8aca6d5cdd99ac3bc8988n/aGozi 88.214.24.56:443
2021-05-14 15:45:40d00805faa8f8aca6d5cdd99ac3bc8988n/aGozi 88.214.24.56:443
2021-05-14 15:41:42bdf5cefc0d4de47c96b3e289048e8b20n/aGozi 88.214.24.56:443
2021-05-14 15:41:42bdf5cefc0d4de47c96b3e289048e8b20n/aGozi 88.214.24.56:443

# of entries: 100 (max: 100)