SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint a585fb98c171bd5e2c91fbb5a32364df6e136f1f.

Database Entry


SHA1 Fingerprint:a585fb98c171bd5e2c91fbb5a32364df6e136f1f
Certificate Common Name (CN):*
Issuer Distinguished Name (DN):*
TLS Version:TLS 1.2
First seen:2018-10-28 13:42:18 UTC
Last seen:2018-10-29 01:28:01 UTC
Status:Blacklisted
Listing reason:Gozi C&C
Listing date:2018-10-28 14:36:35
Malware samples:7
Botnet C&Cs:1

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2018-10-29 01:28:0116c012e2df1d1cab339e354a526ab3a4Virustotal results 19/55 (34.55%) Gozi 144.217.37.230:443
2018-10-28 20:39:545cad3efdc9666c4fb99ef1bb0f20b794Virustotal results 19/56 (33.93%) Gozi 144.217.37.230:443
2018-10-28 19:41:0199514f451eeb65b87f37c7af8a8ad253Virustotal results 16/58 (27.59%) Gozi 144.217.37.230:443
2018-10-28 19:32:3858839f54c819de71db4eb2ba382cbca8Virustotal results 18/57 (31.58%) Gozi 144.217.37.230:443
2018-10-28 19:27:28fca4cf97760d1621516f585908c20449Virustotal results 22/58 (37.93%) Gozi 144.217.37.230:443
2018-10-28 14:54:19b5949d46713f6136496d697b966a1c16Virustotal results 17/58 (29.31%) Gozi 144.217.37.230:443
2018-10-28 13:42:19b54607d797af36fb6ec4db5dd0916ec8Virustotal results 23/57 (40.35%) Gozi 144.217.37.230:443

# of entries: 7 (max: 100)