SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint adb1c86b00ed2ad38e00428d8f348d53d5f85967.

Database Entry


SHA1 Fingerprint:adb1c86b00ed2ad38e00428d8f348d53d5f85967
Certificate Common Name (CN):*
Issuer Distinguished Name (DN):*
TLS Version:TLS 1.2' NOTBEF
First seen:2018-11-20 21:45:22 UTC
Last seen:2018-11-27 08:58:51 UTC
Status:Blacklisted
Listing reason:Gozi C&C
Listing date:2018-11-27 09:11:29
Malware samples:5
Botnet C&Cs:1

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2018-11-27 08:58:5197992fdd94a1838b1d3a6f14786352f6Virustotal results 36/69 (52.17%) Gozi 178.162.132.76:443
2018-11-27 08:58:5197992fdd94a1838b1d3a6f14786352f6Virustotal results 36/69 (52.17%) Gozi 178.162.132.76:443
2018-11-27 07:26:12ec1b8dd33166071bb34c85646373eb08Virustotal results 26/69 (37.68%) Gozi 178.162.132.76:443
2018-11-27 07:26:12ec1b8dd33166071bb34c85646373eb08Virustotal results 26/69 (37.68%) Gozi 178.162.132.76:443
2018-11-25 13:03:53dff8a5332a963f338da262adfec3c28eVirustotal results 20/69 (28.99%) Gozi 178.162.132.76:443
2018-11-25 13:03:53dff8a5332a963f338da262adfec3c28eVirustotal results 20/69 (28.99%) Gozi 178.162.132.76:443
2018-11-22 21:11:23972f5eab223873eebb324785829ad372Virustotal results 37/68 (54.41%) Gozi 178.162.132.76:443
2018-11-22 21:11:23972f5eab223873eebb324785829ad372Virustotal results 37/68 (54.41%) Gozi 178.162.132.76:443
2018-11-20 21:45:231c177bfa9ccc1624fca79db3fad18cc1Virustotal results 13/67 (19.40%) Gozi 178.162.132.76:443
2018-11-20 21:45:231c177bfa9ccc1624fca79db3fad18cc1Virustotal results 13/67 (19.40%) Gozi 178.162.132.76:443

# of entries: 10 (max: 100)