SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint ba66b8103d8fa5c30eb64649bd24cfcb0893bf37.

Database Entry


SHA1 Fingerprint:ba66b8103d8fa5c30eb64649bd24cfcb0893bf37
Certificate Common Name (CN):*
Issuer Distinguished Name (DN):*
TLS Version:TLS 1.2
First seen:2018-10-23 12:45:13 UTC
Last seen:2018-10-29 10:57:50 UTC
Status:Blacklisted
Listing reason:Gozi C&C
Listing date:2018-10-29 08:22:22
Malware samples:85
Botnet C&Cs:1

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2018-10-29 10:57:50dbef8d7f59a0047f4493288afe296399Virustotal results 39/67 (58.21%) Gozi 54.39.81.120:443
2018-10-29 10:57:50dbef8d7f59a0047f4493288afe296399Virustotal results 39/67 (58.21%) Gozi 54.39.81.120:443
2018-10-29 10:25:5151bdb789c33e403b71d1dabbf7e8e97bVirustotal results 40/66 (60.61%) Gozi 54.39.81.120:443
2018-10-29 10:25:5151bdb789c33e403b71d1dabbf7e8e97bVirustotal results 40/66 (60.61%) Gozi 54.39.81.120:443
2018-10-29 05:08:215c92445dc18a68bccaa5283c26e6f979Virustotal results 36/67 (53.73%) Gozi 54.39.81.120:443
2018-10-29 05:08:215c92445dc18a68bccaa5283c26e6f979Virustotal results 36/67 (53.73%) Gozi 54.39.81.120:443
2018-10-29 00:43:137d8dac2009c4adf655f2fbb6a4e7f2a0Virustotal results 40/67 (59.70%) Gozi 54.39.81.120:443
2018-10-29 00:43:137d8dac2009c4adf655f2fbb6a4e7f2a0Virustotal results 40/67 (59.70%) Gozi 54.39.81.120:443
2018-10-28 23:34:285684676c9594bb9e1a8d4036be924ac5Virustotal results 40/68 (58.82%) Gozi 54.39.81.120:443
2018-10-28 23:34:285684676c9594bb9e1a8d4036be924ac5Virustotal results 40/68 (58.82%) Gozi 54.39.81.120:443
2018-10-26 17:21:36ed8ece4d9c7cade5ffd2d2256f9af7ccn/aGozi 54.39.81.120:443
2018-10-26 17:21:36ed8ece4d9c7cade5ffd2d2256f9af7ccn/aGozi 54.39.81.120:443
2018-10-26 13:49:5607a9a307b46d064570cef34cf4e8cb28Virustotal results 37/59 (62.71%) Gozi 54.39.81.120:443
2018-10-26 13:49:5607a9a307b46d064570cef34cf4e8cb28Virustotal results 37/59 (62.71%) Gozi 54.39.81.120:443
2018-10-26 08:48:195709ac4c61f9c1119d6a4ff24deaac6cn/aGozi 54.39.81.120:443
2018-10-26 08:48:195709ac4c61f9c1119d6a4ff24deaac6cn/aGozi 54.39.81.120:443
2018-10-25 13:27:52c13db2a62c93439c51b9746df496dd94Virustotal results 38/68 (55.88%) Gozi 54.39.81.120:443
2018-10-25 13:27:52c13db2a62c93439c51b9746df496dd94Virustotal results 38/68 (55.88%) Gozi 54.39.81.120:443
2018-10-25 12:36:412870f6814286e3cf823cf401017e944an/aGozi 54.39.81.120:443
2018-10-25 12:36:412870f6814286e3cf823cf401017e944an/aGozi 54.39.81.120:443
2018-10-25 08:43:49c644cee99ee75394621a7a53689d83d0Virustotal results 36/68 (52.94%) Gozi 54.39.81.120:443
2018-10-25 08:43:49c644cee99ee75394621a7a53689d83d0Virustotal results 36/68 (52.94%) Gozi 54.39.81.120:443
2018-10-24 22:21:198e6e9b54c9dd04ab6c1788819ec38a3dn/aGozi 54.39.81.120:443
2018-10-24 22:21:198e6e9b54c9dd04ab6c1788819ec38a3dn/aGozi 54.39.81.120:443
2018-10-24 20:47:54c35e275f852c23c54e854efe03bb6893Virustotal results 37/68 (54.41%) Gozi 54.39.81.120:443
2018-10-24 20:47:54c35e275f852c23c54e854efe03bb6893Virustotal results 37/68 (54.41%) Gozi 54.39.81.120:443
2018-10-24 19:40:019ba75f8286079f783a68ea6b32e2e041n/aGozi 54.39.81.120:443
2018-10-24 19:40:019ba75f8286079f783a68ea6b32e2e041n/aGozi 54.39.81.120:443
2018-10-24 19:15:220a89bebbfd22e752575ee54ebeb4fff0Virustotal results 37/68 (54.41%) Gozi 54.39.81.120:443
2018-10-24 19:15:220a89bebbfd22e752575ee54ebeb4fff0Virustotal results 37/68 (54.41%) Gozi 54.39.81.120:443
2018-10-24 19:12:5907b842a783a7682f7b2735083b2e9a23Virustotal results 47/67 (70.15%) Gozi 54.39.81.120:443
2018-10-24 19:12:5907b842a783a7682f7b2735083b2e9a23Virustotal results 47/67 (70.15%) Gozi 54.39.81.120:443
2018-10-24 17:07:542a1283dddbb86e070106018358d07e00n/aGozi 54.39.81.120:443
2018-10-24 17:07:542a1283dddbb86e070106018358d07e00n/aGozi 54.39.81.120:443
2018-10-24 17:06:1492ecf3a589d31562258dce635e965dd9n/aGozi 54.39.81.120:443
2018-10-24 17:06:1492ecf3a589d31562258dce635e965dd9n/aGozi 54.39.81.120:443
2018-10-24 16:30:46861e4887baff7f19600257e77db60fa6n/aGozi 54.39.81.120:443
2018-10-24 16:30:46861e4887baff7f19600257e77db60fa6n/aGozi 54.39.81.120:443
2018-10-24 15:30:52657273c02bd9416e88afac22c1e3abe6n/aGozi 54.39.81.120:443
2018-10-24 15:30:52657273c02bd9416e88afac22c1e3abe6n/aGozi 54.39.81.120:443
2018-10-24 15:28:380bfacd40a063994c96eb0828b7c0de1dVirustotal results 40/67 (59.70%) Gozi 54.39.81.120:443
2018-10-24 15:28:380bfacd40a063994c96eb0828b7c0de1dVirustotal results 40/67 (59.70%) Gozi 54.39.81.120:443
2018-10-24 15:25:007ea846d6ef9b390464c1d5e7e4b18c06n/aGozi 54.39.81.120:443
2018-10-24 15:25:007ea846d6ef9b390464c1d5e7e4b18c06n/aGozi 54.39.81.120:443
2018-10-24 15:09:020afa81ca59fd41c22fa2f280a08c1131Virustotal results 37/68 (54.41%) Gozi 54.39.81.120:443
2018-10-24 15:09:020afa81ca59fd41c22fa2f280a08c1131Virustotal results 37/68 (54.41%) Gozi 54.39.81.120:443
2018-10-24 14:16:117d25c08eda7e5936c7779c7918336362n/aGozi 54.39.81.120:443
2018-10-24 14:16:117d25c08eda7e5936c7779c7918336362n/aGozi 54.39.81.120:443
2018-10-24 13:37:27c78e0c7675fdc489e8190b0c74c5cabbVirustotal results 35/68 (51.47%) Gozi 54.39.81.120:443
2018-10-24 13:37:27c78e0c7675fdc489e8190b0c74c5cabbVirustotal results 35/68 (51.47%) Gozi 54.39.81.120:443
2018-10-24 13:32:52dd543b4f52282753aa51f789dfa6be36Virustotal results 36/69 (52.17%) Gozi 54.39.81.120:443
2018-10-24 13:32:52dd543b4f52282753aa51f789dfa6be36Virustotal results 36/69 (52.17%) Gozi 54.39.81.120:443
2018-10-24 12:47:427ef633ed257755ef59ed75de61d5e6c4n/aGozi 54.39.81.120:443
2018-10-24 12:47:427ef633ed257755ef59ed75de61d5e6c4n/aGozi 54.39.81.120:443
2018-10-24 12:33:45951c01f5190ad1ff819664a975e772a8n/aGozi 54.39.81.120:443
2018-10-24 12:33:45951c01f5190ad1ff819664a975e772a8n/aGozi 54.39.81.120:443
2018-10-24 12:32:090860842b566151ffbd57a2825ed95a9fVirustotal results 36/67 (53.73%) Formbook54.39.81.120:443
2018-10-24 12:32:090860842b566151ffbd57a2825ed95a9fVirustotal results 36/67 (53.73%) Formbook54.39.81.120:443
2018-10-24 12:17:04316f362430c98366d3060aa6b1f13379n/aGozi 54.39.81.120:443
2018-10-24 12:17:04316f362430c98366d3060aa6b1f13379n/aGozi 54.39.81.120:443
2018-10-24 11:56:201cbf81ceeab2e67734f4a88bc61ecbd8Virustotal results 49/67 (73.13%) Gozi 54.39.81.120:443
2018-10-24 11:56:201cbf81ceeab2e67734f4a88bc61ecbd8Virustotal results 49/67 (73.13%) Gozi 54.39.81.120:443
2018-10-24 11:45:35e8f6d1428be454a997d9427c2030847aVirustotal results 35/67 (52.24%) Gozi 54.39.81.120:443
2018-10-24 11:45:35e8f6d1428be454a997d9427c2030847aVirustotal results 35/67 (52.24%) Gozi 54.39.81.120:443
2018-10-24 11:42:16d1f5845ac8a530e3bb181fda1766cdc2Virustotal results 36/68 (52.94%) Gozi 54.39.81.120:443
2018-10-24 11:42:16d1f5845ac8a530e3bb181fda1766cdc2Virustotal results 36/68 (52.94%) Gozi 54.39.81.120:443
2018-10-24 11:23:57e55a5a92b6885abeb2cdffaf27c4fa7eVirustotal results 37/68 (54.41%) Gozi 54.39.81.120:443
2018-10-24 11:23:57e55a5a92b6885abeb2cdffaf27c4fa7eVirustotal results 37/68 (54.41%) Gozi 54.39.81.120:443
2018-10-24 11:19:09ded79567634af4e74a70a2caf7cfffccVirustotal results 36/67 (53.73%) Gozi 54.39.81.120:443
2018-10-24 11:19:09ded79567634af4e74a70a2caf7cfffccVirustotal results 36/67 (53.73%) Gozi 54.39.81.120:443
2018-10-24 11:13:447f6c03be742176acff32dcae1bbb0445n/aGozi 54.39.81.120:443
2018-10-24 11:13:447f6c03be742176acff32dcae1bbb0445n/aGozi 54.39.81.120:443
2018-10-24 11:04:29b4bcb8056f054b90676b3d4a6188fbd0Virustotal results 35/66 (53.03%) Gozi 54.39.81.120:443
2018-10-24 11:04:29b4bcb8056f054b90676b3d4a6188fbd0Virustotal results 35/66 (53.03%) Gozi 54.39.81.120:443
2018-10-24 10:56:247892913b2e18d2e6b52f5fe313d096bdn/aGozi 54.39.81.120:443
2018-10-24 10:56:247892913b2e18d2e6b52f5fe313d096bdn/aGozi 54.39.81.120:443
2018-10-24 10:39:325056c081d29b2dbed3cd9c4ebb29dec3n/aGozi 54.39.81.120:443
2018-10-24 10:39:325056c081d29b2dbed3cd9c4ebb29dec3n/aGozi 54.39.81.120:443
2018-10-24 10:31:06038d317798b88fca5923b496dd4d2089Virustotal results 36/67 (53.73%) Gozi 54.39.81.120:443
2018-10-24 10:31:06038d317798b88fca5923b496dd4d2089Virustotal results 36/67 (53.73%) Gozi 54.39.81.120:443
2018-10-24 09:49:20dc03591a124dd2c70ae063320ca8af40Virustotal results 37/67 (55.22%) Gozi 54.39.81.120:443
2018-10-24 09:49:20dc03591a124dd2c70ae063320ca8af40Virustotal results 37/67 (55.22%) Gozi 54.39.81.120:443
2018-10-24 09:31:54d6df2e42ddb72697fa0cb0d2d964ac8bVirustotal results 35/69 (50.72%) Gozi 54.39.81.120:443
2018-10-24 09:31:54d6df2e42ddb72697fa0cb0d2d964ac8bVirustotal results 35/69 (50.72%) Gozi 54.39.81.120:443
2018-10-24 09:16:55b1f1cb98089eda75deb0ecf30f6c420fVirustotal results 36/67 (53.73%) Gozi 54.39.81.120:443
2018-10-24 09:16:55b1f1cb98089eda75deb0ecf30f6c420fVirustotal results 36/67 (53.73%) Gozi 54.39.81.120:443
2018-10-24 08:59:52227bf403a2990dd20a43bc001dc0d42bn/aGozi 54.39.81.120:443
2018-10-24 08:59:52227bf403a2990dd20a43bc001dc0d42bn/aGozi 54.39.81.120:443
2018-10-24 08:54:394721a1e4222f14643749e157bf8dd479n/aGozi 54.39.81.120:443
2018-10-24 08:54:394721a1e4222f14643749e157bf8dd479n/aGozi 54.39.81.120:443
2018-10-24 08:43:599050a6dcbccabefc7dccbd785b1a4ef3n/aGozi 54.39.81.120:443
2018-10-24 08:43:599050a6dcbccabefc7dccbd785b1a4ef3n/aGozi 54.39.81.120:443
2018-10-24 08:37:09d117c3c893b7cbb7e082dc2eda4af11bVirustotal results 37/66 (56.06%) Gozi 54.39.81.120:443
2018-10-24 08:37:09d117c3c893b7cbb7e082dc2eda4af11bVirustotal results 37/66 (56.06%) Gozi 54.39.81.120:443
2018-10-24 08:20:237b26c85dcf8228530db89ca6bad2e37bn/aGozi 54.39.81.120:443
2018-10-24 08:20:237b26c85dcf8228530db89ca6bad2e37bn/aGozi 54.39.81.120:443
2018-10-24 08:02:3838a50f3a98af1beaf0143f21786fac12n/aGozi 54.39.81.120:443
2018-10-24 08:02:3838a50f3a98af1beaf0143f21786fac12n/aGozi 54.39.81.120:443
2018-10-24 07:53:51f8b323d6ed745c209ea71a1aea1e6b84Virustotal results 36/66 (54.55%) Gozi 54.39.81.120:443
2018-10-24 07:53:51f8b323d6ed745c209ea71a1aea1e6b84Virustotal results 36/66 (54.55%) Gozi 54.39.81.120:443

# of entries: 100 (max: 100)