SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint ba66b8103d8fa5c30eb64649bd24cfcb0893bf37.

Database Entry


SHA1 Fingerprint:ba66b8103d8fa5c30eb64649bd24cfcb0893bf37
Certificate Common Name (CN):*
Issuer Distinguished Name (DN):*
TLS Version:TLS 1.2
First seen:2018-10-23 12:45:13 UTC
Last seen:2018-10-29 10:57:50 UTC
Status:Blacklisted
Listing reason:Gozi C&C
Listing date:2018-10-29 08:22:22
Malware samples:85
Botnet C&Cs:1

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2018-10-29 10:57:50dbef8d7f59a0047f4493288afe296399Virustotal results 39/67 (58.21%) Gozi 54.39.81.120:443
2018-10-29 10:25:5151bdb789c33e403b71d1dabbf7e8e97bVirustotal results 40/66 (60.61%) Gozi 54.39.81.120:443
2018-10-29 05:08:215c92445dc18a68bccaa5283c26e6f979Virustotal results 36/67 (53.73%) Gozi 54.39.81.120:443
2018-10-29 00:43:137d8dac2009c4adf655f2fbb6a4e7f2a0Virustotal results 40/67 (59.70%) Gozi 54.39.81.120:443
2018-10-28 23:34:285684676c9594bb9e1a8d4036be924ac5Virustotal results 40/68 (58.82%) Gozi 54.39.81.120:443
2018-10-26 17:21:36ed8ece4d9c7cade5ffd2d2256f9af7ccn/aGozi 54.39.81.120:443
2018-10-26 13:49:5607a9a307b46d064570cef34cf4e8cb28Virustotal results 37/59 (62.71%) Gozi 54.39.81.120:443
2018-10-26 08:48:195709ac4c61f9c1119d6a4ff24deaac6cn/aGozi 54.39.81.120:443
2018-10-25 13:27:52c13db2a62c93439c51b9746df496dd94Virustotal results 38/68 (55.88%) Gozi 54.39.81.120:443
2018-10-25 12:36:412870f6814286e3cf823cf401017e944an/aGozi 54.39.81.120:443
2018-10-25 08:43:49c644cee99ee75394621a7a53689d83d0Virustotal results 36/68 (52.94%) Gozi 54.39.81.120:443
2018-10-24 22:21:198e6e9b54c9dd04ab6c1788819ec38a3dn/aGozi 54.39.81.120:443
2018-10-24 20:47:54c35e275f852c23c54e854efe03bb6893Virustotal results 37/68 (54.41%) Gozi 54.39.81.120:443
2018-10-24 19:40:019ba75f8286079f783a68ea6b32e2e041n/aGozi 54.39.81.120:443
2018-10-24 19:15:220a89bebbfd22e752575ee54ebeb4fff0Virustotal results 37/68 (54.41%) Gozi 54.39.81.120:443
2018-10-24 19:12:5907b842a783a7682f7b2735083b2e9a23Virustotal results 47/67 (70.15%) Gozi 54.39.81.120:443
2018-10-24 17:07:542a1283dddbb86e070106018358d07e00n/aGozi 54.39.81.120:443
2018-10-24 17:06:1492ecf3a589d31562258dce635e965dd9n/aGozi 54.39.81.120:443
2018-10-24 16:30:46861e4887baff7f19600257e77db60fa6n/aGozi 54.39.81.120:443
2018-10-24 15:30:52657273c02bd9416e88afac22c1e3abe6n/aGozi 54.39.81.120:443
2018-10-24 15:28:380bfacd40a063994c96eb0828b7c0de1dVirustotal results 40/67 (59.70%) Gozi 54.39.81.120:443
2018-10-24 15:25:007ea846d6ef9b390464c1d5e7e4b18c06n/aGozi 54.39.81.120:443
2018-10-24 15:09:020afa81ca59fd41c22fa2f280a08c1131Virustotal results 37/68 (54.41%) Gozi 54.39.81.120:443
2018-10-24 14:16:117d25c08eda7e5936c7779c7918336362n/aGozi 54.39.81.120:443
2018-10-24 13:37:27c78e0c7675fdc489e8190b0c74c5cabbVirustotal results 35/68 (51.47%) Gozi 54.39.81.120:443
2018-10-24 13:32:52dd543b4f52282753aa51f789dfa6be36Virustotal results 36/69 (52.17%) Gozi 54.39.81.120:443
2018-10-24 12:47:427ef633ed257755ef59ed75de61d5e6c4n/aGozi 54.39.81.120:443
2018-10-24 12:33:45951c01f5190ad1ff819664a975e772a8n/aGozi 54.39.81.120:443
2018-10-24 12:32:090860842b566151ffbd57a2825ed95a9fVirustotal results 36/67 (53.73%) Formbook54.39.81.120:443
2018-10-24 12:17:04316f362430c98366d3060aa6b1f13379n/aGozi 54.39.81.120:443
2018-10-24 11:56:201cbf81ceeab2e67734f4a88bc61ecbd8Virustotal results 49/67 (73.13%) Gozi 54.39.81.120:443
2018-10-24 11:45:35e8f6d1428be454a997d9427c2030847aVirustotal results 35/67 (52.24%) Gozi 54.39.81.120:443
2018-10-24 11:42:16d1f5845ac8a530e3bb181fda1766cdc2Virustotal results 36/68 (52.94%) Gozi 54.39.81.120:443
2018-10-24 11:23:57e55a5a92b6885abeb2cdffaf27c4fa7eVirustotal results 37/68 (54.41%) Gozi 54.39.81.120:443
2018-10-24 11:19:09ded79567634af4e74a70a2caf7cfffccVirustotal results 36/67 (53.73%) Gozi 54.39.81.120:443
2018-10-24 11:13:447f6c03be742176acff32dcae1bbb0445n/aGozi 54.39.81.120:443
2018-10-24 11:04:29b4bcb8056f054b90676b3d4a6188fbd0Virustotal results 35/66 (53.03%) Gozi 54.39.81.120:443
2018-10-24 10:56:247892913b2e18d2e6b52f5fe313d096bdn/aGozi 54.39.81.120:443
2018-10-24 10:39:325056c081d29b2dbed3cd9c4ebb29dec3n/aGozi 54.39.81.120:443
2018-10-24 10:31:06038d317798b88fca5923b496dd4d2089Virustotal results 36/67 (53.73%) Gozi 54.39.81.120:443
2018-10-24 09:49:20dc03591a124dd2c70ae063320ca8af40Virustotal results 37/67 (55.22%) Gozi 54.39.81.120:443
2018-10-24 09:31:54d6df2e42ddb72697fa0cb0d2d964ac8bVirustotal results 35/69 (50.72%) Gozi 54.39.81.120:443
2018-10-24 09:16:55b1f1cb98089eda75deb0ecf30f6c420fVirustotal results 36/67 (53.73%) Gozi 54.39.81.120:443
2018-10-24 08:59:52227bf403a2990dd20a43bc001dc0d42bn/aGozi 54.39.81.120:443
2018-10-24 08:54:394721a1e4222f14643749e157bf8dd479n/aGozi 54.39.81.120:443
2018-10-24 08:43:599050a6dcbccabefc7dccbd785b1a4ef3n/aGozi 54.39.81.120:443
2018-10-24 08:37:09d117c3c893b7cbb7e082dc2eda4af11bVirustotal results 37/66 (56.06%) Gozi 54.39.81.120:443
2018-10-24 08:20:237b26c85dcf8228530db89ca6bad2e37bn/aGozi 54.39.81.120:443
2018-10-24 08:02:3838a50f3a98af1beaf0143f21786fac12n/aGozi 54.39.81.120:443
2018-10-24 07:53:51f8b323d6ed745c209ea71a1aea1e6b84Virustotal results 36/66 (54.55%) Gozi 54.39.81.120:443
2018-10-24 07:20:5823bf168372b8663a954f0b2892ddbd7cn/aGozi 54.39.81.120:443
2018-10-24 07:20:17c7ca8e6cdc760087e0a24e4e8ce09e2eVirustotal results 33/68 (48.53%) Gozi 54.39.81.120:443
2018-10-24 06:34:200e5d5560743e9764da4b1280df0ca65aVirustotal results 47/65 (72.31%) Gozi 54.39.81.120:443
2018-10-24 05:42:568c3ca353da4c41c402390ee3c43501f0n/aGozi 54.39.81.120:443
2018-10-24 04:51:38a97412921853a0aabf870c8f3bb2e3feVirustotal results 36/68 (52.94%) Gozi 54.39.81.120:443
2018-10-24 03:48:06e12b5f44f09904ce15dfee6495d33a7dVirustotal results 35/66 (53.03%) Gozi 54.39.81.120:443
2018-10-24 03:34:1445124a9bbc12887b0d7e05efe5148a55n/aGozi 54.39.81.120:443
2018-10-24 02:55:5346eec94be58c1cfc9b80dfd3d926733fn/aGozi 54.39.81.120:443
2018-10-24 02:06:25237c470efcdf620b50c2ec03167ed76an/aGozi 54.39.81.120:443
2018-10-24 01:50:33f6eb75f81c001e15b83e055e3a61cc14Virustotal results 35/68 (51.47%) Gozi 54.39.81.120:443
2018-10-24 00:41:46b0dc4b495677ec39fcc5c661da3938f0Virustotal results 36/68 (52.94%) Gozi 54.39.81.120:443
2018-10-24 00:40:065aac92c98b10375786e32cfa9d85bf2cn/aGozi 54.39.81.120:443
2018-10-24 00:28:294bca123087d0c61d410fa028c550ed70n/aGozi 54.39.81.120:443
2018-10-24 00:10:10cebb4cd12271746ed9fbe07a0eea877fVirustotal results 36/68 (52.94%) Gozi 54.39.81.120:443
2018-10-23 23:37:12d48d67bc5053a8be9a636fb3fd3140e2Virustotal results 36/67 (53.73%) Gozi 54.39.81.120:443
2018-10-23 23:33:41f982f98f0a962d431ebbe8f5567bc11dVirustotal results 35/67 (52.24%) Gozi 54.39.81.120:443
2018-10-23 22:54:09de7f20f34ce2548ca908a303b9f66463Virustotal results 47/68 (69.12%) Gozi 54.39.81.120:443
2018-10-23 22:53:12c82aad642de0420b14347146c115e214Virustotal results 36/66 (54.55%) AZORult 54.39.81.120:443
2018-10-23 22:20:54bbf7520bc956049b4e1b4846aaf26a3cVirustotal results 35/67 (52.24%) Gozi 54.39.81.120:443
2018-10-23 22:19:325cd1ecc2994c61d0f77183543d45bd26n/aGozi 54.39.81.120:443
2018-10-23 22:09:53a4a3ec9788ee005d4a9120b94683540cVirustotal results 34/65 (52.31%) Gozi 54.39.81.120:443
2018-10-23 21:47:21fcdc3f43dca6f96496334d1fbc884d2fVirustotal results 36/68 (52.94%) Gozi 54.39.81.120:443
2018-10-23 21:22:07366a4449f5182e5212f41ac8b3d3d0ebn/aGozi 54.39.81.120:443
2018-10-23 21:20:26427bae6698c998f7924cbcb4987a4871n/aGozi 54.39.81.120:443
2018-10-23 21:14:30ec12112dd7704316bab42558210d6242Virustotal results 36/68 (52.94%) Gozi 54.39.81.120:443
2018-10-23 21:01:06cf863ee792459c01d0104858fc1fcfddVirustotal results 36/67 (53.73%) Gozi 54.39.81.120:443
2018-10-23 21:00:036e2d2b2fb2fc29f35a6ad6fee4350182n/aGozi 54.39.81.120:443
2018-10-23 20:28:257cff42283e677ab39fd0172d807ec056n/aGozi 54.39.81.120:443
2018-10-23 20:23:425409aec695a83f9232e3563a0ce35a31n/aGozi 54.39.81.120:443
2018-10-23 15:53:2305446f1188f7bc2c3a36dcd7fbfdbc3cVirustotal results 8/67 (11.94%) Gozi 54.39.81.120:443
2018-10-23 15:12:236b1604c81030674507eb4b79f969de7fn/aGozi 54.39.81.120:443
2018-10-23 14:49:599ae1ef732e360966e506bc13f0b98a36n/aGozi 54.39.81.120:443
2018-10-23 13:31:068709332e4dfc39d2b8d032c85e35d2e7n/aGozi 54.39.81.120:443
2018-10-23 13:20:0722e6a25564cd24c26795ad2c57985e94n/aGozi 54.39.81.120:443
2018-10-23 12:45:1439e83a70da98ba0ea7ede57a8b6338bfVirustotal results 16/57 (28.07%) Gozi 54.39.81.120:443

# of entries: 85 (max: 100)