SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint bb694169bae7ce98f5ba83890fe4515f41abc805.

Database Entry


SHA1 Fingerprint:bb694169bae7ce98f5ba83890fe4515f41abc805
Certificate Common Name (CN):vilecorbeanca.xyz
Issuer Distinguished Name (DN):Let's Encrypt Authority X3
TLS Version:TLS 1.2
First seen:2020-07-12 22:30:56 UTC
Last seen:2020-07-13 08:03:34 UTC
Status:Blacklisted
Listing reason:Gozi C&C
Listing date:2020-07-13 07:25:07
Malware samples:20
Botnet C&Cs:1

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2020-07-13 08:03:34f933630c2ec6bbd2275f2507d4895ec5n/aGozi 188.130.138.207:443
2020-07-13 07:42:0751373389a8df39b4101b69346e3ba336n/aGozi 188.130.138.207:443
2020-07-13 00:24:04998b4bcb2362a38ef9908f6bcc067017n/aDridex 188.130.138.207:443
2020-07-13 00:17:147c1ea37c39ba7773b69fa0b5440f5383n/aDridex 188.130.138.207:443
2020-07-13 00:16:01f21c5191da0fa36c92e6337165312bd9n/aGozi 188.130.138.207:443
2020-07-13 00:14:404457af2a52bc95f50a3ef74414a35228n/aDridex 188.130.138.207:443
2020-07-13 00:13:182d73534d30043381aa344b34b192a766n/aGozi 188.130.138.207:443
2020-07-12 23:17:37fc34f0c7715d97e80cefe7d16bfe89b1n/aGozi 188.130.138.207:443
2020-07-12 23:14:02030f158fd0926dc576cfa44338a950d8n/aDridex 188.130.138.207:443
2020-07-12 23:09:514977df8be22a4034f021c9d4ebe7b07bn/aDridex 188.130.138.207:443
2020-07-12 23:09:22cbf4595d1fe0d7aff74002c35d4c7b84n/aDridex 188.130.138.207:443
2020-07-12 23:08:05909f9dd500ce23854fa4585d44e215e9n/aGozi 188.130.138.207:443
2020-07-12 23:06:188508a7ce21a3da5981aa82a0bcf60fafn/aDridex 188.130.138.207:443
2020-07-12 23:05:356625e7e399080c408f655b9cb093392an/aDridex 188.130.138.207:443
2020-07-12 23:02:116e5829a65869fe25c6f674edccc316ben/aGozi 188.130.138.207:443
2020-07-12 22:54:5493897aa2998c1991834aa52bf86c0ad5n/aGozi 188.130.138.207:443
2020-07-12 22:54:45977a186e004774a9d7a4bd45a3e93a47n/aDridex 188.130.138.207:443
2020-07-12 22:45:565e341c51a64b5af4b1cb300c2b05a157n/aDridex 188.130.138.207:443
2020-07-12 22:39:48c23654934d1d0d9d95a47f5d74fd99d6n/aGozi 188.130.138.207:443
2020-07-12 22:30:56228b50e37a8adedc50d8e76302b6f76en/aDridex 188.130.138.207:443

# of entries: 20 (max: 100)