SSL Certificates
The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint c1f87bec7cd36db02855527a8b47555425c1504e.
Database Entry
SHA1 Fingerprint: | c1f87bec7cd36db02855527a8b47555425c1504e |
---|---|
Certificate Common Name (CN): | etc/emailAddress=support@site.com |
Issuer Distinguished Name (DN): | etc/emailAddress=support@site.com |
TLS Version: | TLS 1.2 |
First seen: | 2015-09-22 14:45:47 UTC |
Last seen: | 2016-04-17 03:51:55 UTC |
Status: | Blacklisted |
Listing reason: | Gozi C&C |
Listing date: | 2015-09-23 09:49:11 |
Malware samples: | 22 |
Botnet C&Cs: | 9 |
Malware Samples
The table below documents all malware samples associated with this SSL certificate.
Timestamp (UTC) | Malware Sample (MD5 hash) | VT | Signature | Botnet C&C (IP:port) |
---|---|---|---|---|
2016-04-17 03:51:55 | 05b9003db1972d382be4be6bd897f81c | 9/57 (15.79%) | Gozi | 62.213.103.173:443 |
2016-04-17 03:51:55 | 05b9003db1972d382be4be6bd897f81c | 9/57 (15.79%) | Gozi | 62.213.103.173:443 |
2016-04-10 18:22:48 | 43624f4d7586146107c9dc1c373bb06a | 10/57 (17.54%) | Gozi | 37.46.131.147:443 |
2016-04-10 18:22:48 | 43624f4d7586146107c9dc1c373bb06a | 10/57 (17.54%) | Gozi | 37.46.131.147:443 |
2016-04-10 11:14:50 | ff39ee556744c3232350e5151080d395 | 7/57 (12.28%) | Gozi | 37.46.131.147:443 |
2016-04-10 11:14:50 | ff39ee556744c3232350e5151080d395 | 7/57 (12.28%) | Gozi | 37.46.131.147:443 |
2016-02-22 22:48:31 | c62c2f1f38563951ebb3c9d444a6c86c | 3/56 (5.36%) | Gozi | 31.41.45.9:443 |
2016-02-22 22:48:31 | c62c2f1f38563951ebb3c9d444a6c86c | 3/56 (5.36%) | Gozi | 31.41.45.9:443 |
2016-02-21 18:32:13 | cc6082461b2b979e7f8375a1f75caa72 | 18/55 (32.73%) | Gozi | 31.41.45.9:443 |
2016-02-21 18:32:13 | cc6082461b2b979e7f8375a1f75caa72 | 18/55 (32.73%) | Gozi | 31.41.45.9:443 |
2016-02-21 16:18:38 | 7b73dd0a492c462da46f031270c8227d | 23/52 (44.23%) | Gozi | 31.41.45.9:443 |
2016-02-21 16:18:38 | 7b73dd0a492c462da46f031270c8227d | 23/52 (44.23%) | Gozi | 31.41.45.9:443 |
2016-02-21 14:06:29 | 6b91c03fbbebd4dff44e4e4b305fedf4 | 28/57 (49.12%) | Gozi | 31.41.45.9:443 |
2016-02-21 14:06:29 | 6b91c03fbbebd4dff44e4e4b305fedf4 | 28/57 (49.12%) | Gozi | 31.41.45.9:443 |
2016-02-19 21:19:13 | acad8b10c5d4ef7f212e0a54c6fb95cc | 27/55 (49.09%) | Gozi | 31.41.45.9:443 |
2016-02-19 21:19:13 | acad8b10c5d4ef7f212e0a54c6fb95cc | 27/55 (49.09%) | Gozi | 31.41.45.9:443 |
2016-02-19 20:59:05 | c200e522d04652f6a8f88c753d41394e | 25/55 (45.45%) | Gozi | 31.41.45.9:443 |
2016-02-19 20:59:05 | c200e522d04652f6a8f88c753d41394e | 25/55 (45.45%) | Gozi | 31.41.45.9:443 |
2016-02-19 18:06:51 | dfc99f48e23eccacda66bf894dea140d | 12/56 (21.43%) | Gozi | 31.41.45.9:443 |
2016-02-19 18:06:51 | dfc99f48e23eccacda66bf894dea140d | 12/56 (21.43%) | Gozi | 31.41.45.9:443 |
2016-02-19 18:01:25 | 81e6ffdf386245a073d12d80519a32e3 | 20/55 (36.36%) | Gozi | 31.41.45.9:443 |
2016-02-19 18:01:25 | 81e6ffdf386245a073d12d80519a32e3 | 20/55 (36.36%) | Gozi | 31.41.45.9:443 |
2016-01-13 10:18:59 | ce0ba205e6ec932857ecab6c39ea4364 | 53/71 (74.65%) | Gozi | 185.14.28.9:443 |
2016-01-13 10:18:59 | ce0ba205e6ec932857ecab6c39ea4364 | 53/71 (74.65%) | Gozi | 185.14.28.9:443 |
2015-12-26 19:11:18 | 98ffeae38b1e87bacecfbf773d2a8a80 | n/a | Gozi | 31.41.44.5:443 |
2015-12-26 19:11:18 | 98ffeae38b1e87bacecfbf773d2a8a80 | n/a | Gozi | 31.41.44.5:443 |
2015-12-26 14:00:33 | cc3ee0ee8ab5c0c1288f7698660e9c91 | 2/53 (3.77%) | Gozi | 31.41.44.5:443 |
2015-12-26 14:00:33 | cc3ee0ee8ab5c0c1288f7698660e9c91 | 2/53 (3.77%) | Gozi | 31.41.44.5:443 |
2015-12-15 15:36:15 | 35032e5ffe92dc1cd99ac25d4830fe83 | 34/53 (64.15%) | Gozi | 95.215.108.11:443 |
2015-12-15 15:36:15 | 35032e5ffe92dc1cd99ac25d4830fe83 | 34/53 (64.15%) | Gozi | 95.215.108.11:443 |
2015-12-14 18:33:31 | d77e103592d3787d84da1c3b93f5d069 | 2/56 (3.57%) | Gozi | 95.215.108.11:443 |
2015-12-14 18:33:31 | d77e103592d3787d84da1c3b93f5d069 | 2/56 (3.57%) | Gozi | 95.215.108.11:443 |
2015-11-16 02:28:32 | f8255a56d46f46887745a974d0b31241 | 7/55 (12.73%) | Gozi | 185.82.202.73:443 |
2015-11-16 02:28:32 | f8255a56d46f46887745a974d0b31241 | 7/55 (12.73%) | Gozi | 185.82.202.73:443 |
2015-11-15 08:20:46 | 7505d042ab97eda1391adcf87a95ebce | 23/56 (41.07%) | Gozi | 185.82.202.73:443 |
2015-11-15 08:20:46 | 7505d042ab97eda1391adcf87a95ebce | 23/56 (41.07%) | Gozi | 185.82.202.73:443 |
2015-10-17 11:29:08 | c4829aec136b34edb57c678fb97ffc42 | 2/54 (3.70%) | Gozi | 95.215.108.70:443 |
2015-10-17 11:29:08 | c4829aec136b34edb57c678fb97ffc42 | 2/54 (3.70%) | Gozi | 95.215.108.70:443 |
2015-10-16 08:39:03 | de414d7c488aa54e9a5fe8deb706bee7 | 5/53 (9.43%) | Gozi | 95.215.108.70:443 |
2015-10-16 08:39:03 | de414d7c488aa54e9a5fe8deb706bee7 | 5/53 (9.43%) | Gozi | 95.215.108.70:443 |
2015-09-28 22:22:51 | 5d9d3491f0ca5039e480f57dc59467d8 | 28/56 (50.00%) | Gozi | 95.215.108.70:443 |
2015-09-28 22:22:51 | 5d9d3491f0ca5039e480f57dc59467d8 | 28/56 (50.00%) | Gozi | 95.215.108.70:443 |
2015-09-22 14:45:47 | c7872508eededb17cf864886270fd3e9 | 3/56 (5.36%) | Gozi | 185.82.200.100:443 |
2015-09-22 14:45:47 | c7872508eededb17cf864886270fd3e9 | 3/56 (5.36%) | Gozi | 185.82.200.100:443 |
# of entries: 44 (max: 100)