SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint cb9097e27d1c16ff6d0574c2cce0fc0d066f0f8d.

Database Entry


SHA1 Fingerprint:cb9097e27d1c16ff6d0574c2cce0fc0d066f0f8d
Certificate Common Name (CN):tdsjsext6.com
Issuer Distinguished Name (DN):R3
TLS Version:TLS 1.2
First seen:2021-05-23 11:52:44 UTC
Last seen:2021-05-24 13:13:00 UTC
Status:Blacklisted
Listing reason:Gozi C&C
Listing date:2021-05-23 14:10:44
Malware samples:31
Botnet C&Cs:1

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2021-05-24 13:13:00027dd4c8bd3a8e4a6d23f63fcfffe892n/aGozi 185.50.248.49:443
2021-05-24 12:43:229f86a41f3ffda0f740f3b2328077d45dn/aGozi 185.50.248.49:443
2021-05-24 10:38:25b311f435f47825807eed0e54e0338670n/aGozi 185.50.248.49:443
2021-05-24 10:28:3369472b10d51de57775b06fdd0ea739b8n/aGozi 185.50.248.49:443
2021-05-24 10:02:105715030231a6ac6c946b4461d6c91032n/aGozi 185.50.248.49:443
2021-05-24 09:21:00c53084052c1175f6d771a12b60bae37dn/aGozi 185.50.248.49:443
2021-05-24 08:47:10ed650e426f8b0cfe77305db27a7524a3n/aGozi 185.50.248.49:443
2021-05-24 07:49:39f7dae384523150e82b4fa607d0288554n/aGozi 185.50.248.49:443
2021-05-24 07:26:16f5aaebd0d574e7bcf5bcee9e9d4a82ben/aGozi 185.50.248.49:443
2021-05-24 06:53:08e8a3c694fc39f2fc11cc98a039092d9cn/aGozi 185.50.248.49:443
2021-05-24 06:32:170503fec93d7e4902e9e2de90ba2d70fcn/aGozi 185.50.248.49:443
2021-05-24 05:47:4634e3dec3c347c0f8882af6bf35dc6053n/aGozi 185.50.248.49:443
2021-05-24 05:26:06051265a9bf890f1963b95b45cff85a70n/aGozi 185.50.248.49:443
2021-05-24 04:24:32526b7faa3b330ec7390cfd501504e7ecn/aGozi 185.50.248.49:443
2021-05-24 03:58:095172c1fa183a05af6e61824cc537a16fn/aGozi 185.50.248.49:443
2021-05-24 02:31:14aa0504acb9d1ae967323137832275849n/aGozi 185.50.248.49:443
2021-05-24 02:06:11ef1bbe7c50300026f38483c39d400384n/aGozi 185.50.248.49:443
2021-05-24 01:46:026f3ea32d08f95a30263a01da09082c4bn/aGozi 185.50.248.49:443
2021-05-24 01:33:24e4f8503f3a496c4a4ba0cc59a9d395ccn/aGozi 185.50.248.49:443
2021-05-24 01:32:53d99def97b28d3a8be5a355f94467e21fn/aGozi 185.50.248.49:443
2021-05-24 01:30:16aa00eb9458ddbbb663eb66ee80dbedc5Virustotal results 37 / 69 (53.62%) Gozi 185.50.248.49:443
2021-05-24 01:29:46713e16108deabb13d773ce36f5dc002cVirustotal results 39 / 69 (56.52%) Gozi 185.50.248.49:443
2021-05-24 01:27:513bd0a0df4b002da98fe56f89c982b16cVirustotal results 37 / 69 (53.62%) Gozi 185.50.248.49:443
2021-05-24 01:25:45492076d2d0e123d67a38e65ad5aaee6aVirustotal results 40 / 69 (57.97%) Gozi 185.50.248.49:443
2021-05-23 19:28:3603c3428647fab84180e189042b6c85e5Virustotal results 37 / 69 (53.62%) Gozi 185.50.248.49:443
2021-05-23 15:41:24b45181979facd5485184f32a5045d637n/aGozi 185.50.248.49:443
2021-05-23 14:46:162348dd9b6f9f9e98305c239412278190n/aGozi 185.50.248.49:443
2021-05-23 14:07:511da0601d46dd56e2cfff320376dcf6d9n/aGozi 185.50.248.49:443
2021-05-23 13:36:049fcf3ab8703045032737668793f5563bn/aGozi 185.50.248.49:443
2021-05-23 13:30:0006b71339cf8eae41cddbdef17e4dba9fn/aGozi 185.50.248.49:443
2021-05-23 11:52:449d20ef32ffa9b3efbca81407fec42a78n/aGozi 185.50.248.49:443

# of entries: 31 (max: 100)