SSL Certificates
The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint ed0c166e2af7f79874a89c97d038349e10e9cea9.
Database Entry
SHA1 Fingerprint: | ed0c166e2af7f79874a89c97d038349e10e9cea9 |
---|---|
Certificate Common Name (CN): | *.grounddoesstart.live |
Issuer Distinguished Name (DN): | R3 |
TLS Version: | TLS 1.2 |
First seen: | 2021-05-24 01:25:44 UTC |
Last seen: | 2021-05-24 06:53:07 UTC |
Status: | Blacklisted |
Listing reason: | Gozi C&C |
Listing date: | 2021-05-24 06:38:15 |
Malware samples: | 17 |
Botnet C&Cs: | 1 |
Malware Samples
The table below documents all malware samples associated with this SSL certificate.
Timestamp (UTC) | Malware Sample (MD5 hash) | VT | Signature | Botnet C&C (IP:port) |
---|---|---|---|---|
2021-05-24 06:53:07 | e8a3c694fc39f2fc11cc98a039092d9c | n/a | Gozi | 31.44.185.19:443 |
2021-05-24 06:53:07 | e8a3c694fc39f2fc11cc98a039092d9c | n/a | Gozi | 31.44.185.19:443 |
2021-05-24 06:32:16 | 0503fec93d7e4902e9e2de90ba2d70fc | n/a | Gozi | 31.44.185.19:443 |
2021-05-24 06:32:16 | 0503fec93d7e4902e9e2de90ba2d70fc | n/a | Gozi | 31.44.185.19:443 |
2021-05-24 06:23:50 | 7837a49cac10d6ab48c654f93d3b2bf7 | n/a | Gozi | 31.44.185.19:443 |
2021-05-24 06:23:50 | 7837a49cac10d6ab48c654f93d3b2bf7 | n/a | Gozi | 31.44.185.19:443 |
2021-05-24 05:47:42 | 34e3dec3c347c0f8882af6bf35dc6053 | n/a | Gozi | 31.44.185.19:443 |
2021-05-24 05:47:42 | 34e3dec3c347c0f8882af6bf35dc6053 | n/a | Gozi | 31.44.185.19:443 |
2021-05-24 05:26:05 | 051265a9bf890f1963b95b45cff85a70 | n/a | Gozi | 31.44.185.19:443 |
2021-05-24 05:26:05 | 051265a9bf890f1963b95b45cff85a70 | n/a | Gozi | 31.44.185.19:443 |
2021-05-24 04:24:29 | 526b7faa3b330ec7390cfd501504e7ec | n/a | Gozi | 31.44.185.19:443 |
2021-05-24 04:24:29 | 526b7faa3b330ec7390cfd501504e7ec | n/a | Gozi | 31.44.185.19:443 |
2021-05-24 03:58:06 | 5172c1fa183a05af6e61824cc537a16f | n/a | Gozi | 31.44.185.19:443 |
2021-05-24 03:58:06 | 5172c1fa183a05af6e61824cc537a16f | n/a | Gozi | 31.44.185.19:443 |
2021-05-24 02:31:12 | aa0504acb9d1ae967323137832275849 | n/a | Gozi | 31.44.185.19:443 |
2021-05-24 02:31:12 | aa0504acb9d1ae967323137832275849 | n/a | Gozi | 31.44.185.19:443 |
2021-05-24 02:06:08 | ef1bbe7c50300026f38483c39d400384 | n/a | Gozi | 31.44.185.19:443 |
2021-05-24 02:06:08 | ef1bbe7c50300026f38483c39d400384 | n/a | Gozi | 31.44.185.19:443 |
2021-05-24 01:45:54 | 6f3ea32d08f95a30263a01da09082c4b | n/a | Gozi | 31.44.185.19:443 |
2021-05-24 01:45:54 | 6f3ea32d08f95a30263a01da09082c4b | n/a | Gozi | 31.44.185.19:443 |
2021-05-24 01:33:43 | db3d0749f2905024807ae7f53e843f49 | 39 / 69 (56.52%) | Gozi | 31.44.185.19:443 |
2021-05-24 01:33:43 | db3d0749f2905024807ae7f53e843f49 | 39 / 69 (56.52%) | Gozi | 31.44.185.19:443 |
2021-05-24 01:33:21 | e4f8503f3a496c4a4ba0cc59a9d395cc | n/a | Gozi | 31.44.185.19:443 |
2021-05-24 01:33:21 | e4f8503f3a496c4a4ba0cc59a9d395cc | n/a | Gozi | 31.44.185.19:443 |
2021-05-24 01:32:50 | d99def97b28d3a8be5a355f94467e21f | n/a | Gozi | 31.44.185.19:443 |
2021-05-24 01:32:50 | d99def97b28d3a8be5a355f94467e21f | n/a | Gozi | 31.44.185.19:443 |
2021-05-24 01:30:12 | aa00eb9458ddbbb663eb66ee80dbedc5 | 37 / 69 (53.62%) | Gozi | 31.44.185.19:443 |
2021-05-24 01:30:12 | aa00eb9458ddbbb663eb66ee80dbedc5 | 37 / 69 (53.62%) | Gozi | 31.44.185.19:443 |
2021-05-24 01:29:39 | 713e16108deabb13d773ce36f5dc002c | 39 / 69 (56.52%) | Gozi | 31.44.185.19:443 |
2021-05-24 01:29:39 | 713e16108deabb13d773ce36f5dc002c | 39 / 69 (56.52%) | Gozi | 31.44.185.19:443 |
2021-05-24 01:27:48 | 3bd0a0df4b002da98fe56f89c982b16c | 37 / 69 (53.62%) | Gozi | 31.44.185.19:443 |
2021-05-24 01:27:48 | 3bd0a0df4b002da98fe56f89c982b16c | 37 / 69 (53.62%) | Gozi | 31.44.185.19:443 |
2021-05-24 01:25:44 | 492076d2d0e123d67a38e65ad5aaee6a | 40 / 69 (57.97%) | Gozi | 31.44.185.19:443 |
2021-05-24 01:25:44 | 492076d2d0e123d67a38e65ad5aaee6a | 40 / 69 (57.97%) | Gozi | 31.44.185.19:443 |
# of entries: 34 (max: 100)