SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint f5639b20d13517445e5dfb6c01d1f24df616b034.

Database Entry


SHA1 Fingerprint:f5639b20d13517445e5dfb6c01d1f24df616b034
Certificate Common Name (CN):tidiraone.icu
Issuer Distinguished Name (DN):Let's Encrypt Authority X3
TLS Version:TLS 1.2
First seen:2018-10-03 15:04:48 UTC
Last seen:2018-10-04 10:49:52 UTC
Status:Blacklisted
Listing reason:Gozi C&C
Listing date:2018-10-04 09:44:45
Malware samples:18
Botnet C&Cs:1

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2018-10-04 10:49:5217a9847e2dbf83dbf2f81539005e1e8cn/aGozi 185.246.153.252:443
2018-10-04 10:45:490232dab0ff834fb13f0a17ee05e7f1e8Virustotal results 33/69 (47.83%) Gozi 185.246.153.252:443
2018-10-04 10:39:0291fa4d4332b0018b2cf66b8a4a00e6d0n/aGozi 185.246.153.252:443
2018-10-04 10:32:149df46c5e010562c01e7776b70ae7a9cdn/aGozi 185.246.153.252:443
2018-10-04 07:51:36aeecf4f501293b8b334cf5fe0f97e6faVirustotal results 30/68 (44.12%) Gozi 185.246.153.252:443
2018-10-04 07:32:00cf6e87af545745f6bb6ab4fa7161badbVirustotal results 37/69 (53.62%) Gozi 185.246.153.252:443
2018-10-04 07:15:36085d610d456a0cf66a0a6f8aca30997bVirustotal results 32/68 (47.06%) Gozi 185.246.153.252:443
2018-10-04 06:47:478a34bda136a8e7858bac01c1f257d251n/aGozi 185.246.153.252:443
2018-10-04 06:36:33acb007032aaa9edfc05fb7f51e1151e7Virustotal results 32/69 (46.38%) Gozi 185.246.153.252:443
2018-10-04 06:31:41d919668b29eb88b6a530eec0406aa743Virustotal results 35/68 (51.47%) Gozi 185.246.153.252:443
2018-10-04 05:52:07a095b2fd75655cde20ea37152f55104fVirustotal results 30/68 (44.12%) Gozi 185.246.153.252:443
2018-10-03 19:46:108eac083433afc180c728fad286c37200n/aGozi 185.246.153.252:443
2018-10-03 19:11:30ed33fcde6695edccbd0d844f1a9ea373Virustotal results 36/68 (52.94%) Gozi 185.246.153.252:443
2018-10-03 15:50:4950597e436876e9c69996ac3147571733Virustotal results 18/58 (31.03%) Gozi 185.246.153.252:443
2018-10-03 15:50:392e85c942520922f0bde9eda50d4fa579Virustotal results 36/69 (52.17%) Gozi 185.246.153.252:443
2018-10-03 15:18:00c47d78b708d2d3a260d15ef3cfb58f87Virustotal results 36/68 (52.94%) Gozi 185.246.153.252:443
2018-10-03 15:05:01a569ebcf1078652e036190382d2e81f6Virustotal results 35/69 (50.72%) Gozi 185.246.153.252:443
2018-10-03 15:04:52cea99798368c5d89ccd16ea98a9c1a21Virustotal results 35/69 (50.72%) Gozi 185.246.153.252:443

# of entries: 18 (max: 100)