SSL Certificates

The following table shows further information as well as a list of malware samples including the corresponding botnet C&C associated with the SSL certificate fingerprint 1b55e71e5b641a7ba5ea0e99ee0e6f1980ec9ae3.

Database Entry


SHA1 Fingerprint:1b55e71e5b641a7ba5ea0e99ee0e6f1980ec9ae3
Certificate Common Name (CN):kiff.store
Issuer Distinguished Name (DN):R3
TLS Version:TLSv1
First seen:2021-06-02 17:27:41 UTC
Last seen:2021-06-06 04:21:12 UTC
Status:Blacklisted
Listing reason:Malware C&C
Listing date:2021-06-03 18:49:10
Malware samples:9
Botnet C&Cs:1

Malware Samples


The table below documents all malware samples associated with this SSL certificate.

Timestamp (UTC)Malware Sample (MD5 hash)VTSignatureBotnet C&C (IP:port)
2021-06-06 04:21:1207a068530e89b8030f16d62c814ac7cfn/aAdware.FileTour185.250.204.130:443
2021-06-04 07:41:53cfa2b58f744340f2825b16fbe54f82fbVirustotal results 33 / 69 (47.83%) RaccoonStealer185.250.204.130:443
2021-06-04 02:10:27a6c18ea55934592156bf5e3bd8ee7c8eVirustotal results 42 / 70 (60.00%) RedLineStealer185.250.204.130:443
2021-06-03 20:24:488e4639500eac5465dc0475be84156667Virustotal results 41 / 69 (59.42%) ArkeiStealer185.250.204.130:443
2021-06-03 17:13:431fecb6eb98e8ee72bb5f006dd79c6f2fVirustotal results 27 / 70 (38.57%) RaccoonStealer185.250.204.130:443
2021-06-03 13:02:16db4a917bdaa25195ccb4706b77a817f6Virustotal results 28 / 70 (40.00%) Adware.FileTour185.250.204.130:443
2021-06-03 10:49:44b00f279b575b3f07a06352a37a378323Virustotal results 40 / 68 (58.82%) CryptBot185.250.204.130:443
2021-06-03 07:53:57f7b95569f9898370aea6f4b59b9e97fbVirustotal results 38 / 70 (54.29%) CryptBot185.250.204.130:443
2021-06-02 17:27:4127b98ddbcff37c453ae0346b024cc0d7Virustotal results 30 / 69 (43.48%) RedLineStealer185.250.204.130:443

# of entries: 9 (max: 100)