JA3 Fingerprints

You can find further information about the JA3 fingerprint 03e186a7f83285e93341de478334006e, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:03e186a7f83285e93341de478334006e
First seen:2017-07-24 18:17:14 UTC
Last seen:2018-08-30 23:44:33 UTC
Status:Blacklisted
Malware samples:52
Destination IPs:31
Malware:Tofsee -
Listing date:2018-11-14 12:35:26

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2018-08-30 23:44:33eb46194457d0cbe8b70979d8b7adaee0Virustotal results 40/68 (58.82%) 104.23.128.76:443
2018-06-16 01:46:548e13edc0f37e99c530a5b2f13ec22bd2Virustotal results 37/68 (54.41%) 94.100.180.215:443
2018-06-16 01:46:548e13edc0f37e99c530a5b2f13ec22bd2Virustotal results 37/68 (54.41%) 217.69.139.60:443
2018-06-16 01:46:548e13edc0f37e99c530a5b2f13ec22bd2Virustotal results 37/68 (54.41%) 94.100.180.64:443
2018-06-16 01:46:548e13edc0f37e99c530a5b2f13ec22bd2Virustotal results 37/68 (54.41%) 217.69.139.61:443
2018-06-16 01:46:548e13edc0f37e99c530a5b2f13ec22bd2Virustotal results 37/68 (54.41%) 217.69.133.148:443
2018-05-02 04:14:12ac0653064eab82d499d9f8a341a19956Virustotal results 45/66 (68.18%) 66.135.213.240:443
2018-04-25 19:05:322a2007452846138393bdec13994f1688Virustotal results 50/67 (74.63%) 2.19.77.81:443
2018-04-17 12:48:193bcccda298181eb81d4b981dd12a20e1Virustotal results 40/66 (60.61%) 2.19.77.81:443
2018-04-16 17:43:16329cb8c50ac98a197ebbd449cfe2ae1eVirustotal results 47/65 (72.31%) 2.19.77.81:443
2018-04-10 17:07:58d5a2a15d8898112654351a7243889e31Virustotal results 47/66 (71.21%) 92.122.65.18:443
2018-04-09 10:43:2339cfcf769265e2fa34c00498833c7e8en/a104.66.184.22:443
2018-04-08 07:20:088c2cf865e0e739d34d6e2312e76d8ac7Virustotal results 46/67 (68.66%) 23.201.250.90:443
2018-04-08 07:20:088c2cf865e0e739d34d6e2312e76d8ac7Virustotal results 46/67 (68.66%) 2.19.77.81:443
2018-04-06 10:48:455da1af3f493a50dce95a66e6022d62fdVirustotal results 46/68 (67.65%) 2.19.77.81:443
2018-03-16 11:21:20a4c3adce9333277ebc3de0557d861832Virustotal results 40/67 (59.70%) 104.96.17.149:443
2018-03-16 11:21:20a4c3adce9333277ebc3de0557d861832Virustotal results 40/67 (59.70%) 2.18.131.217:443
2018-02-07 20:47:577bf23bc96ac5a48d5a5e297c8dc1e30cn/a2.19.77.81:443
2018-01-06 01:49:11d1ee485abb9df62a14209490030a0217Virustotal results 44/68 (64.71%) 23.38.23.27:443
2018-01-06 01:49:11d1ee485abb9df62a14209490030a0217Virustotal results 44/68 (64.71%) 104.73.136.164:443
2018-01-04 21:01:13e4ff21bf664c9ce6c3cef968b49a729eVirustotal results 45/67 (67.16%) 23.38.23.27:443
2018-01-04 21:01:13e4ff21bf664c9ce6c3cef968b49a729eVirustotal results 45/67 (67.16%) 104.73.136.164:443
2018-01-04 06:02:056f4fb680b8fc42f861281f383805c8ffn/a104.73.136.164:443
2018-01-03 19:21:07c35397d61ccd020d0759c309e8a40682Virustotal results 38/68 (55.88%) 184.24.195.183:443
2017-12-04 17:59:28e69f25769ac59726cea6218d618d0ae2Virustotal results 36/68 (52.94%) 104.96.17.149:443
2017-11-07 00:39:109465acb4cc009bb21757d716c98c7ba5Virustotal results 36/68 (52.94%) 88.221.187.62:443
2017-10-28 12:23:08a33eded0a6c8e4f4d7b608f20af6605dVirustotal results 47/65 (72.31%) 2.19.77.81:443
2017-09-29 03:31:30a3f0254d33d4668b2ed186b0a1507fbaVirustotal results 31/65 (47.69%) 23.222.41.239:443
2017-09-28 06:31:14948f0f60972b9fcfb5ffe56f00c6fc94n/a84.53.148.223:443
2017-09-27 13:38:288bb43c5e8cc48c2be5e4ea09c2ebfa5fVirustotal results 35/64 (54.69%) 23.14.8.44:443
2017-09-26 17:03:5710a42a3fff9a86e1140c60f85bc86531Virustotal results 45/67 (67.16%) 2.19.77.81:443
2017-09-26 16:34:11391ddc649243b5cc850d8bd5784aea20n/a2.18.119.192:443
2017-09-26 16:34:11391ddc649243b5cc850d8bd5784aea20n/a2.17.227.183:443
2017-09-26 16:34:11391ddc649243b5cc850d8bd5784aea20n/a84.53.148.223:443
2017-09-26 16:34:11391ddc649243b5cc850d8bd5784aea20n/a23.36.161.46:443
2017-09-26 13:13:31a3158c7a6d60a1be1b5485b1dbb2bb92Virustotal results 47/65 (72.31%) 2.19.77.81:443
2017-09-26 09:12:30f581641a548ebbdab117d6d1eecab2c7n/a23.62.133.237:443
2017-09-25 16:45:109fda0bf0ddab9fdc7f34bea60b7bbadfn/a2.19.77.81:443
2017-09-25 14:17:56196fc3b5861a607f838a37aa3d42e1b7Virustotal results 52/66 (78.79%) 104.81.104.99:443
2017-09-25 07:11:157285e3617bfa7642cfbeecadbe0b4df6Virustotal results 42/65 (64.62%) 23.46.113.110:443
2017-09-24 23:30:59d9ae2640698d674beeae00ab3b7b0532n/a23.62.133.237:443
2017-09-23 22:33:43068be7fd86ecf055e640b6ba89e906e4Virustotal results 28/64 (43.75%) 23.62.133.237:443
2017-09-23 22:33:43068be7fd86ecf055e640b6ba89e906e4Virustotal results 28/64 (43.75%) 2.18.119.192:443
2017-09-23 22:33:43068be7fd86ecf055e640b6ba89e906e4Virustotal results 28/64 (43.75%) 184.86.225.137:443
2017-09-23 16:22:412ecf24e97d22a630ca14a0f3b3aae0fcVirustotal results 44/65 (67.69%) 23.62.133.237:443
2017-09-22 11:12:2722519b3b39d161554aadc99160ff67a9n/a2.19.77.81:443
2017-09-21 07:54:092966d15ad4982051e8fe35c3cb0d26d4Virustotal results 40/65 (61.54%) 104.66.184.22:443
2017-09-21 07:54:092966d15ad4982051e8fe35c3cb0d26d4Virustotal results 40/65 (61.54%) 2.19.77.81:443
2017-09-21 07:02:22c9a2ef16256e8ae07362f27e5bcda988n/a2.19.77.81:443
2017-09-20 11:25:49c9395284572f6e4e7c9cc86d69bfa36cn/a23.46.113.110:443
2017-09-20 05:27:37fe4866f83a041d608ce6f2f0ea9fc639n/a23.216.247.225:443
2017-09-19 22:24:20b0e9155a7bcfa77ccd64b57c591e485dVirustotal results 38/64 (59.38%) 2.19.77.81:443
2017-09-19 17:06:36df99c659ae2ec084ecf03d52baae4312Virustotal results 42/65 (64.62%) 23.200.89.199:443
2017-09-19 17:06:36df99c659ae2ec084ecf03d52baae4312Virustotal results 42/65 (64.62%) 104.125.29.217:443
2017-09-19 17:06:36df99c659ae2ec084ecf03d52baae4312Virustotal results 42/65 (64.62%) 104.66.184.22:443
2017-09-19 16:40:53056a440e3157af17f3128f45efe1e1acVirustotal results 41/65 (63.08%) 23.62.133.237:443
2017-09-19 14:54:02c3d0142194b5b67f837673453f42e40aVirustotal results 43/65 (66.15%) 2.19.77.81:443
2017-09-19 05:18:44a61c63d31140a23d380f441fd1638a72Virustotal results 38/64 (59.38%) 23.62.133.237:443
2017-09-18 16:40:30556248e8edd0ea332f6bf9ac05b2a4f3Virustotal results 47/65 (72.31%) 2.18.119.192:443
2017-09-18 10:35:3205091a83a40b7fd548f4a6c693b93bbaVirustotal results 42/65 (64.62%) 2.19.77.81:443
2017-09-17 18:47:244deebc4a6d506e70514387b338cab196n/a23.62.133.237:443
2017-09-17 17:38:5865c8507820a1262a22e4aa8aa228ca03n/a104.66.184.22:443
2017-09-17 17:38:5865c8507820a1262a22e4aa8aa228ca03n/a2.19.77.81:443
2017-09-15 07:24:134d743f8a6465cc697dc47959d4a49a23Virustotal results 37/64 (57.81%) 23.64.16.161:443
2017-09-15 07:24:134d743f8a6465cc697dc47959d4a49a23Virustotal results 37/64 (57.81%) 23.62.133.237:443
2017-09-06 22:10:011d909d0a541e39594a3f192c1d032239n/a2.19.77.81:443
2017-09-04 21:05:523ed81bbf1cdb17a4543f61e6098dc590n/a2.19.77.81:443
2017-09-03 19:02:38e046e0264b954b0444812c57c3633b5bVirustotal results 35/64 (54.69%) 104.66.184.22:443
2017-09-03 01:19:00130c25065ca6a7bf068ee18c2b27026bn/a104.66.184.22:443
2017-07-24 18:17:149fde381339660186a3dfaf8b504256d5Virustotal results 25/62 (40.32%) 23.62.133.237:443

# of entries: 70 (max: 100)