JA3 Fingerprints

You can find further information about the JA3 fingerprint 17fd49722f8d11f3d76dce84f8e099a7, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:17fd49722f8d11f3d76dce84f8e099a7
First seen:2018-03-19 23:02:27 UTC
Last seen:2020-03-29 08:34:06 UTC
Status:Blacklisted
Malware samples:1'829
Destination IPs:1'064
Malware:Tofsee -
Listing date:2018-11-14 12:35:06

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2020-03-29 08:34:06c260b388b3a0a6a42d1dc18f67eb1b5eVirustotal results 31 / 72 (43.06%) 3.223.170.63:443
2020-03-29 08:34:06c260b388b3a0a6a42d1dc18f67eb1b5eVirustotal results 31 / 72 (43.06%) 52.6.219.218:443
2020-03-29 08:34:06c260b388b3a0a6a42d1dc18f67eb1b5eVirustotal results 31 / 72 (43.06%) 52.6.43.214:443
2020-03-29 08:34:06c260b388b3a0a6a42d1dc18f67eb1b5eVirustotal results 31 / 72 (43.06%) 34.199.165.173:443
2020-03-29 08:34:06c260b388b3a0a6a42d1dc18f67eb1b5eVirustotal results 31 / 72 (43.06%) 52.1.227.226:443
2020-03-29 08:34:06c260b388b3a0a6a42d1dc18f67eb1b5eVirustotal results 31 / 72 (43.06%) 34.225.166.179:443
2020-03-29 08:34:06c260b388b3a0a6a42d1dc18f67eb1b5eVirustotal results 31 / 72 (43.06%) 54.85.231.195:443
2020-03-29 08:34:06c260b388b3a0a6a42d1dc18f67eb1b5eVirustotal results 31 / 72 (43.06%) 54.84.183.247:443
2020-03-29 08:34:05c260b388b3a0a6a42d1dc18f67eb1b5eVirustotal results 31 / 72 (43.06%) 18.205.63.152:443
2020-03-29 08:34:05c260b388b3a0a6a42d1dc18f67eb1b5eVirustotal results 31 / 72 (43.06%) 34.235.26.203:443
2020-03-29 08:34:05c260b388b3a0a6a42d1dc18f67eb1b5eVirustotal results 31 / 72 (43.06%) 52.70.254.172:443
2020-03-29 08:34:05c260b388b3a0a6a42d1dc18f67eb1b5eVirustotal results 31 / 72 (43.06%) 3.224.216.207:443
2020-03-29 08:34:05c260b388b3a0a6a42d1dc18f67eb1b5eVirustotal results 31 / 72 (43.06%) 3.214.89.147:443
2020-03-29 08:34:05c260b388b3a0a6a42d1dc18f67eb1b5eVirustotal results 31 / 72 (43.06%) 52.6.237.1:443
2020-03-29 08:34:05c260b388b3a0a6a42d1dc18f67eb1b5eVirustotal results 31 / 72 (43.06%) 52.2.57.43:443
2020-03-29 08:34:05c260b388b3a0a6a42d1dc18f67eb1b5eVirustotal results 31 / 72 (43.06%) 54.152.19.79:443
2020-03-29 08:34:05c260b388b3a0a6a42d1dc18f67eb1b5eVirustotal results 31 / 72 (43.06%) 52.54.4.209:443
2020-03-29 08:34:04c260b388b3a0a6a42d1dc18f67eb1b5eVirustotal results 31 / 72 (43.06%) 52.3.33.237:443
2020-03-29 08:34:04c260b388b3a0a6a42d1dc18f67eb1b5eVirustotal results 31 / 72 (43.06%) 52.1.36.254:443
2020-03-29 08:34:04c260b388b3a0a6a42d1dc18f67eb1b5eVirustotal results 31 / 72 (43.06%) 35.227.224.91:443
2020-03-29 08:34:04c260b388b3a0a6a42d1dc18f67eb1b5eVirustotal results 31 / 72 (43.06%) 35.201.81.34:443
2020-03-29 08:34:04c260b388b3a0a6a42d1dc18f67eb1b5eVirustotal results 31 / 72 (43.06%) 54.221.66.190:443
2020-03-29 08:34:04c260b388b3a0a6a42d1dc18f67eb1b5eVirustotal results 31 / 72 (43.06%) 54.157.76.194:443
2020-03-29 08:34:04c260b388b3a0a6a42d1dc18f67eb1b5eVirustotal results 31 / 72 (43.06%) 35.173.20.67:443
2020-03-29 08:34:04c260b388b3a0a6a42d1dc18f67eb1b5eVirustotal results 31 / 72 (43.06%) 34.232.100.7:443
2020-03-29 08:34:04c260b388b3a0a6a42d1dc18f67eb1b5eVirustotal results 31 / 72 (43.06%) 54.236.143.39:443
2020-03-29 08:34:04c260b388b3a0a6a42d1dc18f67eb1b5eVirustotal results 31 / 72 (43.06%) 34.203.178.99:443
2020-03-29 08:34:04c260b388b3a0a6a42d1dc18f67eb1b5eVirustotal results 31 / 72 (43.06%) 3.227.89.186:443
2020-03-29 08:34:04c260b388b3a0a6a42d1dc18f67eb1b5eVirustotal results 31 / 72 (43.06%) 34.236.84.150:443
2020-03-29 08:34:03c260b388b3a0a6a42d1dc18f67eb1b5eVirustotal results 31 / 72 (43.06%) 52.4.184.110:443
2020-03-29 08:34:03c260b388b3a0a6a42d1dc18f67eb1b5eVirustotal results 31 / 72 (43.06%) 54.224.44.28:443
2020-03-29 08:34:03c260b388b3a0a6a42d1dc18f67eb1b5eVirustotal results 31 / 72 (43.06%) 52.201.35.193:443
2020-03-29 00:54:10aabf7a7dfd185f1e3969712068f359a8Virustotal results 38 / 73 (52.05%) 54.173.247.61:443
2020-03-28 11:08:09cc116150b8cfdfa2f572101a8d42a00dVirustotal results 30 / 73 (41.10%) 3.214.89.147:443
2020-03-28 11:08:09cc116150b8cfdfa2f572101a8d42a00dVirustotal results 30 / 73 (41.10%) 52.22.10.59:443
2020-03-28 08:13:187d0d77195b18f47e203629bbd0044018n/a18.211.18.251:443
2020-03-28 06:32:332fa08b5df03fa494f7ae182ca4019115n/a104.18.6.10:443
2020-03-28 06:32:322fa08b5df03fa494f7ae182ca4019115n/a104.16.233.91:443
2020-03-28 06:32:322fa08b5df03fa494f7ae182ca4019115n/a104.16.100.49:443
2020-03-28 06:32:312fa08b5df03fa494f7ae182ca4019115n/a104.16.57.47:443
2020-03-28 06:32:302fa08b5df03fa494f7ae182ca4019115n/a3.221.61.25:443
2020-03-28 06:32:302fa08b5df03fa494f7ae182ca4019115n/a92.122.108.111:443
2020-03-28 06:20:130c156d8f2f00bfe4ec9f2b36d5bbda16Virustotal results 25 / 72 (34.72%) 104.16.58.47:443
2020-03-28 03:41:54093930b0fcfd548e7a27799c0942a1b3Virustotal results 22 / 72 (30.56%) 104.36.194.253:443
2020-03-28 03:41:54093930b0fcfd548e7a27799c0942a1b3Virustotal results 22 / 72 (30.56%) 13.112.72.41:443
2020-03-28 03:41:54093930b0fcfd548e7a27799c0942a1b3Virustotal results 22 / 72 (30.56%) 54.88.217.224:443
2020-03-28 03:41:53093930b0fcfd548e7a27799c0942a1b3Virustotal results 22 / 72 (30.56%) 139.131.82.161:443
2020-03-28 03:41:53093930b0fcfd548e7a27799c0942a1b3Virustotal results 22 / 72 (30.56%) 23.45.72.89:443
2020-03-28 03:41:53093930b0fcfd548e7a27799c0942a1b3Virustotal results 22 / 72 (30.56%) 104.36.195.212:443
2020-03-28 03:41:53093930b0fcfd548e7a27799c0942a1b3Virustotal results 22 / 72 (30.56%) 35.227.224.91:443
2020-03-28 03:41:53093930b0fcfd548e7a27799c0942a1b3Virustotal results 22 / 72 (30.56%) 192.0.56.69:443
2020-03-28 03:41:53093930b0fcfd548e7a27799c0942a1b3Virustotal results 22 / 72 (30.56%) 104.18.6.10:443
2020-03-28 03:41:53093930b0fcfd548e7a27799c0942a1b3Virustotal results 22 / 72 (30.56%) 104.122.243.167:443
2020-03-28 03:41:53093930b0fcfd548e7a27799c0942a1b3Virustotal results 22 / 72 (30.56%) 192.0.58.194:443
2020-03-28 03:41:53093930b0fcfd548e7a27799c0942a1b3Virustotal results 22 / 72 (30.56%) 107.23.58.221:443
2020-03-28 03:41:53093930b0fcfd548e7a27799c0942a1b3Virustotal results 22 / 72 (30.56%) 192.0.56.111:443
2020-03-28 03:41:53093930b0fcfd548e7a27799c0942a1b3Virustotal results 22 / 72 (30.56%) 192.0.58.193:443
2020-03-28 03:41:53093930b0fcfd548e7a27799c0942a1b3Virustotal results 22 / 72 (30.56%) 104.22.9.71:443
2020-03-28 03:41:53093930b0fcfd548e7a27799c0942a1b3Virustotal results 22 / 72 (30.56%) 111.206.250.168:443
2020-03-28 03:41:53093930b0fcfd548e7a27799c0942a1b3Virustotal results 22 / 72 (30.56%) 192.0.50.110:443
2020-03-28 03:41:53093930b0fcfd548e7a27799c0942a1b3Virustotal results 22 / 72 (30.56%) 54.236.133.60:443
2020-03-28 03:41:53093930b0fcfd548e7a27799c0942a1b3Virustotal results 22 / 72 (30.56%) 104.76.50.44:443
2020-03-28 03:41:53093930b0fcfd548e7a27799c0942a1b3Virustotal results 22 / 72 (30.56%) 104.16.119.50:443
2020-03-28 03:41:53093930b0fcfd548e7a27799c0942a1b3Virustotal results 22 / 72 (30.56%) 58.87.82.241:443
2020-03-28 03:41:53093930b0fcfd548e7a27799c0942a1b3Virustotal results 22 / 72 (30.56%) 34.107.165.220:443
2020-03-28 03:41:52093930b0fcfd548e7a27799c0942a1b3Virustotal results 22 / 72 (30.56%) 192.0.58.178:443
2020-03-28 03:41:52093930b0fcfd548e7a27799c0942a1b3Virustotal results 22 / 72 (30.56%) 192.0.56.76:443
2020-03-28 03:41:52093930b0fcfd548e7a27799c0942a1b3Virustotal results 22 / 72 (30.56%) 54.241.130.38:443
2020-03-28 00:44:33060d3c57ad3a89c6e600bb586cc814d0Virustotal results 19 / 65 (29.23%) 104.16.57.47:443
2020-03-28 00:44:33060d3c57ad3a89c6e600bb586cc814d0Virustotal results 19 / 65 (29.23%) 3.217.207.251:443
2020-03-27 19:28:2808808e888c5bc8e69eb42b81b567caf5n/a104.16.130.238:443
2020-03-27 19:28:2808808e888c5bc8e69eb42b81b567caf5n/a104.16.131.238:443
2020-03-27 16:28:22df9803868c79bf013c113b1eaa7723d2n/a104.16.130.238:443
2020-03-27 15:13:42926941535345db23a2f45b3995939b80Virustotal results 22 / 72 (30.56%) 52.222.148.61:443
2020-03-27 15:13:41926941535345db23a2f45b3995939b80Virustotal results 22 / 72 (30.56%) 104.16.58.47:443
2020-03-27 15:13:40926941535345db23a2f45b3995939b80Virustotal results 22 / 72 (30.56%) 23.43.120.119:443
2020-03-27 15:13:39926941535345db23a2f45b3995939b80Virustotal results 22 / 72 (30.56%) 192.0.50.54:443
2020-03-27 13:54:178815daa15c9acd80b0c2940ce1d276acVirustotal results 24 / 72 (33.33%) 104.16.131.238:443
2020-03-27 11:18:520bb2b03883d61987cda2ca662ba0db60n/a92.122.108.111:443
2020-03-27 11:18:520bb2b03883d61987cda2ca662ba0db60n/a18.214.161.218:443
2020-03-27 11:18:520bb2b03883d61987cda2ca662ba0db60n/a104.18.31.112:443
2020-03-27 11:18:510bb2b03883d61987cda2ca662ba0db60n/a157.240.7.174:443
2020-03-27 11:18:510bb2b03883d61987cda2ca662ba0db60n/a104.16.131.238:443
2020-03-27 11:18:510bb2b03883d61987cda2ca662ba0db60n/a3.221.116.27:443
2020-03-27 11:18:510bb2b03883d61987cda2ca662ba0db60n/a35.201.81.34:443
2020-03-27 08:06:4599b6fc26f6a4f013ae61cc3102e3a392n/a3.223.126.213:443
2020-03-27 08:06:4499b6fc26f6a4f013ae61cc3102e3a392n/a104.16.130.238:443
2020-03-27 08:06:4499b6fc26f6a4f013ae61cc3102e3a392n/a52.222.148.61:443
2020-03-27 08:06:4399b6fc26f6a4f013ae61cc3102e3a392n/a104.18.30.112:443
2020-03-27 08:00:52cd0f9d101208331d0682a14607fb8935Virustotal results 55 / 73 (75.34%) 34.225.166.179:443
2020-03-27 08:00:52cd0f9d101208331d0682a14607fb8935Virustotal results 55 / 73 (75.34%) 18.214.251.199:443
2020-03-27 08:00:52cd0f9d101208331d0682a14607fb8935Virustotal results 55 / 73 (75.34%) 35.173.20.67:443
2020-03-27 08:00:209fbcc892773395183458ab838eacb662Virustotal results 24 / 73 (32.88%) 184.31.92.200:443
2020-03-27 08:00:209fbcc892773395183458ab838eacb662Virustotal results 24 / 73 (32.88%) 52.52.96.91:443
2020-03-27 08:00:209fbcc892773395183458ab838eacb662Virustotal results 24 / 73 (32.88%) 192.0.50.54:443
2020-03-27 08:00:209fbcc892773395183458ab838eacb662Virustotal results 24 / 73 (32.88%) 3.222.239.146:443
2020-03-27 08:00:209fbcc892773395183458ab838eacb662Virustotal results 24 / 73 (32.88%) 34.226.16.184:443
2020-03-27 08:00:209fbcc892773395183458ab838eacb662Virustotal results 24 / 73 (32.88%) 184.50.169.13:443
2020-03-27 08:00:209fbcc892773395183458ab838eacb662Virustotal results 24 / 73 (32.88%) 52.52.16.38:443
2020-03-27 08:00:199fbcc892773395183458ab838eacb662Virustotal results 24 / 73 (32.88%) 54.175.88.106:443

# of entries: 100 (max: 100)