JA3 Fingerprints

You can find further information about the JA3 fingerprint 17fd49722f8d11f3d76dce84f8e099a7, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:17fd49722f8d11f3d76dce84f8e099a7
First seen:2018-03-19 23:02:27 UTC
Last seen:2019-01-05 19:56:33 UTC
Status:Blacklisted
Malware samples:60
Destination IPs:81
Malware:Tofsee -
Listing date:2018-11-14 12:35:06

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2019-01-05 19:56:33a26dd9ab29f62033ad37ebc874a20a7cn/a104.28.1.124:443
2018-12-27 19:29:284577728e7e6ea0c371746efd0341813aVirustotal results 46/71 (64.79%) 104.24.16.55:443
2018-12-13 20:30:4639e07898d58e72ee3be94015fa178552Virustotal results 22/70 (31.43%) 173.244.176.226:443
2018-12-11 15:36:300ddb54791d2232498e2b25ed65484c89Virustotal results 24/70 (34.29%) 34.194.18.127:443
2018-12-11 15:36:290ddb54791d2232498e2b25ed65484c89Virustotal results 24/70 (34.29%) 104.81.126.76:443
2018-12-11 15:36:290ddb54791d2232498e2b25ed65484c89Virustotal results 24/70 (34.29%) 54.81.21.118:443
2018-12-10 23:44:03dac816d1c7b4ac33bc491a2c26ef83c2n/a2.23.135.191:443
2018-12-08 11:55:1754aaa042e75d20b5b9b22763639024b8Virustotal results 39/70 (55.71%) 64.14.192.118:443
2018-12-07 04:17:015919f2f95678c9689bb2ab633f04ecedVirustotal results 40/69 (57.97%) 65.154.255.209:443
2018-11-29 20:46:04020b08c9f4ece0ca858b702b57b5b6eeVirustotal results 37/69 (53.62%) 104.24.17.55:443
2018-11-25 16:01:2205754754e9926dfc92751235f56f1fd8Virustotal results 36/69 (52.17%) 104.24.16.55:443
2018-11-23 04:28:05162c6f6b1e73f0733e3a932d8b07dc2eVirustotal results 37/68 (54.41%) 104.24.16.55:443
2018-11-18 19:19:40bc95c3f699cea00f31cc288e669d9bd3Virustotal results 18/67 (26.87%) 23.38.44.138:443
2018-09-24 11:51:485793ba55688f17cfd1a5e730ea2e98b5Virustotal results 41/69 (59.42%) 66.211.185.82:443
2018-09-24 11:51:325793ba55688f17cfd1a5e730ea2e98b5Virustotal results 41/69 (59.42%) 66.135.216.190:443
2018-09-24 11:51:285793ba55688f17cfd1a5e730ea2e98b5Virustotal results 41/69 (59.42%) 66.135.220.14:443
2018-09-24 11:51:285793ba55688f17cfd1a5e730ea2e98b5Virustotal results 41/69 (59.42%) 66.135.220.19:443
2018-09-24 11:51:275793ba55688f17cfd1a5e730ea2e98b5Virustotal results 41/69 (59.42%) 66.135.204.237:443
2018-09-24 11:51:245793ba55688f17cfd1a5e730ea2e98b5Virustotal results 41/69 (59.42%) 66.211.160.88:443
2018-09-24 11:51:215793ba55688f17cfd1a5e730ea2e98b5Virustotal results 41/69 (59.42%) 66.211.185.34:443
2018-09-24 11:51:205793ba55688f17cfd1a5e730ea2e98b5Virustotal results 41/69 (59.42%) 66.211.160.196:443
2018-09-24 11:51:195793ba55688f17cfd1a5e730ea2e98b5Virustotal results 41/69 (59.42%) 66.135.213.249:443
2018-09-24 11:51:175793ba55688f17cfd1a5e730ea2e98b5Virustotal results 41/69 (59.42%) 66.211.185.47:443
2018-09-24 11:51:165793ba55688f17cfd1a5e730ea2e98b5Virustotal results 41/69 (59.42%) 66.211.181.50:443
2018-09-24 11:51:135793ba55688f17cfd1a5e730ea2e98b5Virustotal results 41/69 (59.42%) 66.211.181.96:443
2018-09-24 11:51:125793ba55688f17cfd1a5e730ea2e98b5Virustotal results 41/69 (59.42%) 66.135.209.105:443
2018-09-24 11:51:115793ba55688f17cfd1a5e730ea2e98b5Virustotal results 41/69 (59.42%) 66.211.181.81:443
2018-09-24 11:51:115793ba55688f17cfd1a5e730ea2e98b5Virustotal results 41/69 (59.42%) 66.135.211.73:443
2018-09-12 20:51:4609cf784d332da326e2f0fffe342d47a9Virustotal results 38/68 (55.88%) 159.53.232.19:443
2018-09-12 20:51:4609cf784d332da326e2f0fffe342d47a9Virustotal results 38/68 (55.88%) 159.53.224.16:443
2018-08-31 14:20:0633e8e299c080c4f87d97fd3503f4703bVirustotal results 37/66 (56.06%) 159.127.208.39:443
2018-08-26 03:25:14104b66e2ff9ccd28ef2e0590b7b046a4Virustotal results 36/68 (52.94%) 159.127.208.39:443
2018-08-25 10:22:26b451435099b3f713fdbfbde0310b0edaVirustotal results 31/68 (45.59%) 104.36.192.187:443
2018-08-24 15:14:248820060303e2fdcfe558f54cc298a039Virustotal results 38/68 (55.88%) 104.16.63.63:443
2018-08-22 06:04:48654fe47faa6909830c3d7d79c1001e30Virustotal results 42/68 (61.76%) 216.68.193.18:443
2018-08-22 06:04:48654fe47faa6909830c3d7d79c1001e30Virustotal results 42/68 (61.76%) 104.16.63.63:443
2018-08-21 23:46:5559b2d88d5704527cccbdf1993f6b964cVirustotal results 40/68 (58.82%) 216.68.193.18:443
2018-08-21 23:46:5559b2d88d5704527cccbdf1993f6b964cVirustotal results 40/68 (58.82%) 104.16.63.63:443
2018-08-18 20:42:419886dfd099a35579fe8514e6a31f0d70Virustotal results 20/68 (29.41%) 104.16.63.63:443
2018-08-17 06:35:3071ef8a5f0aa3b2d9c514e4b7f1e3e5c1Virustotal results 18/68 (26.47%) 216.68.193.18:443
2018-08-17 06:35:3071ef8a5f0aa3b2d9c514e4b7f1e3e5c1Virustotal results 18/68 (26.47%) 104.16.63.63:443
2018-08-16 22:49:02e3afadac7bd0b56d49271a320aa604b4Virustotal results 30/68 (44.12%) 216.68.193.18:443
2018-08-07 18:21:274fe8afdadf0ddec643493308652620a0Virustotal results 40/67 (59.70%) 216.68.193.18:443
2018-08-03 00:45:287a74d80ac6b4cec14a43dbd9434cf37eVirustotal results 37/67 (55.22%) 216.68.193.18:443
2018-07-16 19:55:255a090506422531ad0e82901fb9ed381fVirustotal results 40/64 (62.50%) 159.153.191.239:443
2018-07-16 19:55:255a090506422531ad0e82901fb9ed381fVirustotal results 40/64 (62.50%) 159.153.191.240:443
2018-06-18 07:11:475f85b1b0f9380a0f614848b9a1f48661Virustotal results 20/68 (29.41%) 66.211.181.81:443
2018-06-18 07:11:475f85b1b0f9380a0f614848b9a1f48661Virustotal results 20/68 (29.41%) 66.211.181.96:443
2018-06-18 07:11:475f85b1b0f9380a0f614848b9a1f48661Virustotal results 20/68 (29.41%) 66.211.185.34:443
2018-06-16 01:26:5258205cbdf0396e2b7649d23dc6033c50Virustotal results 42/68 (61.76%) 104.36.192.236:443
2018-06-13 06:20:28106c7b4f0f82ffa17c33e82b33cad573Virustotal results 14/67 (20.90%) 34.231.175.144:443
2018-06-13 06:20:28106c7b4f0f82ffa17c33e82b33cad573Virustotal results 14/67 (20.90%) 54.152.118.246:443
2018-06-13 06:20:28106c7b4f0f82ffa17c33e82b33cad573Virustotal results 14/67 (20.90%) 18.208.85.232:443
2018-06-11 08:50:58c5340ca6aa526d4d86cb37692864ebeaVirustotal results 25/68 (36.76%) 185.156.184.30:443
2018-05-30 02:33:1235d92ac538e72c5ef8b49e3c79b86694Virustotal results 22/66 (33.33%) 104.36.193.153:443
2018-05-28 17:31:376d8371cd42322e64cd99141cc8f3e1d9Virustotal results 31/66 (46.97%) 54.84.180.162:443
2018-05-28 17:31:376d8371cd42322e64cd99141cc8f3e1d9Virustotal results 31/66 (46.97%) 107.23.23.211:443
2018-05-28 17:31:376d8371cd42322e64cd99141cc8f3e1d9Virustotal results 31/66 (46.97%) 18.233.41.236:443
2018-05-28 17:31:376d8371cd42322e64cd99141cc8f3e1d9Virustotal results 31/66 (46.97%) 54.174.205.250:443
2018-05-28 17:31:376d8371cd42322e64cd99141cc8f3e1d9Virustotal results 31/66 (46.97%) 52.71.177.203:443
2018-05-28 17:31:376d8371cd42322e64cd99141cc8f3e1d9Virustotal results 31/66 (46.97%) 54.209.167.169:443
2018-05-28 17:31:376d8371cd42322e64cd99141cc8f3e1d9Virustotal results 31/66 (46.97%) 54.85.141.67:443
2018-05-28 17:31:376d8371cd42322e64cd99141cc8f3e1d9Virustotal results 31/66 (46.97%) 88.99.142.163:443
2018-05-28 17:31:376d8371cd42322e64cd99141cc8f3e1d9Virustotal results 31/66 (46.97%) 34.199.85.246:443
2018-05-28 17:31:376d8371cd42322e64cd99141cc8f3e1d9Virustotal results 31/66 (46.97%) 54.85.158.223:443
2018-05-28 17:31:376d8371cd42322e64cd99141cc8f3e1d9Virustotal results 31/66 (46.97%) 54.236.191.98:443
2018-05-28 17:31:376d8371cd42322e64cd99141cc8f3e1d9Virustotal results 31/66 (46.97%) 107.23.227.166:443
2018-05-28 17:31:376d8371cd42322e64cd99141cc8f3e1d9Virustotal results 31/66 (46.97%) 18.204.250.78:443
2018-05-28 17:31:376d8371cd42322e64cd99141cc8f3e1d9Virustotal results 31/66 (46.97%) 18.233.114.243:443
2018-05-28 17:31:376d8371cd42322e64cd99141cc8f3e1d9Virustotal results 31/66 (46.97%) 34.196.202.237:443
2018-05-28 17:31:376d8371cd42322e64cd99141cc8f3e1d9Virustotal results 31/66 (46.97%) 54.236.192.173:443
2018-05-28 17:31:376d8371cd42322e64cd99141cc8f3e1d9Virustotal results 31/66 (46.97%) 34.199.244.26:443
2018-05-28 17:31:376d8371cd42322e64cd99141cc8f3e1d9Virustotal results 31/66 (46.97%) 34.192.189.74:443
2018-05-27 18:26:20d94b8fbcd3aed19b17afe0c1318a3c95Virustotal results 3/65 (4.62%) 52.72.143.39:443
2018-05-27 18:26:20d94b8fbcd3aed19b17afe0c1318a3c95Virustotal results 3/65 (4.62%) 54.85.158.223:443
2018-05-27 18:26:20d94b8fbcd3aed19b17afe0c1318a3c95Virustotal results 3/65 (4.62%) 54.209.167.169:443
2018-05-27 18:26:20d94b8fbcd3aed19b17afe0c1318a3c95Virustotal results 3/65 (4.62%) 34.195.16.138:443
2018-05-27 18:26:20d94b8fbcd3aed19b17afe0c1318a3c95Virustotal results 3/65 (4.62%) 54.85.203.119:443
2018-05-27 18:26:20d94b8fbcd3aed19b17afe0c1318a3c95Virustotal results 3/65 (4.62%) 52.205.58.111:443
2018-05-25 04:16:50b3d2fe81be2e5406f590701e4819c5dbVirustotal results 45/67 (67.16%) 104.27.158.30:443
2018-05-16 14:56:28ea8ebff77d2b56d29467a67f65d2d735Virustotal results 44/65 (67.69%) 104.36.192.190:443
2018-05-16 14:56:28ea8ebff77d2b56d29467a67f65d2d735Virustotal results 44/65 (67.69%) 104.36.192.215:443
2018-05-15 10:02:409a24b7e019632985d4357312b201d806Virustotal results 41/66 (62.12%) 104.36.193.154:443
2018-05-15 10:02:409a24b7e019632985d4357312b201d806Virustotal results 41/66 (62.12%) 104.36.192.233:443
2018-04-18 06:24:37b931b8e286951c868b4565e02e144be2Virustotal results 25/67 (37.31%) 184.86.81.113:443
2018-04-13 05:28:2214587f387748738734bea6b4eb73e829Virustotal results 22/66 (33.33%) 159.53.224.14:443
2018-04-11 03:36:452c990947d0beb19a5674fe774792c9d3n/a138.201.166.72:443
2018-04-10 20:51:28ba940a7f8ff7d5dbefc9c9c45bc6429cVirustotal results 20/64 (31.25%) 66.211.185.47:443
2018-04-10 20:51:28ba940a7f8ff7d5dbefc9c9c45bc6429cVirustotal results 20/64 (31.25%) 84.20.200.150:443
2018-04-10 10:07:15e06dbe52a1816f36e9c7bca255335ab2Virustotal results 43/67 (64.18%) 94.125.59.62:443
2018-04-09 21:04:1720f0a425d4dd52db90681cfa88eb2841Virustotal results 54/67 (80.60%) 78.47.11.190:443
2018-03-29 19:23:54b19cc2189121e26f86349536c2e8dc2fn/a104.36.192.150:443
2018-03-26 13:16:517060d7c2ff5678e94bba74abf7a92cf5Virustotal results 45/67 (67.16%) 107.154.189.13:443
2018-03-25 16:35:53c5851748533dfd69fd7f2deac9aa8ac7Virustotal results 45/67 (67.16%) 202.248.34.97:443
2018-03-24 09:47:39b26cf59c21e3941b132d743daefdf340Virustotal results 26/68 (38.24%) 159.53.85.77:443
2018-03-24 06:51:33e579700ba4c8a6ce827a0293222e57f4Virustotal results 39/65 (60.00%) 104.16.8.251:443
2018-03-23 10:21:26fbb31d75f2332a213f9f3cc3610a92d9Virustotal results 40/64 (62.50%) 104.16.8.251:443
2018-03-22 18:17:36ff9e76c6c5b09efe2e3bb75f36702ea1Virustotal results 41/64 (64.06%) 104.16.8.251:443
2018-03-22 11:00:282f1029bebc9483864e9e2d1707921b61Virustotal results 31/65 (47.69%) 104.20.170.51:443
2018-03-21 21:27:5836a892eb9ee5a9228b4a252aa35df225Virustotal results 42/67 (62.69%) 104.20.170.51:443

# of entries: 100 (max: 100)