JA3 Fingerprints

You can find further information about the JA3 fingerprint 17fd49722f8d11f3d76dce84f8e099a7, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:17fd49722f8d11f3d76dce84f8e099a7
First seen:2018-03-19 23:02:27 UTC
Last seen:2019-07-17 07:23:22 UTC
Status:Blacklisted
Malware samples:201
Destination IPs:294
Malware:Tofsee -
Listing date:2018-11-14 12:35:06

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2019-07-17 07:23:22502ff191574b8ce64a2129a32e45046an/a216.98.48.226:443
2019-07-17 06:14:477447a3b86e5b20ec82d70e57b10c58fcn/a34.228.154.101:443
2019-07-16 21:46:15812c26c1f88df47995c081b5150a735dn/a52.86.66.66:443
2019-07-16 21:31:49511e1285a286477ae761e078cddd5131n/a104.199.64.136:443
2019-07-16 18:32:40ed66891448685c12fcf4ebf471aecdden/a54.88.204.224:443
2019-07-16 18:32:37ed66891448685c12fcf4ebf471aecdden/a3.210.7.60:443
2019-07-16 18:32:37ed66891448685c12fcf4ebf471aecdden/a104.199.64.136:443
2019-07-16 16:26:384b4caf2102ceea46f1df2c1d60470692n/a34.192.45.41:443
2019-07-16 15:32:5272144ef5621a625b4ce91457b357ccc7n/a104.199.64.136:443
2019-07-16 14:47:166e2601e72f4d2570a150f6c6f83aa3den/a52.21.234.37:443
2019-07-16 14:47:116e2601e72f4d2570a150f6c6f83aa3den/a34.234.126.223:443
2019-07-16 14:44:002c6be2dbd35edeaa6f6b4617ad52b190n/a34.237.157.90:443
2019-07-16 14:43:532c6be2dbd35edeaa6f6b4617ad52b190n/a104.199.64.136:443
2019-07-15 18:09:239acfb27a482a0ac42cd9caf72a24545cn/a104.199.64.136:443
2019-07-15 17:57:05f75c3a41c46fc4b7175f2aea17d53d9an/a104.199.64.136:443
2019-07-12 12:04:287dd64f8b3adf22d6fda1a81c8e9ca7c2n/a104.199.64.136:443
2019-07-12 09:58:36ba290a66881a6fa0d7166814ce561515n/a3.85.69.224:443
2019-07-12 09:58:36ba290a66881a6fa0d7166814ce561515n/a52.72.190.169:443
2019-07-12 09:58:35ba290a66881a6fa0d7166814ce561515n/a34.228.154.101:443
2019-07-12 09:58:35ba290a66881a6fa0d7166814ce561515n/a52.86.66.66:443
2019-07-12 09:58:35ba290a66881a6fa0d7166814ce561515n/a104.199.64.136:443
2019-07-12 07:00:331ea3c3ba195440fc3285d0b122075b75n/a34.228.154.101:443
2019-07-12 07:00:331ea3c3ba195440fc3285d0b122075b75n/a52.54.191.161:443
2019-07-12 07:00:301ea3c3ba195440fc3285d0b122075b75n/a104.199.64.136:443
2019-07-12 05:18:064eda2eeb63ce0a4d05569388a812a484n/a54.210.61.39:443
2019-07-12 05:18:054eda2eeb63ce0a4d05569388a812a484n/a34.231.227.192:443
2019-07-12 05:18:054eda2eeb63ce0a4d05569388a812a484n/a104.199.64.136:443
2019-07-12 05:18:054eda2eeb63ce0a4d05569388a812a484n/a54.88.122.16:443
2019-07-11 16:19:53673c92785e75e35bbbb80a95aefebb65n/a52.5.11.92:443
2019-07-11 16:19:53673c92785e75e35bbbb80a95aefebb65n/a34.228.86.83:443
2019-07-11 16:19:53673c92785e75e35bbbb80a95aefebb65n/a104.199.64.136:443
2019-07-11 16:13:0835ceda9c477122b284251baf428b95fcn/a52.3.178.115:443
2019-07-11 16:13:0735ceda9c477122b284251baf428b95fcn/a104.199.64.136:443
2019-07-11 10:59:067e873d5c8a72ef1bcfc4c351c65e3b75n/a54.86.191.164:443
2019-07-11 10:59:057e873d5c8a72ef1bcfc4c351c65e3b75n/a54.85.141.67:443
2019-07-11 10:59:057e873d5c8a72ef1bcfc4c351c65e3b75n/a104.199.64.136:443
2019-07-11 10:59:057e873d5c8a72ef1bcfc4c351c65e3b75n/a52.2.130.126:443
2019-07-11 06:40:1259f4105de61bf4e7eb491a8650402b7an/a34.234.126.223:443
2019-07-11 06:40:1159f4105de61bf4e7eb491a8650402b7an/a54.86.103.91:443
2019-07-10 22:36:4159ec5fab91f14de56c821d9b92c7a00en/a104.199.64.136:443
2019-07-10 21:35:46ce5194812e701ed63ebac43472393972n/a104.199.64.136:443
2019-07-10 05:55:42421d608bfdb1a0a25bd6bb1daa349a60n/a52.201.68.62:443
2019-07-10 05:55:42421d608bfdb1a0a25bd6bb1daa349a60n/a52.21.39.12:443
2019-07-10 05:55:41421d608bfdb1a0a25bd6bb1daa349a60n/a34.239.188.93:443
2019-07-09 17:28:32bd88dc6d2fedec6468452602a9da1ab8n/a18.233.129.248:443
2019-07-09 17:28:28bd88dc6d2fedec6468452602a9da1ab8n/a104.199.64.136:443
2019-07-09 13:25:0411cd438b395cd9399204fa867b724c2dn/a104.199.64.136:443
2019-07-09 06:41:5956d9d88d48bab9774d2c8139bbc9e057Virustotal results 16/67 (23.88%) 54.173.234.241:443
2019-07-09 06:15:50a059f830872a775233648088eecd858cn/a52.2.144.95:443
2019-07-09 06:15:48a059f830872a775233648088eecd858cn/a104.199.64.136:443
2019-07-09 06:15:48a059f830872a775233648088eecd858cn/a34.225.14.179:443
2019-07-09 03:17:13b98eb2bb254dde3c5297286f5ca63e9en/a18.233.231.44:443
2019-07-09 03:17:13b98eb2bb254dde3c5297286f5ca63e9en/a35.172.18.69:443
2019-07-09 03:17:13b98eb2bb254dde3c5297286f5ca63e9en/a54.173.234.241:443
2019-07-09 03:17:13b98eb2bb254dde3c5297286f5ca63e9en/a18.208.27.101:443
2019-07-09 03:17:12b98eb2bb254dde3c5297286f5ca63e9en/a52.72.190.169:443
2019-07-09 02:56:2470bdcfcf2b0ed00daa0940524c8b6bdbn/a50.16.4.139:443
2019-07-09 02:56:2470bdcfcf2b0ed00daa0940524c8b6bdbn/a34.225.80.76:443
2019-07-09 02:56:2470bdcfcf2b0ed00daa0940524c8b6bdbn/a34.233.92.140:443
2019-07-09 02:56:2370bdcfcf2b0ed00daa0940524c8b6bdbn/a52.202.222.43:443
2019-07-08 06:43:1488aa47e21dd1c8682be7126133530cd7n/a34.228.154.101:443
2019-07-08 06:43:1388aa47e21dd1c8682be7126133530cd7n/a34.205.183.103:443
2019-07-08 06:43:0988aa47e21dd1c8682be7126133530cd7n/a104.199.64.136:443
2019-07-08 06:05:26e8d50f84670898ff45eba3a6b5bafbd1n/a34.236.49.91:443
2019-07-07 08:12:587039819afb52385e1b46726e27773898n/a34.239.188.93:443
2019-07-07 08:12:587039819afb52385e1b46726e27773898n/a52.1.250.103:443
2019-07-07 08:12:527039819afb52385e1b46726e27773898n/a54.85.31.80:443
2019-07-07 08:12:517039819afb52385e1b46726e27773898n/a34.236.199.170:443
2019-07-07 06:50:19f0dc337209bbb5b10c81f0869aeb1d31n/a104.199.64.136:443
2019-07-06 21:55:387b320c583b777144180a0341479448a5n/a34.236.207.126:443
2019-07-03 08:30:45772304e0b8236c1bc562703f6b9679c8Virustotal results 28/70 (40.00%) 97.65.7.77:443
2019-07-02 06:26:42a3744634f9f45d633ce83d791b49b5a3Virustotal results 35/69 (50.72%) 54.88.204.224:443
2019-07-01 13:56:5891e47da67d75b3501c47f17d6169ace1n/a54.245.215.163:443
2019-07-01 13:56:5891e47da67d75b3501c47f17d6169ace1n/a151.101.38.167:443
2019-07-01 13:56:5891e47da67d75b3501c47f17d6169ace1n/a54.148.127.108:443
2019-06-30 19:29:441aca3c0d9a66623c64d99b9019d80eebn/a34.196.117.233:443
2019-06-30 13:19:1769faf13147f3becfb9c372201ef039f7n/a34.197.186.35:443
2019-06-30 13:19:1769faf13147f3becfb9c372201ef039f7n/a52.71.66.128:443
2019-06-29 14:04:362fdd4fe97dc65942d931a0833b7d8eb4n/a34.210.42.176:443
2019-06-29 14:04:362fdd4fe97dc65942d931a0833b7d8eb4n/a35.162.135.37:443
2019-06-29 14:04:362fdd4fe97dc65942d931a0833b7d8eb4n/a52.42.120.179:443
2019-06-28 17:57:4437bc10d23453b93bd91a8642f354c23fn/a151.101.38.167:443
2019-06-28 17:57:4437bc10d23453b93bd91a8642f354c23fn/a54.148.127.108:443
2019-06-28 17:57:4437bc10d23453b93bd91a8642f354c23fn/a34.210.42.176:443
2019-06-27 17:52:1812f07108fcbe0a60b6bce36a24ffdb28n/a107.22.123.15:443
2019-06-26 22:01:03420e48eb9fc473778b561deba2d72805n/a34.199.219.167:443
2019-06-26 22:01:03420e48eb9fc473778b561deba2d72805n/a52.44.21.34:443
2019-06-26 22:01:03420e48eb9fc473778b561deba2d72805n/a35.165.236.109:443
2019-06-26 22:01:02420e48eb9fc473778b561deba2d72805n/a151.101.38.167:443
2019-06-26 22:01:00420e48eb9fc473778b561deba2d72805n/a54.81.252.172:443
2019-06-26 22:01:00420e48eb9fc473778b561deba2d72805n/a18.235.220.163:443
2019-06-26 22:01:00420e48eb9fc473778b561deba2d72805n/a34.235.15.141:443
2019-06-24 12:03:31c934eac36e129d140cbcdfeef5d79bb6n/a151.101.38.167:443
2019-06-23 16:44:208eca7583b51b99ae6ea4b68d6ff5560cn/a35.165.236.109:443
2019-06-23 16:44:208eca7583b51b99ae6ea4b68d6ff5560cn/a151.101.38.167:443
2019-06-23 07:27:048233150f7129392c8f4e0f935ab5f852n/a151.101.38.167:443
2019-06-23 07:27:038233150f7129392c8f4e0f935ab5f852n/a35.165.236.109:443
2019-06-23 07:27:038233150f7129392c8f4e0f935ab5f852n/a34.210.42.176:443
2019-06-22 16:38:049b2b3970effdd49a3194b83a272b29bdn/a151.101.86.167:443
2019-06-22 07:38:081c11e2985474128ddef2a34961591c0bVirustotal results 27/69 (39.13%) 34.210.42.176:443

# of entries: 100 (max: 100)