JA3 Fingerprints

You can find further information about the JA3 fingerprint 1aa7bf8b97e540ca5edd75f7b8384bfa, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:1aa7bf8b97e540ca5edd75f7b8384bfa
First seen:2017-07-14 20:23:38 UTC
Last seen:2019-07-28 01:38:22 UTC
Status:Blacklisted
Malware samples:1'735
Destination IPs:1'173
Malware:TrickBot -
Listing date:2019-06-20 14:09:25

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2019-07-28 01:38:225fd14d18426e0429d9f424cf22b90a97n/a189.80.134.122:449
2019-07-28 01:38:225fd14d18426e0429d9f424cf22b90a97n/a108.174.56.159:447
2019-07-28 01:38:225fd14d18426e0429d9f424cf22b90a97n/a190.154.203.218:449
2019-07-28 01:33:2241b34476ae7ef23eed5464e778a0d0f1Virustotal results 40/70 (57.14%) 187.58.56.26:449
2019-07-28 01:33:2241b34476ae7ef23eed5464e778a0d0f1Virustotal results 40/70 (57.14%) 189.80.134.122:449
2019-07-28 01:33:2241b34476ae7ef23eed5464e778a0d0f1Virustotal results 40/70 (57.14%) 108.174.56.159:447
2019-07-27 23:50:31f17de07f921c772e1f103fed4d8e08faVirustotal results 39/69 (56.52%) 190.154.203.218:449
2019-07-27 23:20:2560e4f79518787291832c8cceb7e4961dVirustotal results 40/71 (56.34%) 107.172.248.98:447
2019-07-27 23:20:2560e4f79518787291832c8cceb7e4961dVirustotal results 40/71 (56.34%) 107.173.34.151:447
2019-07-27 23:20:2560e4f79518787291832c8cceb7e4961dVirustotal results 40/71 (56.34%) 190.154.203.218:449
2019-07-27 22:44:5406fbbd937c492cea00868040b95bdc21Virustotal results 40/70 (57.14%) 168.227.229.112:449
2019-07-27 21:47:4344883149ff763f8f09a8272e7e7f7ce8Virustotal results 40/70 (57.14%) 192.3.83.168:447
2019-07-27 21:47:4344883149ff763f8f09a8272e7e7f7ce8Virustotal results 40/70 (57.14%) 190.154.203.218:449
2019-07-27 21:47:4344883149ff763f8f09a8272e7e7f7ce8Virustotal results 40/70 (57.14%) 107.173.34.151:447
2019-07-27 21:27:34a844a05320282ff6e21a05f15eaefaaeVirustotal results 40/70 (57.14%) 190.154.203.218:449
2019-07-27 21:27:34a844a05320282ff6e21a05f15eaefaaeVirustotal results 40/70 (57.14%) 107.173.34.151:447
2019-07-27 21:27:34a844a05320282ff6e21a05f15eaefaaeVirustotal results 40/70 (57.14%) 36.89.85.103:449
2019-07-27 21:01:43ccad0430cdf367ecb7608a9be86370caVirustotal results 39/70 (55.71%) 107.181.175.122:443
2019-07-27 21:01:43ccad0430cdf367ecb7608a9be86370caVirustotal results 39/70 (55.71%) 190.154.203.218:449
2019-07-27 21:01:43ccad0430cdf367ecb7608a9be86370caVirustotal results 39/70 (55.71%) 108.174.56.159:447
2019-07-27 20:00:575b214845078e6249967ab097447d3bc1Virustotal results 13/68 (19.12%) 190.154.203.218:449
2019-07-27 20:00:575b214845078e6249967ab097447d3bc1Virustotal results 13/68 (19.12%) 107.173.34.151:447
2019-07-27 20:00:575b214845078e6249967ab097447d3bc1Virustotal results 13/68 (19.12%) 189.80.134.122:449
2019-07-27 17:47:554a2b3cac465e12255f4fd6ea759d70a0Virustotal results 39/71 (54.93%) 107.173.34.151:447
2019-07-27 17:47:554a2b3cac465e12255f4fd6ea759d70a0Virustotal results 39/71 (54.93%) 108.174.56.159:447
2019-07-27 17:47:554a2b3cac465e12255f4fd6ea759d70a0Virustotal results 39/71 (54.93%) 189.80.134.122:449
2019-07-27 17:47:554a2b3cac465e12255f4fd6ea759d70a0Virustotal results 39/71 (54.93%) 190.154.203.218:449
2019-07-27 17:47:554a2b3cac465e12255f4fd6ea759d70a0Virustotal results 39/71 (54.93%) 185.141.25.116:447
2019-07-27 16:59:446301b764a2e4d4514f2e2cbb73a65376Virustotal results 40/70 (57.14%) 107.172.248.98:447
2019-07-27 16:59:446301b764a2e4d4514f2e2cbb73a65376Virustotal results 40/70 (57.14%) 107.173.34.151:447
2019-07-27 16:59:446301b764a2e4d4514f2e2cbb73a65376Virustotal results 40/70 (57.14%) 189.80.134.122:449
2019-07-27 16:59:446301b764a2e4d4514f2e2cbb73a65376Virustotal results 40/70 (57.14%) 191.37.181.152:449
2019-07-27 16:16:155b9fb0d38f417aa4dfba0a43354b675dn/a108.174.56.159:447
2019-07-27 16:16:155b9fb0d38f417aa4dfba0a43354b675dn/a190.154.203.218:449
2019-07-27 16:16:145b9fb0d38f417aa4dfba0a43354b675dn/a189.80.134.122:449
2019-07-27 15:22:34ae0eb09dcd0e44da135f4ffeed933c16n/a190.154.203.218:449
2019-07-27 15:22:34ae0eb09dcd0e44da135f4ffeed933c16n/a107.172.248.98:447
2019-07-27 15:22:34ae0eb09dcd0e44da135f4ffeed933c16n/a107.173.34.151:447
2019-07-27 13:55:32aa283fee51f26bdd2be0f1c90dbb68d5Virustotal results 40/71 (56.34%) 189.80.134.122:449
2019-07-27 13:55:32aa283fee51f26bdd2be0f1c90dbb68d5Virustotal results 40/71 (56.34%) 107.173.34.151:447
2019-07-27 13:55:32aa283fee51f26bdd2be0f1c90dbb68d5Virustotal results 40/71 (56.34%) 36.89.85.103:449
2019-07-27 13:55:32aa283fee51f26bdd2be0f1c90dbb68d5Virustotal results 40/71 (56.34%) 108.174.56.159:447
2019-07-27 13:21:29987a983266054226da5100696c0974e2n/a190.154.203.218:449
2019-07-27 13:21:29987a983266054226da5100696c0974e2n/a108.174.56.159:447
2019-07-27 13:21:29987a983266054226da5100696c0974e2n/a202.4.169.178:449
2019-07-27 13:21:29987a983266054226da5100696c0974e2n/a107.172.248.98:447
2019-07-27 11:35:5020662e9a30c53bcfc7d9c4f9737f2ef3n/a190.154.203.218:449
2019-07-27 11:35:5020662e9a30c53bcfc7d9c4f9737f2ef3n/a108.174.56.159:447
2019-07-27 11:16:45764c746ef0532ae6d0b63a553c9df89cVirustotal results 39/72 (54.17%) 190.154.203.218:449
2019-07-27 11:16:45764c746ef0532ae6d0b63a553c9df89cVirustotal results 39/72 (54.17%) 108.174.56.159:447
2019-07-27 11:16:45764c746ef0532ae6d0b63a553c9df89cVirustotal results 39/72 (54.17%) 107.172.248.98:447
2019-07-27 09:40:486952119171b9c3c959a42e76be6fc00an/a190.154.203.218:449
2019-07-27 09:40:486952119171b9c3c959a42e76be6fc00an/a107.172.248.98:447
2019-07-27 09:40:06847effbdf9139e05ac054f3c1bf59eb9Virustotal results 37/68 (54.41%) 202.4.169.178:449
2019-07-27 09:40:06847effbdf9139e05ac054f3c1bf59eb9Virustotal results 37/68 (54.41%) 190.154.203.218:449
2019-07-27 09:40:06847effbdf9139e05ac054f3c1bf59eb9Virustotal results 37/68 (54.41%) 31.202.132.95:447
2019-07-27 09:22:378cf3ad5a7e88fc60288091b98bad7f0fVirustotal results 39/71 (54.93%) 190.154.203.218:449
2019-07-27 07:41:25b8dcd32567f896a3913c87b77af036b1Virustotal results 38/67 (56.72%) 187.58.56.26:449
2019-07-27 07:31:29a0f65037000b3dc9404625cc3e1a619bVirustotal results 51/72 (70.83%) 108.174.56.159:447
2019-07-27 07:31:29a0f65037000b3dc9404625cc3e1a619bVirustotal results 51/72 (70.83%) 189.80.134.122:449
2019-07-27 07:13:3278790d59788676d76962c2add504fbefn/a185.141.25.116:447
2019-07-27 07:13:3278790d59788676d76962c2add504fbefn/a108.174.56.159:447
2019-07-27 07:13:3278790d59788676d76962c2add504fbefn/a189.80.134.122:449
2019-07-27 07:13:3278790d59788676d76962c2add504fbefn/a190.154.203.218:449
2019-07-27 07:00:32b4f6bf0a6100e116ddaaf423ac1788feVirustotal results 39/71 (54.93%) 36.89.85.103:449
2019-07-27 05:12:582e103bd1da7475bda3b545385680d749Virustotal results 39/71 (54.93%) 202.4.169.178:449
2019-07-27 05:12:582e103bd1da7475bda3b545385680d749Virustotal results 39/71 (54.93%) 108.174.56.159:447
2019-07-27 05:12:582e103bd1da7475bda3b545385680d749Virustotal results 39/71 (54.93%) 181.129.93.226:449
2019-07-27 04:48:16e99d69826903b756d1265e5cf3f64d04Virustotal results 39/71 (54.93%) 190.154.203.218:449
2019-07-27 04:07:49f1064c1ac2e0f067fda756342a18a992n/a185.141.25.116:447
2019-07-27 04:07:49f1064c1ac2e0f067fda756342a18a992n/a190.154.203.218:449
2019-07-27 04:03:443dbae3111d90e8d11af9f88d1fea82efVirustotal results 39/71 (54.93%) 108.174.56.159:447
2019-07-27 04:03:443dbae3111d90e8d11af9f88d1fea82efVirustotal results 39/71 (54.93%) 131.196.184.141:449
2019-07-27 04:03:443dbae3111d90e8d11af9f88d1fea82efVirustotal results 39/71 (54.93%) 190.154.203.218:449
2019-07-27 04:03:443dbae3111d90e8d11af9f88d1fea82efVirustotal results 39/71 (54.93%) 107.173.34.151:447
2019-07-27 03:46:07132002b66ef4ea621b4e73d86fbb70faVirustotal results 38/70 (54.29%) 185.141.25.116:447
2019-07-27 03:46:07132002b66ef4ea621b4e73d86fbb70faVirustotal results 38/70 (54.29%) 189.80.134.122:449
2019-07-27 03:46:07132002b66ef4ea621b4e73d86fbb70faVirustotal results 38/70 (54.29%) 125.99.253.34:449
2019-07-27 03:42:37eb6596b61da6d804e924c7296f4fd51bVirustotal results 18/69 (26.09%) 185.141.25.116:447
2019-07-27 03:42:37eb6596b61da6d804e924c7296f4fd51bVirustotal results 18/69 (26.09%) 189.80.134.122:449
2019-07-27 03:42:37eb6596b61da6d804e924c7296f4fd51bVirustotal results 18/69 (26.09%) 107.172.248.98:447
2019-07-27 03:42:37eb6596b61da6d804e924c7296f4fd51bVirustotal results 18/69 (26.09%) 36.89.85.103:449
2019-07-26 23:50:54082c15ba156f6ff83233b3b827769c2fVirustotal results 17/67 (25.37%) 107.173.140.104:447
2019-07-26 23:50:54082c15ba156f6ff83233b3b827769c2fVirustotal results 17/67 (25.37%) 189.80.134.122:449
2019-07-26 23:50:54082c15ba156f6ff83233b3b827769c2fVirustotal results 17/67 (25.37%) 190.154.203.218:449
2019-07-26 23:36:581eeb712e840be61d7d3691fc6491855dVirustotal results 37/70 (52.86%) 108.174.56.159:447
2019-07-26 23:36:581eeb712e840be61d7d3691fc6491855dVirustotal results 37/70 (52.86%) 185.61.148.203:447
2019-07-26 23:36:581eeb712e840be61d7d3691fc6491855dVirustotal results 37/70 (52.86%) 190.154.203.218:449
2019-07-26 23:19:25b62aa244c6661c8812660b89b7453c59Virustotal results 39/71 (54.93%) 192.3.83.168:447
2019-07-26 23:19:25b62aa244c6661c8812660b89b7453c59Virustotal results 39/71 (54.93%) 190.154.203.218:449
2019-07-26 19:02:396ec0f9117658d286aec47246780068e9n/a192.210.132.15:443
2019-07-26 19:02:396ec0f9117658d286aec47246780068e9n/a107.173.140.104:447
2019-07-26 19:02:396ec0f9117658d286aec47246780068e9n/a190.152.4.210:449
2019-07-26 17:53:5213195149918cf9652d2356d3b14af87cVirustotal results 38/71 (53.52%) 186.42.186.202:449
2019-07-26 17:53:5213195149918cf9652d2356d3b14af87cVirustotal results 38/71 (53.52%) 107.173.34.151:447
2019-07-26 17:53:5213195149918cf9652d2356d3b14af87cVirustotal results 38/71 (53.52%) 181.129.140.140:449
2019-07-26 17:53:5213195149918cf9652d2356d3b14af87cVirustotal results 38/71 (53.52%) 108.174.56.159:447
2019-07-26 17:53:5113195149918cf9652d2356d3b14af87cVirustotal results 38/71 (53.52%) 189.80.134.122:449
2019-07-26 17:40:3622f257d9cb7a222f16d785136f78b3e9Virustotal results 29/70 (41.43%) 107.173.34.151:447
2019-07-26 17:40:3622f257d9cb7a222f16d785136f78b3e9Virustotal results 29/70 (41.43%) 181.129.93.226:449

# of entries: 100 (max: 100)