JA3 Fingerprints

You can find further information about the JA3 fingerprint 1d095e68489d3c535297cd8dffb06cb9, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:1d095e68489d3c535297cd8dffb06cb9
First seen:2017-08-12 19:56:28 UTC
Last seen:2020-05-30 05:21:32 UTC
Status:Blacklisted
Malware samples:65
Destination IPs:69
Malware:Tofsee -
Listing date:2018-11-14 12:52:51

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2020-05-30 05:21:327a3f4ff5f17743604dbcbf9b0fa69626Virustotal results 24 / 73 (32.88%) 31.13.70.1:443
2020-04-21 17:08:42125c8c1bfe684223c36f5258b7aadbf4Virustotal results 41 / 72 (56.94%) 31.13.70.1:443
2020-04-10 18:39:45c7777b9401bde070e12a26b763096273Virustotal results 42 / 72 (58.33%) 157.240.17.17:443
2020-03-30 18:35:5431c141bc80f71a4ba2ed422590496a56n/a125.209.238.153:993
2020-03-30 18:35:5431c141bc80f71a4ba2ed422590496a56n/a203.217.227.162:993
2020-03-25 16:19:4239b961c13850e7910d07c9d1993b47a7Virustotal results 20 / 72 (27.78%) 31.13.92.10:443
2020-03-19 21:25:46a990bfa906c958fd3e735278ef046e41Virustotal results 54 / 73 (73.97%) 31.13.92.36:443
2020-01-22 01:39:26bb4bc69313d7cb79534650ff90b839b7n/a217.146.190.234:993
2019-11-07 20:05:48aa1134e88d0118a445ea5871eabf01d7Virustotal results 37 / 71 (52.11%) 208.118.63.36:993
2019-11-07 06:27:08f048bb9072ef1736dcfc47e771699d2aVirustotal results 51 / 71 (71.83%) 35.168.84.102:443
2019-11-07 05:31:2528685dde1ca6b4b3ddd792c2f6b49c5fVirustotal results 35 / 72 (48.61%) 3.91.135.215:443
2019-10-09 21:56:3340b4f5fe690c83a52ac479c554a90ef4n/a117.53.114.13:995
2019-10-09 21:48:2880bb6f54e052751d7b377cb875530d28n/a117.53.114.13:995
2019-09-14 08:56:50fba6ba534d1dc1bb74a9ff97f49fb33fn/a217.74.64.236:993
2019-09-12 06:41:359c6d855e81c1bc5972e248ac1614a37cn/a54.85.109.5:443
2019-09-12 06:41:349c6d855e81c1bc5972e248ac1614a37cn/a52.204.167.205:443
2019-09-12 06:41:339c6d855e81c1bc5972e248ac1614a37cn/a34.229.8.114:443
2019-09-12 06:41:329c6d855e81c1bc5972e248ac1614a37cn/a52.6.88.49:443
2019-09-12 06:41:329c6d855e81c1bc5972e248ac1614a37cn/a54.82.145.47:443
2019-09-12 06:39:5085d4178488527a5506f1b1bb5f044196Virustotal results 22 / 69 (31.88%) 52.4.128.184:443
2019-09-11 20:14:51ddde4ae918caff05b5db6e330c7eed10n/a54.80.65.78:443
2019-09-04 21:06:084ea69070aa479dc889a2fc52edca500eVirustotal results 28 / 70 (40.00%) 213.180.147.154:993
2019-08-29 01:35:521b3b89f3572ad5bf2822ac39b49bfd78n/a146.20.147.246:993
2019-08-28 17:40:5379bba380f743b0add5e0fc01aa606504n/a77.238.185.51:993
2019-07-21 17:19:5335dc0eb0f593aad80d0263e56fc4dccfn/a77.238.185.51:993
2019-07-15 13:17:03d90111f59c6d8fe8cad98c7dd1659d9bn/a195.130.132.15:993
2019-07-15 13:17:03d90111f59c6d8fe8cad98c7dd1659d9bn/a77.238.185.51:993
2019-07-15 13:17:03d90111f59c6d8fe8cad98c7dd1659d9bn/a108.177.126.108:993
2019-06-30 19:29:441aca3c0d9a66623c64d99b9019d80eebn/a173.194.69.109:993
2019-06-30 13:19:1769faf13147f3becfb9c372201ef039f7n/a77.238.185.51:993
2019-06-30 13:19:1669faf13147f3becfb9c372201ef039f7n/a40.101.80.2:993
2019-06-29 18:20:17ea52a134bf24974c665a7ede382c35e0Virustotal results 45/71 (63.38%) 188.125.73.109:993
2019-06-29 05:26:239495f6da1a244f2e6cef8d368a2a9490n/a77.238.185.51:993
2019-06-29 05:26:239495f6da1a244f2e6cef8d368a2a9490n/a40.101.41.162:993
2019-06-29 05:26:209495f6da1a244f2e6cef8d368a2a9490n/a40.101.125.226:993
2019-06-24 15:05:149c1f806d943252b0a4f5c0b615b5fd14n/a188.125.73.109:993
2019-06-24 15:05:139c1f806d943252b0a4f5c0b615b5fd14n/a217.146.190.234:993
2019-06-24 12:03:31c934eac36e129d140cbcdfeef5d79bb6n/a98.136.102.26:993
2019-06-22 07:38:081c11e2985474128ddef2a34961591c0bVirustotal results 27/69 (39.13%) 217.146.190.234:993
2019-06-22 07:38:071c11e2985474128ddef2a34961591c0bVirustotal results 27/69 (39.13%) 77.75.79.170:993
2019-06-16 20:46:2633ede7e2497d0a627f6b9656fec566c1n/a64.98.36.151:993
2019-06-16 20:46:2533ede7e2497d0a627f6b9656fec566c1n/a213.180.147.154:993
2019-06-08 09:10:206e5f202d9145b281f075c6ef480ee924Virustotal results 29/72 (40.28%) 35.153.58.124:443
2019-06-08 09:10:196e5f202d9145b281f075c6ef480ee924Virustotal results 29/72 (40.28%) 34.238.74.93:443
2019-06-08 09:10:196e5f202d9145b281f075c6ef480ee924Virustotal results 29/72 (40.28%) 52.5.219.22:443
2019-05-19 03:23:066b3656c5adf8f094f252455982c7f546Virustotal results 42/73 (57.53%) 31.13.92.36:443
2019-04-12 14:12:180f1a79ccdb4d3ca3608b60f98785220cn/a34.233.159.233:443
2019-04-12 14:12:180f1a79ccdb4d3ca3608b60f98785220cn/a34.236.111.10:443
2019-01-05 19:56:32a26dd9ab29f62033ad37ebc874a20a7cn/a31.13.72.8:443
2018-12-13 20:12:454b2405676f726333a5ad5754ae3af6b4Virustotal results 36/68 (52.94%) 185.60.216.15:443
2018-12-07 06:32:511493bba5bf03b8580e145de4453b8287Virustotal results 15/70 (21.43%) 104.16.120.50:443
2018-11-16 13:26:370d0e3832ff519b3ce734f8f122debcf4Virustotal results 27/67 (40.30%) 185.60.216.15:443
2018-10-09 04:51:50e16582bbc7a4adcc0d7791b6b3ae6ca7Virustotal results 37/69 (53.62%) 80.12.24.10:993
2018-10-09 04:51:50e16582bbc7a4adcc0d7791b6b3ae6ca7Virustotal results 37/69 (53.62%) 212.27.48.2:993
2018-09-08 08:36:38ebd6d9e598b593e72bc70b3eef9379e2Virustotal results 37/68 (54.41%) 8.42.96.52:443
2018-08-07 19:53:365aa41bee21e519b59ef6654fffdcd83cVirustotal results 36/68 (52.94%) 66.135.213.236:443
2018-08-07 19:53:365aa41bee21e519b59ef6654fffdcd83cVirustotal results 36/68 (52.94%) 66.135.194.123:443
2018-08-07 19:53:365aa41bee21e519b59ef6654fffdcd83cVirustotal results 36/68 (52.94%) 66.135.203.166:443
2018-08-07 19:53:365aa41bee21e519b59ef6654fffdcd83cVirustotal results 36/68 (52.94%) 66.211.179.180:443
2018-08-07 19:53:365aa41bee21e519b59ef6654fffdcd83cVirustotal results 36/68 (52.94%) 66.211.161.211:443
2018-08-07 19:53:365aa41bee21e519b59ef6654fffdcd83cVirustotal results 36/68 (52.94%) 66.135.211.101:443
2018-08-07 19:53:365aa41bee21e519b59ef6654fffdcd83cVirustotal results 36/68 (52.94%) 66.135.203.198:443
2018-08-07 19:53:365aa41bee21e519b59ef6654fffdcd83cVirustotal results 36/68 (52.94%) 66.135.211.100:443
2018-08-07 19:53:365aa41bee21e519b59ef6654fffdcd83cVirustotal results 36/68 (52.94%) 66.211.179.150:443
2018-07-29 10:13:12260233e99f6c8d4df7260ac1ff33f023Virustotal results 37/68 (54.41%) 66.135.211.101:443
2018-07-29 10:13:12260233e99f6c8d4df7260ac1ff33f023Virustotal results 37/68 (54.41%) 66.135.194.123:443
2018-07-05 11:01:04ce8fdb3df879be0b02547a98f58f0a08Virustotal results 41/67 (61.19%) 151.101.1.140:443
2018-07-05 02:33:08e5dfe98e38ab3ec6644f7be47f1f2757Virustotal results 40/67 (59.70%) 151.101.85.140:443
2018-04-09 23:49:01486902e15220dbd0bf14dab73d319452Virustotal results 48/67 (71.64%) 23.75.208.40:443
2018-03-15 18:01:268811babed9c459bc29cb6e7750856103Virustotal results 49/67 (73.13%) 66.211.168.91:443
2018-03-15 11:00:092f5b4cb7b255a824b590328a4e32c663Virustotal results 31/60 (51.67%) 173.0.84.98:443
2018-03-15 09:51:25c6f1bd8fbc0a6548a92109ccd91b5474Virustotal results 43/67 (64.18%) 173.0.84.98:443
2018-03-15 09:43:0011e405b169a9277db4d3b97ef85957c8Virustotal results 49/67 (73.13%) 173.0.84.98:443
2018-03-15 04:05:02095d070d4524a88029710b364a43c9deVirustotal results 51/66 (77.27%) 173.0.88.98:443
2018-02-21 14:32:49ac9bac6fac42462867809ffe8c5c3333Virustotal results 33/68 (48.53%) 217.69.139.60:443
2018-02-21 08:11:1120cbac1db50b4842d8718f431e9d1dadn/a23.36.225.57:443
2018-02-21 04:35:337100fc1d3286476063f65c3c03683e3cn/a23.217.109.227:443
2018-02-21 03:49:09a2973d5c11d6c7ef9a93304b78fa96e8Virustotal results 42/68 (61.76%) 23.217.109.227:443
2018-02-21 01:46:188e12f3be4b169f4627bb67f987710f4aVirustotal results 44/68 (64.71%) 2.20.78.12:443
2018-02-21 01:31:268744b6e1eae4ec3d9f66c32947561e2bVirustotal results 44/68 (64.71%) 23.217.109.227:443
2018-02-21 00:36:26cde6871551e5ffa76c7311e70e2de1baVirustotal results 42/67 (62.69%) 23.36.225.57:443
2018-02-20 23:35:4478b84e7642c755add2dfdf9249313576Virustotal results 41/68 (60.29%) 23.36.225.57:443
2018-02-20 23:20:417edbcaad6177bc721e01e370740fb91fn/a23.217.109.227:443
2018-02-20 22:07:42123f4de2d834059a35814a709515fca7n/a2.18.234.35:443
2018-02-18 08:20:328fe4b20b4121b4e4d19cab10f2789741Virustotal results 48/67 (71.64%) 23.36.225.57:443
2018-02-16 20:58:151f42efd2f7a1372227026ec7ca505d1dVirustotal results 34/68 (50.00%) 23.217.109.227:443
2018-02-03 14:00:11058d0d58c6087982e4eb77b7492d81aeVirustotal results 44/65 (67.69%) 104.20.39.142:443
2018-01-19 08:03:428820ace121cf7def54bb539f7be1b945Virustotal results 32/66 (48.48%) 203.234.219.124:443
2018-01-19 08:03:428820ace121cf7def54bb539f7be1b945Virustotal results 32/66 (48.48%) 211.45.37.10:443
2018-01-15 13:59:1396f06a121e2a216933e07b73ce771666Virustotal results 13/67 (19.40%) 66.135.203.198:443
2018-01-15 13:59:1396f06a121e2a216933e07b73ce771666Virustotal results 13/67 (19.40%) 66.211.179.150:443
2018-01-15 13:59:1396f06a121e2a216933e07b73ce771666Virustotal results 13/67 (19.40%) 66.135.203.166:443
2018-01-15 13:59:1396f06a121e2a216933e07b73ce771666Virustotal results 13/67 (19.40%) 66.135.209.82:443
2018-01-15 13:59:1396f06a121e2a216933e07b73ce771666Virustotal results 13/67 (19.40%) 66.135.213.210:443
2017-11-08 18:52:0121d91154a84095b9d701ec7ea093f554n/a66.135.203.166:443
2017-11-08 18:52:0121d91154a84095b9d701ec7ea093f554n/a66.135.211.100:443
2017-11-08 18:52:0121d91154a84095b9d701ec7ea093f554n/a66.211.179.180:443
2017-11-08 18:52:0121d91154a84095b9d701ec7ea093f554n/a66.135.211.101:443
2017-11-08 18:52:0121d91154a84095b9d701ec7ea093f554n/a66.211.179.150:443
2017-08-12 19:56:287b464466e9386eba1a90e581b30d849bVirustotal results 43/56 (76.79%) 104.25.38.26:443

# of entries: 100 (max: 100)