JA3 Fingerprints

You can find further information about the JA3 fingerprint 1d095e68489d3c535297cd8dffb06cb9, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:1d095e68489d3c535297cd8dffb06cb9
First seen:2017-08-12 19:56:28 UTC
Last seen:2019-01-05 19:56:32 UTC
Status:Blacklisted
Malware samples:33
Destination IPs:32
Malware:Tofsee -
Listing date:2018-11-14 12:52:51

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2019-01-05 19:56:32a26dd9ab29f62033ad37ebc874a20a7cn/a31.13.72.8:443
2018-12-13 20:12:454b2405676f726333a5ad5754ae3af6b4Virustotal results 36/68 (52.94%) 185.60.216.15:443
2018-12-07 06:32:511493bba5bf03b8580e145de4453b8287Virustotal results 15/70 (21.43%) 104.16.120.50:443
2018-11-16 13:26:370d0e3832ff519b3ce734f8f122debcf4Virustotal results 27/67 (40.30%) 185.60.216.15:443
2018-10-09 04:51:50e16582bbc7a4adcc0d7791b6b3ae6ca7Virustotal results 37/69 (53.62%) 80.12.24.10:993
2018-10-09 04:51:50e16582bbc7a4adcc0d7791b6b3ae6ca7Virustotal results 37/69 (53.62%) 212.27.48.2:993
2018-09-08 08:36:38ebd6d9e598b593e72bc70b3eef9379e2Virustotal results 37/68 (54.41%) 8.42.96.52:443
2018-08-07 19:53:365aa41bee21e519b59ef6654fffdcd83cVirustotal results 36/68 (52.94%) 66.211.179.180:443
2018-08-07 19:53:365aa41bee21e519b59ef6654fffdcd83cVirustotal results 36/68 (52.94%) 66.135.194.123:443
2018-08-07 19:53:365aa41bee21e519b59ef6654fffdcd83cVirustotal results 36/68 (52.94%) 66.135.203.166:443
2018-08-07 19:53:365aa41bee21e519b59ef6654fffdcd83cVirustotal results 36/68 (52.94%) 66.135.213.236:443
2018-08-07 19:53:365aa41bee21e519b59ef6654fffdcd83cVirustotal results 36/68 (52.94%) 66.211.161.211:443
2018-08-07 19:53:365aa41bee21e519b59ef6654fffdcd83cVirustotal results 36/68 (52.94%) 66.135.211.101:443
2018-08-07 19:53:365aa41bee21e519b59ef6654fffdcd83cVirustotal results 36/68 (52.94%) 66.135.203.198:443
2018-08-07 19:53:365aa41bee21e519b59ef6654fffdcd83cVirustotal results 36/68 (52.94%) 66.135.211.100:443
2018-08-07 19:53:365aa41bee21e519b59ef6654fffdcd83cVirustotal results 36/68 (52.94%) 66.211.179.150:443
2018-07-29 10:13:12260233e99f6c8d4df7260ac1ff33f023Virustotal results 37/68 (54.41%) 66.135.211.101:443
2018-07-29 10:13:12260233e99f6c8d4df7260ac1ff33f023Virustotal results 37/68 (54.41%) 66.135.194.123:443
2018-07-05 11:01:04ce8fdb3df879be0b02547a98f58f0a08Virustotal results 41/67 (61.19%) 151.101.1.140:443
2018-07-05 02:33:08e5dfe98e38ab3ec6644f7be47f1f2757Virustotal results 40/67 (59.70%) 151.101.85.140:443
2018-04-09 23:49:01486902e15220dbd0bf14dab73d319452Virustotal results 48/67 (71.64%) 23.75.208.40:443
2018-03-15 18:01:268811babed9c459bc29cb6e7750856103Virustotal results 49/67 (73.13%) 66.211.168.91:443
2018-03-15 11:00:092f5b4cb7b255a824b590328a4e32c663Virustotal results 31/60 (51.67%) 173.0.84.98:443
2018-03-15 09:51:25c6f1bd8fbc0a6548a92109ccd91b5474Virustotal results 43/67 (64.18%) 173.0.84.98:443
2018-03-15 09:43:0011e405b169a9277db4d3b97ef85957c8Virustotal results 49/67 (73.13%) 173.0.84.98:443
2018-03-15 04:05:02095d070d4524a88029710b364a43c9deVirustotal results 51/66 (77.27%) 173.0.88.98:443
2018-02-21 14:32:49ac9bac6fac42462867809ffe8c5c3333Virustotal results 33/68 (48.53%) 217.69.139.60:443
2018-02-21 08:11:1120cbac1db50b4842d8718f431e9d1dadn/a23.36.225.57:443
2018-02-21 04:35:337100fc1d3286476063f65c3c03683e3cn/a23.217.109.227:443
2018-02-21 03:49:09a2973d5c11d6c7ef9a93304b78fa96e8Virustotal results 42/68 (61.76%) 23.217.109.227:443
2018-02-21 01:46:188e12f3be4b169f4627bb67f987710f4aVirustotal results 44/68 (64.71%) 2.20.78.12:443
2018-02-21 01:31:268744b6e1eae4ec3d9f66c32947561e2bVirustotal results 44/68 (64.71%) 23.217.109.227:443
2018-02-21 00:36:26cde6871551e5ffa76c7311e70e2de1baVirustotal results 42/67 (62.69%) 23.36.225.57:443
2018-02-20 23:35:4478b84e7642c755add2dfdf9249313576Virustotal results 41/68 (60.29%) 23.36.225.57:443
2018-02-20 23:20:417edbcaad6177bc721e01e370740fb91fn/a23.217.109.227:443
2018-02-20 22:07:42123f4de2d834059a35814a709515fca7n/a2.18.234.35:443
2018-02-18 08:20:328fe4b20b4121b4e4d19cab10f2789741Virustotal results 48/67 (71.64%) 23.36.225.57:443
2018-02-16 20:58:151f42efd2f7a1372227026ec7ca505d1dVirustotal results 34/68 (50.00%) 23.217.109.227:443
2018-02-03 14:00:11058d0d58c6087982e4eb77b7492d81aeVirustotal results 44/65 (67.69%) 104.20.39.142:443
2018-01-19 08:03:428820ace121cf7def54bb539f7be1b945Virustotal results 32/66 (48.48%) 203.234.219.124:443
2018-01-19 08:03:428820ace121cf7def54bb539f7be1b945Virustotal results 32/66 (48.48%) 211.45.37.10:443
2018-01-15 13:59:1396f06a121e2a216933e07b73ce771666Virustotal results 13/67 (19.40%) 66.135.203.198:443
2018-01-15 13:59:1396f06a121e2a216933e07b73ce771666Virustotal results 13/67 (19.40%) 66.211.179.150:443
2018-01-15 13:59:1396f06a121e2a216933e07b73ce771666Virustotal results 13/67 (19.40%) 66.135.203.166:443
2018-01-15 13:59:1396f06a121e2a216933e07b73ce771666Virustotal results 13/67 (19.40%) 66.135.209.82:443
2018-01-15 13:59:1396f06a121e2a216933e07b73ce771666Virustotal results 13/67 (19.40%) 66.135.213.210:443
2017-11-08 18:52:0121d91154a84095b9d701ec7ea093f554n/a66.135.203.166:443
2017-11-08 18:52:0121d91154a84095b9d701ec7ea093f554n/a66.135.211.100:443
2017-11-08 18:52:0121d91154a84095b9d701ec7ea093f554n/a66.211.179.180:443
2017-11-08 18:52:0121d91154a84095b9d701ec7ea093f554n/a66.135.211.101:443
2017-11-08 18:52:0121d91154a84095b9d701ec7ea093f554n/a66.211.179.150:443
2017-08-12 19:56:287b464466e9386eba1a90e581b30d849bVirustotal results 43/56 (76.79%) 104.25.38.26:443

# of entries: 52 (max: 100)