JA3 Fingerprints

You can find further information about the JA3 fingerprint 25d74b7b4b779eb1efd4b31d26d651c6, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:25d74b7b4b779eb1efd4b31d26d651c6
First seen:2019-08-03 20:15:33 UTC
Last seen:2020-06-06 08:20:40 UTC
Status:Blacklisted
Malware samples:134
Destination IPs:16
Malware:Tofsee -
Listing date:2020-01-09 14:30:41

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2020-06-06 08:20:40291500fd2bd96429e39d3aaee59f7a3fVirustotal results 37 / 72 (51.39%) 40.101.51.114:993
2020-06-04 17:13:4389977105987000082f42424f45a64457Virustotal results 45 / 71 (63.38%) 40.101.51.146:993
2020-06-03 20:11:22444189ff62dbf1b86beed92fdfdb5d90Virustotal results 41 / 73 (56.16%) 40.101.84.2:993
2020-06-03 18:59:334076dfd3e8f7ce86e7c846928aa3661aVirustotal results 21 / 73 (28.77%) 52.97.155.114:993
2020-06-03 05:58:3423a03cd4232c3a51e0cd109b67f18855Virustotal results 34 / 73 (46.58%) 40.101.50.194:993
2020-06-02 23:05:350c076ef11a5eab18ba13181bbdd4f52fVirustotal results 38 / 73 (52.05%) 52.97.144.178:993
2020-06-01 21:04:22565a92e31f0939322a91e35be5c55961Virustotal results 32 / 73 (43.84%) 40.101.12.82:993
2020-06-01 08:23:00165ddff83c7394de9caa7e7199bb0030Virustotal results 56 / 73 (76.71%) 40.101.84.210:993
2020-06-01 07:07:380ef677668df589aa19e622d623139069Virustotal results 46 / 72 (63.89%) 40.101.51.146:993
2020-06-01 06:50:099004f899c8f2e342c9ef722ace6718a9Virustotal results 38 / 73 (52.05%) 40.101.19.162:993
2020-05-31 12:28:555ee07e9f53d82de0ba8eca75b4f12c11Virustotal results 40 / 73 (54.79%) 40.101.84.210:993
2020-05-31 07:59:0043f4ec91f341bc01a16884a3e891fc67Virustotal results 50 / 73 (68.49%) 40.101.121.2:993
2020-05-30 20:20:17905e801af6d84772c2b961a0e1032840Virustotal results 46 / 72 (63.89%) 40.101.84.2:993
2020-05-30 15:45:00776e7db40bc3b50ae269d927c10e1f6dVirustotal results 56 / 73 (76.71%) 40.101.126.130:993
2020-05-30 12:03:0842171261efc6586d2fb11777f49ea3a3Virustotal results 56 / 72 (77.78%) 52.97.163.2:993
2020-05-29 23:39:013c43139fe11d77d4578ce7a103c2b270Virustotal results 39 / 73 (53.42%) 40.101.30.242:993
2020-05-29 20:30:400442765c8308662fc48d5158b8f63410Virustotal results 41 / 72 (56.94%) 40.101.126.130:993
2020-05-29 18:42:141818543d2a2006ae9b498cdec8d1417dVirustotal results 52 / 73 (71.23%) 40.101.28.178:993
2019-09-08 23:30:43e5a795371fddd895edff42606a3612f3n/a217.69.139.90:993
2019-09-08 04:17:5971ee7e217d09aa326fe03ac74326f60dVirustotal results 33 / 68 (48.53%) 217.69.139.90:993
2019-09-08 02:30:4378174d7d966f4afd91cef7d6b847973cVirustotal results 24 / 65 (36.92%) 94.100.180.90:993
2019-09-08 01:33:539edf624e82e937b1e1a89be17db46ea4n/a217.69.139.90:993
2019-09-07 19:09:149f488f91ea3e6e1d033b61ad886e98e3n/a94.100.180.90:993
2019-09-07 18:50:29bd054caf91b0b7bdca83f0d4ac29ce38n/a94.100.180.90:993
2019-09-07 01:55:44d25b1fdd3c50acda31d8c4d6b51d7fe8n/a94.100.180.90:993
2019-09-06 16:00:3217d776a21be0501d2d86276aaa113780n/a217.69.139.90:993
2019-09-06 05:40:33b4aeb05f29bafcb4e9d969a9a6ad56d3Virustotal results 33 / 66 (50.00%) 94.100.180.90:993
2019-09-05 09:56:59db6098971c82933fbb382b7da4dcd304n/a94.100.180.90:993
2019-09-05 09:56:4471edb62981757165054fa172127239a7n/a94.100.180.90:993
2019-09-05 08:52:20115a438807a9262e15b085b26bbea33fn/a94.100.180.90:993
2019-09-05 07:59:02fbc71040ebe5662a7be8a5e8dae81691Virustotal results 23 / 67 (34.33%) 94.100.180.90:993
2019-09-05 01:41:4188ddb800f09364ef57ee2d2dab28ca14n/a217.69.139.90:993
2019-09-05 01:27:317584316e9d238e2e64102ba25b28f5e5n/a94.100.180.90:993
2019-09-04 23:48:55b3fc25cfb8d243450fbd1deef8ff1a97n/a217.69.139.90:993
2019-09-04 23:48:53b3fc25cfb8d243450fbd1deef8ff1a97n/a94.100.180.90:993
2019-09-04 23:40:02f503c557b0dc9d106c7e00dc4ef44716n/a217.69.139.90:993
2019-09-04 23:21:46efc9e65aa1b20cbbe422a3bd33b326f1n/a217.69.139.90:993
2019-09-04 22:30:5881146303e695748cc034121a830667e5Virustotal results 39 / 67 (58.21%) 217.69.139.90:993
2019-09-04 22:01:23d36c91d8d690303b15fd3fde69c941c1n/a94.100.180.90:993
2019-09-04 21:35:301abab6a4bc3518c9be54ad3f68d56e87n/a217.69.139.90:993
2019-09-04 19:23:20c511cc7f9d96bf9f45d45253f7048a17n/a94.100.180.90:993
2019-09-04 19:01:189f958bae4313a3548cdd709a5f73ed14n/a94.100.180.90:993
2019-09-03 12:41:31be8a9af9f3bea0700928db10ee219547Virustotal results 48 / 71 (67.61%) 217.69.139.90:993
2019-09-02 08:33:05138f4808a6dfa79a71ed482de9a7ac64n/a94.100.180.90:993
2019-08-31 10:35:23fe55c19b3e75ff1120a3d000321cbe16n/a94.100.180.90:993
2019-08-31 08:34:0403a9201cdc354544ef4cc021b134fb3bn/a217.69.139.90:993
2019-08-31 08:08:11e0b71794e2b11a9016f25e2dfa04d44cn/a217.69.139.90:993
2019-08-31 06:25:4078a79855c70450e09e387bde9845f043Virustotal results 50 / 70 (71.43%) 94.100.180.90:993
2019-08-30 22:46:371900419ff74feb3fa10222e76dae653bn/a217.69.139.90:993
2019-08-29 11:35:59be5288a99f8ab14468c74223462ed0d0n/a94.100.180.90:993
2019-08-29 03:32:354efdf836385a73344e458c3e8ed8e75dn/a217.69.139.90:993
2019-08-29 02:35:23a44c963eb658ce4179cc97cdb09ceb59n/a217.69.139.90:993
2019-08-29 01:51:248330bac9adf4a7de1a59ff71c98be58en/a217.69.139.90:993
2019-08-29 01:35:511b3b89f3572ad5bf2822ac39b49bfd78n/a217.69.139.90:993
2019-08-28 19:53:50f1e05284e9ea796902d51be4f8faa75fn/a217.69.139.90:993
2019-08-28 18:43:06c37de6e96ff41b24fef03a4c2d8d86adn/a217.69.139.90:993
2019-08-28 18:37:090aaee4ac7aeae520759970136baba3b8n/a217.69.139.90:993
2019-08-28 18:18:1383b627411bc88577470688b52ebb2954n/a94.100.180.90:993
2019-08-28 17:40:5079bba380f743b0add5e0fc01aa606504n/a217.69.139.90:993
2019-08-28 15:48:3992370dced2b628df244c54f64cdc3e64n/a94.100.180.90:993
2019-08-27 06:42:006caed899aa13cfd2ddf5c55bafa34c6cn/a217.69.139.90:993
2019-08-26 16:40:59a54d418d25ee00ea777f6da36b9f116fn/a217.69.139.90:993
2019-08-26 16:32:398658c32ac62efb9cab3b6208ace9fd62n/a94.100.180.90:993
2019-08-26 15:45:0054a27ec1c23cd1994950049de8fa27e6Virustotal results 49/66 (74.24%) 217.69.139.90:993
2019-08-26 14:24:31660da2beb2dfa7abf64a03cb84216221n/a94.100.180.90:993
2019-08-26 14:24:31660da2beb2dfa7abf64a03cb84216221n/a217.69.139.90:993
2019-08-26 07:02:28962512f6453b50ec74cd37dd5ba9581cVirustotal results 53/69 (76.81%) 94.100.180.90:993
2019-08-26 02:40:507a25b766f65b2e4eaf5519831f09189dn/a217.69.139.90:993
2019-08-26 02:40:497a25b766f65b2e4eaf5519831f09189dn/a94.100.180.90:993
2019-08-26 01:00:2745c8e838c8d5f93633469a469ca27b5an/a94.100.180.90:993
2019-08-25 20:49:126a8072c0f448e9fa7404a73cb0da7689n/a94.100.180.90:993
2019-08-25 15:27:51c8a31fa1242b964660cefde7c8f0f9d3Virustotal results 53/71 (74.65%) 217.69.139.90:993
2019-08-25 15:27:47c8a31fa1242b964660cefde7c8f0f9d3Virustotal results 53/71 (74.65%) 94.100.180.90:993
2019-08-25 12:36:117bfd8fa8c135985cbf59f2cb3e5900d3n/a217.69.139.90:993
2019-08-24 19:15:00a47eb4d809198d055788c027b075c38bn/a94.100.180.90:993
2019-08-23 07:57:26d28d097583cf396588d68cde3e2e45f4n/a94.100.180.90:993
2019-08-22 21:57:18cb0c6ed809e889735c06929d6a531a70n/a94.100.180.90:993
2019-08-22 10:42:51f1eaecfc3a873e3d334c9452db94c83bVirustotal results 34 / 69 (49.28%) 94.100.180.90:993
2019-08-22 09:37:454c7f679090d9176f34cb1d4077d5e6d7n/a94.100.180.90:993
2019-08-22 09:22:209e8e418c5d9bcaa90725581788b3cc40n/a94.100.180.90:993
2019-08-21 16:12:32d25624ea134cdfee17550d2d690810acn/a94.100.180.90:993
2019-08-21 10:16:58e9035d91e642f15291011176d2c18a93n/a217.69.139.90:993
2019-08-20 14:38:3482244b315a229888b83ac404a1099bc9Virustotal results 57 / 70 (81.43%) 94.100.180.90:993
2019-08-20 08:06:51ac71a2d4fa2361fb0f40eda1c60bb91dn/a217.69.139.90:993
2019-08-20 06:36:2169fa5ee1140faf1e6b5afa7f0941b15eVirustotal results 24 / 62 (38.71%) 217.69.139.90:993
2019-08-19 17:33:291f61211918dd9fbf7e34ab052f3ac064Virustotal results 37 / 55 (67.27%) 94.100.180.90:993
2019-08-19 16:21:295de1d0a9b802c5e9663a28530d480707n/a217.69.139.90:993
2019-08-19 16:21:285de1d0a9b802c5e9663a28530d480707n/a94.100.180.90:993
2019-08-19 11:51:41554ae474863c2ec225f09781deb7aae1n/a94.100.180.90:993
2019-08-19 11:34:42bc2461d95244c269738b35f301475602n/a217.69.139.90:993
2019-08-19 07:31:3437dcc2420ab0f7e18f1103a100ac991eVirustotal results 36 / 70 (51.43%) 217.69.139.90:993
2019-08-19 06:22:59594d77cea10ab64b1a9c7f21ac59de0bVirustotal results 50 / 70 (71.43%) 94.100.180.90:993
2019-08-18 13:28:3613e0b7c14ef551660ce2237fd3df67e0n/a217.69.139.90:993
2019-08-18 08:31:2021f7eff11d406da221033af1ac3fc299Virustotal results 48 / 70 (68.57%) 217.69.139.90:993
2019-08-17 09:32:078253b910c4c0aba02d06eff9426bacf2n/a94.100.180.90:993
2019-08-17 09:32:078253b910c4c0aba02d06eff9426bacf2n/a217.69.139.90:993
2019-08-17 09:27:316440b648e9fa7d977ff6e7ae0936c633Virustotal results 22 / 62 (35.48%) 217.69.139.90:993
2019-08-16 23:21:08a0b8c4819112a1b0fec77a7ea9259f2bVirustotal results 25 / 65 (38.46%) 94.100.180.90:993
2019-08-16 15:54:325db7ff1c59a49a3745f1a4ddfa6f8910n/a94.100.180.90:993
2019-08-16 09:47:13da4332c8b3b039ce5f40f7038b4c9021n/a94.100.180.90:993

# of entries: 100 (max: 100)