JA3 Fingerprints

You can find further information about the JA3 fingerprint 44dab16d680ef93487bc16ad23b3ffb1, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:44dab16d680ef93487bc16ad23b3ffb1
First seen:2019-06-09 22:55:29 UTC
Last seen:2020-10-27 09:50:25 UTC
Status:Blacklisted
Malware samples:776
Destination IPs:27
Malware:Tofsee -
Listing date:2020-01-09 14:27:11

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2020-10-27 09:50:25bf286601fae0a332024b19cc5d73fd20Virustotal results 42 / 62 (67.74%) 31.13.72.36:443
2020-10-27 09:50:19bf286601fae0a332024b19cc5d73fd20Virustotal results 42 / 62 (67.74%) 31.13.72.8:443
2020-10-26 05:36:35b843c3f02573103d11fa3f27b301eca1n/a31.13.72.36:443
2020-10-26 05:36:35b843c3f02573103d11fa3f27b301eca1n/a31.13.72.8:443
2020-10-25 22:55:109708df839d349218b41bf0232eb35c0fVirustotal results 51 / 70 (72.86%) 157.240.194.35:443
2020-10-25 22:55:109708df839d349218b41bf0232eb35c0fVirustotal results 51 / 70 (72.86%) 157.240.194.18:443
2020-10-25 22:55:099708df839d349218b41bf0232eb35c0fVirustotal results 51 / 70 (72.86%) 31.13.72.36:443
2020-10-25 22:20:57859d7f3b36bba74f209c6452518572cdn/a157.240.194.18:443
2020-10-25 22:20:57859d7f3b36bba74f209c6452518572cdn/a31.13.72.36:443
2020-10-25 22:20:56859d7f3b36bba74f209c6452518572cdn/a157.240.194.35:443
2020-10-25 22:00:497d9e8367c683735bb52a10a7de258baan/a31.13.72.36:443
2020-10-25 22:00:487d9e8367c683735bb52a10a7de258baan/a31.13.72.8:443
2020-10-25 20:28:38539cd443a98e3c8649164e6ae8f037adn/a31.13.72.36:443
2020-10-25 20:28:37539cd443a98e3c8649164e6ae8f037adn/a157.240.205.35:443
2020-10-25 20:28:37539cd443a98e3c8649164e6ae8f037adn/a157.240.205.1:443
2020-10-25 20:26:5758205c8ad4a98174c258ca90c0a44fd5Virustotal results 48 / 68 (70.59%) 31.13.72.8:443
2020-10-25 20:26:5658205c8ad4a98174c258ca90c0a44fd5Virustotal results 48 / 68 (70.59%) 31.13.72.36:443
2020-10-25 19:36:083576753fcb7f79349fb3a9f38b2c3a20n/a31.13.72.36:443
2020-10-25 14:06:49ad919090ecd88f745d9c40460d7c3d1fn/a31.13.72.36:443
2020-10-25 14:06:48ad919090ecd88f745d9c40460d7c3d1fn/a31.13.72.8:443
2020-10-25 00:05:268bd06c87d780a175d505065a4cf83f76n/a31.13.72.36:443
2020-10-25 00:05:258bd06c87d780a175d505065a4cf83f76n/a31.13.72.8:443
2020-10-25 00:05:258bd06c87d780a175d505065a4cf83f76n/a157.240.194.35:443
2020-10-24 23:54:4989b9eb7fe0ce2028b3e39a0d7f6cb7cbn/a31.13.72.36:443
2020-10-24 23:54:4989b9eb7fe0ce2028b3e39a0d7f6cb7cbn/a157.240.205.1:443
2020-10-24 23:54:4889b9eb7fe0ce2028b3e39a0d7f6cb7cbn/a157.240.205.35:443
2020-10-24 19:48:512dae1502cd919dad14dd7933fe836922n/a31.13.72.8:443
2020-10-24 19:48:502dae1502cd919dad14dd7933fe836922n/a31.13.72.36:443
2020-10-24 12:22:46b73add72b2e157b120b6f6462123a926Virustotal results 43 / 71 (60.56%) 157.240.194.18:443
2020-10-24 12:22:46b73add72b2e157b120b6f6462123a926Virustotal results 43 / 71 (60.56%) 31.13.72.36:443
2020-10-24 12:22:46b73add72b2e157b120b6f6462123a926Virustotal results 43 / 71 (60.56%) 157.240.20.35:443
2020-10-24 07:56:49aeb0d6b1099fa17d0226665045157f1fVirustotal results 47 / 62 (75.81%) 31.13.72.36:443
2020-10-24 07:56:47aeb0d6b1099fa17d0226665045157f1fVirustotal results 47 / 62 (75.81%) 157.240.194.18:443
2020-10-23 22:01:399ea75512d50807ddb2f7cf65ce1f44d1n/a31.13.72.36:443
2020-10-23 22:01:399ea75512d50807ddb2f7cf65ce1f44d1n/a31.13.72.8:443
2020-10-23 22:01:389ea75512d50807ddb2f7cf65ce1f44d1n/a157.240.194.35:443
2020-10-23 21:33:208b229274260396a4270883be7b72b352n/a31.13.72.36:443
2020-10-23 21:33:208b229274260396a4270883be7b72b352n/a157.240.205.1:443
2020-10-23 21:27:268a979ae312b67ccbc284588e39e7bbc7n/a31.13.72.8:443
2020-10-23 21:27:268a979ae312b67ccbc284588e39e7bbc7n/a31.13.72.36:443
2020-10-23 20:41:286bd342a86c98caaad5d9d2081d987a7an/a157.240.194.35:443
2020-10-23 20:41:276bd342a86c98caaad5d9d2081d987a7an/a31.13.72.36:443
2020-10-23 20:41:266bd342a86c98caaad5d9d2081d987a7an/a31.13.72.8:443
2020-10-23 20:41:266bd342a86c98caaad5d9d2081d987a7an/a157.240.205.35:443
2020-10-23 20:29:0763f714133147e7f08b76a34f77f21471n/a31.13.72.8:443
2020-10-23 20:29:0663f714133147e7f08b76a34f77f21471n/a157.240.194.35:443
2020-10-23 20:29:0663f714133147e7f08b76a34f77f21471n/a31.13.72.36:443
2020-10-23 19:20:145a161856d8a472bee3de7ca256a733d0Virustotal results 44 / 61 (72.13%) 157.240.194.18:443
2020-10-23 19:20:145a161856d8a472bee3de7ca256a733d0Virustotal results 44 / 61 (72.13%) 31.13.72.36:443
2020-10-22 11:59:14cfcd4edd2a5c3212a649c90e8c28108fVirustotal results 38 / 69 (55.07%) 31.13.72.8:443
2020-10-22 11:59:14cfcd4edd2a5c3212a649c90e8c28108fVirustotal results 38 / 69 (55.07%) 31.13.72.36:443
2020-10-22 11:59:14cfcd4edd2a5c3212a649c90e8c28108fVirustotal results 38 / 69 (55.07%) 157.240.194.35:443
2020-10-22 04:01:531ea097dac06a568e8b73d5931df71205Virustotal results 55 / 71 (77.46%) 31.13.72.36:443
2020-10-22 04:01:521ea097dac06a568e8b73d5931df71205Virustotal results 55 / 71 (77.46%) 185.60.216.15:443
2020-10-21 12:40:07e767f4a18f1fd62795b7657c5af25b94Virustotal results 45 / 69 (65.22%) 185.60.216.15:443
2020-10-21 12:40:07e767f4a18f1fd62795b7657c5af25b94Virustotal results 45 / 69 (65.22%) 185.60.216.35:443
2020-10-21 10:38:36cf1f24fb8868b9a2aefa040f6372110an/a185.60.216.35:443
2020-10-21 10:38:36cf1f24fb8868b9a2aefa040f6372110an/a185.60.216.15:443
2020-10-21 08:09:37ac4cd39c271ea76c7cfcc5c4ca2f6aebVirustotal results 49 / 71 (69.01%) 157.240.194.18:443
2020-10-21 08:09:36ac4cd39c271ea76c7cfcc5c4ca2f6aebVirustotal results 49 / 71 (69.01%) 31.13.72.36:443
2020-10-21 05:00:055959fb4fdac381625895c71b6aa82354Virustotal results 52 / 71 (73.24%) 31.13.72.8:443
2020-10-21 05:00:055959fb4fdac381625895c71b6aa82354Virustotal results 52 / 71 (73.24%) 31.13.72.36:443
2020-10-20 20:27:05296c19e924a55e9c543704a54b83bb83n/a31.13.72.8:443
2020-10-20 20:27:04296c19e924a55e9c543704a54b83bb83n/a157.240.205.35:443
2020-10-20 20:27:02296c19e924a55e9c543704a54b83bb83n/a157.240.194.35:443
2020-10-20 20:20:31246811115e42c1e330c6b2cc779f1314Virustotal results 41 / 71 (57.75%) 31.13.72.8:443
2020-10-20 12:07:07d83b97357d25de17ce7753c358a6ad84Virustotal results 50 / 69 (72.46%) 157.240.205.35:443
2020-10-20 12:07:06d83b97357d25de17ce7753c358a6ad84Virustotal results 50 / 69 (72.46%) 31.13.72.8:443
2020-10-20 12:07:06d83b97357d25de17ce7753c358a6ad84Virustotal results 50 / 69 (72.46%) 31.13.72.36:443
2020-10-20 09:31:47cf58effcb1d31dfa9e075ccebc18b889Virustotal results 41 / 68 (60.29%) 31.13.72.8:443
2020-10-20 09:31:46cf58effcb1d31dfa9e075ccebc18b889Virustotal results 41 / 68 (60.29%) 31.13.72.36:443
2020-10-20 01:10:066de9f7d281407ea5506c5220d9869a6cVirustotal results 48 / 68 (70.59%) 31.13.72.8:443
2020-10-20 01:10:066de9f7d281407ea5506c5220d9869a6cVirustotal results 48 / 68 (70.59%) 31.13.72.36:443
2020-10-20 00:09:575e8cdcd0c462df5d08c29a92452e3df8Virustotal results 50 / 70 (71.43%) 185.60.216.35:443
2020-10-20 00:09:575e8cdcd0c462df5d08c29a92452e3df8Virustotal results 50 / 70 (71.43%) 185.60.216.15:443
2020-10-19 22:42:194ef80a44197d7e37f1d995963758fee2Virustotal results 54 / 71 (76.06%) 31.13.72.8:443
2020-10-19 22:42:184ef80a44197d7e37f1d995963758fee2Virustotal results 54 / 71 (76.06%) 31.13.72.36:443
2020-10-19 21:55:173ddc7e243aa3c841a6ad02b9a7cd8249Virustotal results 56 / 69 (81.16%) 31.13.72.36:443
2020-10-19 21:55:163ddc7e243aa3c841a6ad02b9a7cd8249Virustotal results 56 / 69 (81.16%) 157.240.194.18:443
2020-10-19 21:55:143ddc7e243aa3c841a6ad02b9a7cd8249Virustotal results 56 / 69 (81.16%) 157.240.194.35:443
2020-10-19 21:55:133ddc7e243aa3c841a6ad02b9a7cd8249Virustotal results 56 / 69 (81.16%) 185.60.216.15:443
2020-10-19 19:48:0213ccdcc6a707010adfb9b08fcf838df6Virustotal results 52 / 71 (73.24%) 31.13.72.8:443
2020-10-19 19:48:0213ccdcc6a707010adfb9b08fcf838df6Virustotal results 52 / 71 (73.24%) 185.60.216.35:443
2020-10-19 19:48:0113ccdcc6a707010adfb9b08fcf838df6Virustotal results 52 / 71 (73.24%) 31.13.92.36:443
2020-10-19 14:21:26beba8fbcc297d2abdcb58fc1af743d77n/a185.60.216.35:443
2020-10-19 14:21:25beba8fbcc297d2abdcb58fc1af743d77n/a185.60.216.15:443
2020-10-19 14:21:25beba8fbcc297d2abdcb58fc1af743d77n/a31.13.72.36:443
2020-10-19 09:58:41bb7325a7a8d0e4f6fea479a7e3543477Virustotal results 55 / 70 (78.57%) 157.240.194.35:443
2020-10-19 09:58:41bb7325a7a8d0e4f6fea479a7e3543477Virustotal results 55 / 70 (78.57%) 31.13.72.8:443
2020-10-19 07:08:03b961a1b4d8090f242ebd68718177178bn/a157.240.194.35:443
2020-10-19 07:07:58b961a1b4d8090f242ebd68718177178bn/a31.13.72.8:443
2020-10-19 07:07:56b961a1b4d8090f242ebd68718177178bn/a31.13.72.36:443
2020-10-18 21:07:45ad8adf57cc6e40a4dcf24455037abd94n/a157.240.194.35:443
2020-10-18 21:07:44ad8adf57cc6e40a4dcf24455037abd94n/a31.13.72.8:443
2020-10-18 21:07:42ad8adf57cc6e40a4dcf24455037abd94n/a31.13.72.36:443
2020-10-18 20:54:40acc980a35efcb5dddce6d71c02138db9n/a157.240.194.35:443
2020-10-18 20:54:40acc980a35efcb5dddce6d71c02138db9n/a31.13.72.36:443
2020-10-18 20:54:39acc980a35efcb5dddce6d71c02138db9n/a185.60.216.15:443
2020-10-18 20:00:10861c576e20a6b2015515d671a97367f4n/a185.60.216.15:443
2020-10-18 20:00:09861c576e20a6b2015515d671a97367f4n/a185.60.216.35:443

# of entries: 100 (max: 100)