JA3 Fingerprints

You can find further information about the JA3 fingerprint 7dcce5b76c8b17472d024758970a406b, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:7dcce5b76c8b17472d024758970a406b
First seen:2017-11-22 12:42:46 UTC
Last seen:2019-10-19 12:00:47 UTC
Status:Blacklisted
Malware samples:100
Destination IPs:108
Malware:Tofsee -
Listing date:2018-11-14 12:39:56

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2019-10-19 12:00:4793dc038c818571f5fbc134ad8decc6e4Virustotal results 22 / 70 (31.43%) 67.195.228.111:25
2019-10-19 11:56:13f229ae681a7a16c83e35a65e4eeaff22n/a67.195.228.111:25
2019-10-19 11:56:13f229ae681a7a16c83e35a65e4eeaff22n/a173.194.202.26:25
2019-10-19 11:56:13f229ae681a7a16c83e35a65e4eeaff22n/a98.136.96.93:25
2019-10-19 11:56:12f229ae681a7a16c83e35a65e4eeaff22n/a66.102.1.27:25
2019-10-19 11:56:12f229ae681a7a16c83e35a65e4eeaff22n/a172.217.194.26:25
2019-10-19 11:56:11f229ae681a7a16c83e35a65e4eeaff22n/a209.85.233.27:25
2019-10-19 11:05:40df87f70e3cbda59c32a21d8bc8e8c101n/a66.102.1.27:25
2019-10-19 09:02:24ab03cce8dfa7ef39f0e01cc598c50dfbn/a209.85.233.27:25
2019-10-19 09:02:23ab03cce8dfa7ef39f0e01cc598c50dfbn/a172.217.194.26:25
2019-10-19 09:02:22ab03cce8dfa7ef39f0e01cc598c50dfbn/a108.177.97.26:25
2019-10-19 08:33:52e8ae1182391c16c10e553094320798a2n/a67.195.204.79:25
2019-10-19 07:26:14dde62da0b6a443f02f27578841a9d98en/a108.177.97.26:25
2019-10-19 07:26:13dde62da0b6a443f02f27578841a9d98en/a209.85.233.27:25
2019-10-19 07:26:11dde62da0b6a443f02f27578841a9d98en/a173.194.202.27:25
2019-10-19 07:26:10dde62da0b6a443f02f27578841a9d98en/a98.136.96.77:25
2019-10-19 07:26:09dde62da0b6a443f02f27578841a9d98en/a172.217.194.27:25
2019-10-19 07:26:07dde62da0b6a443f02f27578841a9d98en/a98.136.96.91:25
2019-10-19 07:26:07dde62da0b6a443f02f27578841a9d98en/a98.136.96.75:25
2019-10-19 07:26:05dde62da0b6a443f02f27578841a9d98en/a108.177.97.27:25
2019-10-19 07:26:05dde62da0b6a443f02f27578841a9d98en/a67.195.204.80:25
2019-10-19 07:26:05dde62da0b6a443f02f27578841a9d98en/a173.194.76.26:25
2019-10-19 07:26:05dde62da0b6a443f02f27578841a9d98en/a67.195.228.84:25
2019-10-19 07:26:04dde62da0b6a443f02f27578841a9d98en/a209.85.233.26:25
2019-10-19 07:26:04dde62da0b6a443f02f27578841a9d98en/a98.136.96.74:25
2019-10-13 21:24:58e10a1948140fb67565cd26c24fd9b8f6n/a104.18.252.39:443
2019-10-12 14:00:3852afe0fd82d3681e22c636c313de4c1dVirustotal results 48 / 68 (70.59%) 104.18.252.39:443
2019-10-12 07:13:490f447a8a2d9348546a286c167440264dn/a104.18.252.39:443
2019-10-12 07:13:480f447a8a2d9348546a286c167440264dn/a104.18.253.39:443
2019-10-11 20:33:080c1a6790e3bfb0fc4a832c0652ba8aa6Virustotal results 16 / 70 (22.86%) 104.18.252.39:443
2019-10-09 19:55:064c3a95e0fa78130702ee4c700f875b06n/a104.18.252.39:443
2019-10-09 03:26:417d08a8682d10f94009794197d9e53639n/a104.18.168.222:443
2019-10-09 03:26:417d08a8682d10f94009794197d9e53639n/a104.18.169.222:443
2019-10-06 05:26:583ab2b18645e3f116c535053dacf5d94cn/a104.18.252.39:443
2019-10-06 01:24:09d6389897c8b878e594889d6b241afdcen/a104.18.252.39:443
2019-10-05 19:10:147aaf489f50860b85aa4e5f50b9df7ae1n/a13.224.96.81:443
2019-10-05 18:57:46e58f7e7e8225e7b257987a923808b56cn/a13.225.233.7:443
2019-10-05 18:57:46e58f7e7e8225e7b257987a923808b56cn/a13.32.99.112:443
2019-10-05 18:54:2195bf17b99a837e02752b342d20a1e823n/a13.32.99.68:443
2019-10-05 18:54:2195bf17b99a837e02752b342d20a1e823n/a54.230.14.129:443
2019-10-05 18:40:21a7699d8f934caf6d3bb5a58bcc3999e1n/a54.230.14.93:443
2019-10-04 15:23:51a09f3df74f6eac7214eec05990061ff8n/a104.18.252.39:443
2019-10-04 13:52:32eb390f165509eb96be5d9b7c5bd35900Virustotal results 44 / 69 (63.77%) 54.229.68.77:443
2019-10-04 13:52:32eb390f165509eb96be5d9b7c5bd35900Virustotal results 44 / 69 (63.77%) 54.72.216.241:443
2019-10-04 13:52:31eb390f165509eb96be5d9b7c5bd35900Virustotal results 44 / 69 (63.77%) 52.49.6.246:443
2019-10-04 13:52:31eb390f165509eb96be5d9b7c5bd35900Virustotal results 44 / 69 (63.77%) 52.19.40.147:443
2019-10-04 13:14:15b28944e96c54086bfc42d2125a1a9860n/a104.18.253.39:443
2019-10-04 00:02:00350b856631079cb24e46346dfbf0bde6Virustotal results 34 / 70 (48.57%) 104.18.252.39:443
2019-10-04 00:02:00350b856631079cb24e46346dfbf0bde6Virustotal results 34 / 70 (48.57%) 104.18.253.39:443
2019-10-03 22:03:32d4b1672fffa85cd40db6504f4843f5e3n/a104.18.252.39:443
2019-10-03 21:21:30bb2dc3e51552e368cf2a6ad83974cba0Virustotal results 38 / 69 (55.07%) 52.30.103.23:443
2019-09-30 20:36:196cc3472a31d63c80a37ad0740cceeadfn/a104.18.252.39:443
2019-09-28 03:15:31487393b05adc58ca540b8a9cb3eb9644n/a74.125.133.27:25
2019-09-28 02:56:357ec51583156f33d9f0c2b5eadb9b2c1en/a108.177.97.26:25
2019-09-28 02:56:357ec51583156f33d9f0c2b5eadb9b2c1en/a74.125.133.26:25
2019-09-28 02:46:15be83539f87941f6248fddac3f31ffb12n/a74.125.133.27:25
2019-09-28 02:46:13be83539f87941f6248fddac3f31ffb12n/a67.195.204.75:25
2019-09-28 02:46:12be83539f87941f6248fddac3f31ffb12n/a209.85.233.26:25
2019-09-27 10:24:05a3816e94f9993f081548b565edb3157fVirustotal results 53 / 69 (76.81%) 98.136.96.91:25
2019-09-24 09:43:35bbe4d0328da728e6825666b28b252eb8n/a67.195.228.94:25
2019-09-24 09:43:35bbe4d0328da728e6825666b28b252eb8n/a172.217.194.26:25
2019-09-24 06:53:325f90ff925cccb080016dff7dc0094ecdn/a172.217.194.27:25
2019-09-24 06:53:325f90ff925cccb080016dff7dc0094ecdn/a108.177.97.27:25
2019-09-24 06:53:325f90ff925cccb080016dff7dc0094ecdn/a67.195.228.86:25
2019-09-22 21:09:33b9f1b2fa0f7b96893542a1d12eb1b0ccn/a54.154.13.39:443
2019-09-22 21:09:33b9f1b2fa0f7b96893542a1d12eb1b0ccn/a54.194.132.188:443
2019-09-22 21:09:32b9f1b2fa0f7b96893542a1d12eb1b0ccn/a34.253.104.7:443
2019-09-22 20:56:311c616691d390b4848efb81a849745b65n/a52.209.224.161:443
2019-09-22 20:56:311c616691d390b4848efb81a849745b65n/a34.252.179.162:443
2019-09-22 20:54:2913ec2f0fd860c755075c1a6c438c72ddn/a52.51.252.111:443
2019-09-22 20:53:06552fb570b39469bd5b09f1204d7faba2n/a54.194.103.216:443
2019-09-22 20:51:562ec78f0df8be1a0a366bf800006c9c47n/a54.154.12.178:443
2019-09-22 20:51:562ec78f0df8be1a0a366bf800006c9c47n/a52.51.252.111:443
2019-09-22 20:51:562ec78f0df8be1a0a366bf800006c9c47n/a176.34.129.169:443
2019-09-22 20:51:562ec78f0df8be1a0a366bf800006c9c47n/a34.252.114.84:443
2019-09-22 20:51:552ec78f0df8be1a0a366bf800006c9c47n/a34.250.41.147:443
2019-09-22 20:51:552ec78f0df8be1a0a366bf800006c9c47n/a52.30.134.73:443
2019-09-22 20:39:568aae7339a9a2288108fd6c11b206bdfan/a54.154.15.7:443
2019-09-22 20:39:558aae7339a9a2288108fd6c11b206bdfan/a54.72.216.241:443
2019-09-22 20:39:558aae7339a9a2288108fd6c11b206bdfan/a54.171.116.69:443
2019-09-22 20:39:558aae7339a9a2288108fd6c11b206bdfan/a52.30.103.23:443
2019-09-22 20:39:558aae7339a9a2288108fd6c11b206bdfan/a54.76.60.39:443
2019-09-22 20:36:19ffc7acd485477cca6e8cb468cf8b21f6Virustotal results 53 / 69 (76.81%) 54.72.216.241:443
2019-09-22 20:36:19ffc7acd485477cca6e8cb468cf8b21f6Virustotal results 53 / 69 (76.81%) 52.17.227.174:443
2019-09-22 20:36:1083024292f6fcc07d8266022705251f19n/a52.17.227.174:443
2019-09-22 20:36:1083024292f6fcc07d8266022705251f19n/a54.194.132.188:443
2019-09-22 20:36:1083024292f6fcc07d8266022705251f19n/a54.154.15.7:443
2019-09-22 20:36:1083024292f6fcc07d8266022705251f19n/a54.76.60.39:443
2019-09-22 20:36:1083024292f6fcc07d8266022705251f19n/a54.72.216.241:443
2019-09-22 20:34:3615448cd3e29cf0af06ea5543b4295a31n/a98.136.96.76:25
2019-09-22 20:34:3615448cd3e29cf0af06ea5543b4295a31n/a67.195.204.80:25
2019-09-22 20:34:3615448cd3e29cf0af06ea5543b4295a31n/a173.194.202.26:25
2019-09-22 20:34:3615448cd3e29cf0af06ea5543b4295a31n/a67.195.204.72:25
2019-09-22 20:34:3515448cd3e29cf0af06ea5543b4295a31n/a108.177.97.26:25
2019-09-22 20:30:55b8eb44c5655d0ba87a88a4dedd618bacn/a52.30.134.73:443
2019-09-22 20:30:54b8eb44c5655d0ba87a88a4dedd618bacn/a34.252.68.166:443
2019-09-21 13:23:41631804ee86b4e512c8eab3aea8dbdd85n/a108.177.97.26:25
2019-09-21 13:23:41631804ee86b4e512c8eab3aea8dbdd85n/a67.195.204.72:25
2019-09-21 13:01:5814294ffc2fc4bd40af66bb3578d8e417n/a74.125.71.27:25
2019-09-21 13:01:5814294ffc2fc4bd40af66bb3578d8e417n/a98.136.96.76:25

# of entries: 100 (max: 100)