JA3 Fingerprints

You can find further information about the JA3 fingerprint 911479ac8a0813ed1241b3686ccdade9, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:911479ac8a0813ed1241b3686ccdade9
First seen:2018-03-19 23:24:59 UTC
Last seen:2019-11-12 10:51:51 UTC
Status:Blacklisted
Malware samples:208
Destination IPs:118
Malware:Tofsee -
Listing date:2018-11-14 12:39:46

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2019-11-12 10:51:518f3cb58e5c4844ba85f4427841972422n/a172.217.20.99:443
2019-11-12 10:51:508f3cb58e5c4844ba85f4427841972422n/a172.217.17.68:443
2019-11-12 10:31:317d7e7add0172726bdd4f4ee8716adafdn/a172.217.23.164:443
2019-11-12 10:31:307d7e7add0172726bdd4f4ee8716adafdn/a216.58.210.3:443
2019-11-12 09:23:38db30b9e49bd6963b1d9d442ebeed2a44n/a172.217.168.67:443
2019-11-12 09:23:38db30b9e49bd6963b1d9d442ebeed2a44n/a172.217.168.36:443
2019-11-12 07:57:040f4b50c8c441f76d66adeebe9644621dn/a172.217.168.67:443
2019-11-11 11:32:51fb71f79fefbc5e75418a9abf30c6f6a5n/a172.217.168.35:443
2019-11-11 11:32:51fb71f79fefbc5e75418a9abf30c6f6a5n/a172.217.168.68:443
2019-11-11 03:23:4203b468ec3fdc708e1ca571d65d05d125n/a172.217.168.35:443
2019-11-11 03:23:4203b468ec3fdc708e1ca571d65d05d125n/a172.217.168.4:443
2019-11-10 02:09:316384575fd6b749ddd0c5cef02bd078e7n/a216.58.213.132:443
2019-11-10 02:09:316384575fd6b749ddd0c5cef02bd078e7n/a172.217.22.131:443
2019-11-10 02:09:306384575fd6b749ddd0c5cef02bd078e7n/a172.217.22.132:443
2019-11-09 11:03:09923938db1aa19b53186a7e0cd1e09b7fn/a172.217.168.3:443
2019-11-09 11:03:09923938db1aa19b53186a7e0cd1e09b7fn/a172.217.168.68:443
2019-11-09 06:42:50ac8a3b535eded94ec514890b179cb873n/a172.217.168.3:443
2019-11-08 09:00:5667f7dcd4782b25fbd9f43b7a84cd8eccVirustotal results 47 / 69 (68.12%) 172.217.168.35:443
2019-11-08 09:00:5667f7dcd4782b25fbd9f43b7a84cd8eccVirustotal results 47 / 69 (68.12%) 216.58.215.228:443
2019-11-07 13:14:29833bf54e58259b697de8e23d91db18f6n/a172.217.168.35:443
2019-11-06 09:24:446ecf7bf73e2ec703990cbe2b2c587d19n/a172.217.168.36:443
2019-11-06 09:24:436ecf7bf73e2ec703990cbe2b2c587d19n/a172.217.168.35:443
2019-11-06 09:11:56e6af3c8f76eac19f2cd024fd7c883dc6n/a172.217.168.35:443
2019-11-06 09:11:55e6af3c8f76eac19f2cd024fd7c883dc6n/a172.217.168.68:443
2019-11-06 09:11:55e6af3c8f76eac19f2cd024fd7c883dc6n/a216.58.215.228:443
2019-11-06 08:34:255c208dda395ef16244576bc7d2db012en/a172.217.17.68:443
2019-11-06 08:34:245c208dda395ef16244576bc7d2db012en/a172.217.168.195:443
2019-11-04 13:06:53de43b36050f9b364adca1ebda6c4ce04n/a172.217.168.35:443
2019-11-04 13:06:53de43b36050f9b364adca1ebda6c4ce04n/a172.217.168.36:443
2019-11-04 13:03:066a3354e2fe701df49a7933c5199f707fn/a216.58.206.228:443
2019-11-04 13:03:036a3354e2fe701df49a7933c5199f707fn/a216.58.198.195:443
2019-11-04 12:57:56a28c8856f9e43439ca17f9daef0b3574n/a216.58.215.228:443
2019-11-04 12:57:56a28c8856f9e43439ca17f9daef0b3574n/a216.58.215.227:443
2019-11-04 12:52:527d3dccea08ec29cd00579161d98058d8n/a172.217.20.99:443
2019-11-04 12:52:527d3dccea08ec29cd00579161d98058d8n/a172.217.168.228:443
2019-11-04 09:53:36e3c5c3e837a1c066a1ed37679005ca29n/a216.58.215.228:443
2019-11-04 09:53:35e3c5c3e837a1c066a1ed37679005ca29n/a172.217.168.35:443
2019-11-03 03:19:13d8dc780a873d5bc30214938e6c23f8b3Virustotal results 45 / 71 (63.38%) 172.217.21.196:443
2019-11-03 03:19:13d8dc780a873d5bc30214938e6c23f8b3Virustotal results 45 / 71 (63.38%) 216.58.208.35:443
2019-11-02 22:20:44c925f3fd01cfae6eb6bb618b47c4e04fVirustotal results 24 / 70 (34.29%) 172.217.168.36:443
2019-11-02 22:20:44c925f3fd01cfae6eb6bb618b47c4e04fVirustotal results 24 / 70 (34.29%) 216.58.215.227:443
2019-11-02 20:42:5371b2071f7e41ee68b228a460b50d4909Virustotal results 39 / 71 (54.93%) 172.217.168.228:443
2019-11-02 20:42:5271b2071f7e41ee68b228a460b50d4909Virustotal results 39 / 71 (54.93%) 172.217.168.195:443
2019-11-01 22:05:357e85c3f64f4a8687dbf659000bb644b2Virustotal results 28 / 72 (38.89%) 172.217.168.68:443
2019-11-01 22:05:337e85c3f64f4a8687dbf659000bb644b2Virustotal results 28 / 72 (38.89%) 172.217.168.35:443
2019-10-31 19:19:2584fda5848f6f527e818657bd4aeac073n/a172.217.168.4:443
2019-10-31 19:19:2584fda5848f6f527e818657bd4aeac073n/a172.217.168.67:443
2019-10-31 19:19:2484fda5848f6f527e818657bd4aeac073n/a216.58.215.228:443
2019-10-28 01:32:29af3b12a3ab7c15e8edb49141ead54adfn/a172.217.168.67:443
2019-10-28 01:23:4326dab55b455a2812908d6ebb298744ecn/a216.58.204.99:443
2019-10-28 01:23:4326dab55b455a2812908d6ebb298744ecn/a216.58.215.36:443
2019-10-27 13:43:5263a147d574d948ba1dd4f045b7129977n/a216.58.215.228:443
2019-10-27 13:43:5263a147d574d948ba1dd4f045b7129977n/a172.217.168.35:443
2019-10-27 13:43:5263a147d574d948ba1dd4f045b7129977n/a172.217.168.68:443
2019-10-27 13:33:25c1491f53c0243155cf32154dbef293d7n/a172.217.168.228:443
2019-10-27 13:33:25c1491f53c0243155cf32154dbef293d7n/a172.217.168.195:443
2019-10-27 13:33:25c1491f53c0243155cf32154dbef293d7n/a172.217.20.99:443
2019-10-25 15:59:33f208047edb1a8d984fe9a15ae10a69dan/a172.217.22.35:443
2019-10-25 15:59:33f208047edb1a8d984fe9a15ae10a69dan/a172.217.16.196:443
2019-10-24 10:17:36332a2fbad2ff0a5c6dcefb58bd505795n/a172.217.168.3:443
2019-10-24 10:17:36332a2fbad2ff0a5c6dcefb58bd505795n/a172.217.168.4:443
2019-10-24 10:15:58826caa117ee3d31a78f15d20ac9244a2n/a172.217.168.68:443
2019-10-24 10:15:58826caa117ee3d31a78f15d20ac9244a2n/a172.217.168.35:443
2019-10-24 09:51:53a364409c87e39ea0d35559b4af5d4fa5Virustotal results 49 / 70 (70.00%) 172.217.168.3:443
2019-10-24 09:47:046094a9cebe9314a2d9e533ce12fc7607n/a172.217.20.99:443
2019-10-24 09:47:046094a9cebe9314a2d9e533ce12fc7607n/a172.217.168.228:443
2019-10-23 08:42:001ed50d83e24da6b3793181b583338904n/a172.217.168.195:443
2019-10-23 08:42:001ed50d83e24da6b3793181b583338904n/a172.217.19.196:443
2019-10-22 12:11:5710199b2c996f3d0f5ec83cf55cdf8437n/a172.217.19.196:443
2019-10-22 12:11:5710199b2c996f3d0f5ec83cf55cdf8437n/a172.217.20.99:443
2019-10-22 04:46:17af5611d77d929a6ddd9dd9e0fe8ac977Virustotal results 30 / 70 (42.86%) 216.58.215.228:443
2019-10-22 04:46:17af5611d77d929a6ddd9dd9e0fe8ac977Virustotal results 30 / 70 (42.86%) 172.217.168.35:443
2019-10-21 13:25:04f7b9af171f214fa94b1f81f9c5752df9n/a216.58.213.131:443
2019-10-21 13:25:04f7b9af171f214fa94b1f81f9c5752df9n/a216.58.209.228:443
2019-10-21 13:25:04f7b9af171f214fa94b1f81f9c5752df9n/a172.217.18.196:443
2019-10-20 12:31:04b793500053053fa92ae3cb92f5f0a28bVirustotal results 37 / 70 (52.86%) 172.217.168.4:443
2019-10-20 12:31:02b793500053053fa92ae3cb92f5f0a28bVirustotal results 37 / 70 (52.86%) 216.58.215.227:443
2019-10-20 12:24:480bf014a571c074ece17a939175b9a444n/a216.58.210.4:443
2019-10-20 12:24:470bf014a571c074ece17a939175b9a444n/a172.217.22.67:443
2019-10-20 00:20:259fab31e3d9ada9608517b2be18e92627n/a216.58.213.131:443
2019-10-20 00:20:259fab31e3d9ada9608517b2be18e92627n/a216.58.204.100:443
2019-10-19 12:27:52e5a0ec4436b1b2e2186b11fcf5e16143Virustotal results 50 / 69 (72.46%) 216.58.215.227:443
2019-10-19 12:27:51e5a0ec4436b1b2e2186b11fcf5e16143Virustotal results 50 / 69 (72.46%) 172.217.168.35:443
2019-10-19 12:27:51e5a0ec4436b1b2e2186b11fcf5e16143Virustotal results 50 / 69 (72.46%) 172.217.168.68:443
2019-10-19 12:03:18ec8ee0b6c36eb4e4d8ad7d4753553cbcVirustotal results 22 / 71 (30.99%) 216.58.204.100:443
2019-10-19 12:03:18ec8ee0b6c36eb4e4d8ad7d4753553cbcVirustotal results 22 / 71 (30.99%) 216.58.204.99:443
2019-10-19 09:02:24ab03cce8dfa7ef39f0e01cc598c50dfbn/a172.217.19.196:443
2019-10-19 09:02:23ab03cce8dfa7ef39f0e01cc598c50dfbn/a172.217.168.195:443
2019-10-19 08:33:3894eb3f553c44422a188576dd05570b05n/a172.217.20.99:443
2019-10-19 08:33:3894eb3f553c44422a188576dd05570b05n/a172.217.168.228:443
2019-10-18 10:56:18e916853e0fa051a17aafeb74ae35bedbn/a172.217.168.35:443
2019-10-18 10:56:16e916853e0fa051a17aafeb74ae35bedbn/a216.58.215.228:443
2019-10-18 10:53:31e08523fa74d33cc020d77182ca3a401en/a172.217.168.196:443
2019-10-18 10:53:31e08523fa74d33cc020d77182ca3a401en/a172.217.17.67:443
2019-10-18 10:52:544d202cc1f414550ec4f06dadf3c73baan/a172.217.18.100:443
2019-10-18 10:52:544d202cc1f414550ec4f06dadf3c73baan/a172.217.22.99:443
2019-10-18 10:51:234304b3ffd3f1668f8a99d6806f6e9367n/a172.217.168.196:443
2019-10-18 10:51:234304b3ffd3f1668f8a99d6806f6e9367n/a172.217.17.35:443
2019-10-16 23:03:1704bf6236f4168171c86fbeef62258e80n/a172.217.20.99:443
2019-10-16 23:03:1504bf6236f4168171c86fbeef62258e80n/a172.217.168.228:443

# of entries: 100 (max: 100)