JA3 Fingerprints

You can find further information about the JA3 fingerprint 911479ac8a0813ed1241b3686ccdade9, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:911479ac8a0813ed1241b3686ccdade9
First seen:2018-03-19 23:24:59 UTC
Last seen:2018-12-05 06:15:27 UTC
Status:Blacklisted
Malware samples:42
Destination IPs:60
Malware:Tofsee -
Listing date:2018-11-14 12:39:46

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2018-12-05 06:15:27f0a3e4eca113df7d09bbff6c3678ff27Virustotal results 35/69 (50.72%) 172.217.168.36:443
2018-12-05 06:15:27f0a3e4eca113df7d09bbff6c3678ff27Virustotal results 35/69 (50.72%) 172.217.20.99:443
2018-11-26 08:28:448c2a233173810d4f53df1cc5de624d50Virustotal results 35/70 (50.00%) 74.125.206.104:443
2018-11-26 08:28:438c2a233173810d4f53df1cc5de624d50Virustotal results 35/70 (50.00%) 74.125.206.94:443
2018-11-11 10:31:283159bed9fa80ab6ca9f84f960fbb5af5Virustotal results 20/67 (29.85%) 172.217.16.67:443
2018-11-11 10:31:273159bed9fa80ab6ca9f84f960fbb5af5Virustotal results 20/67 (29.85%) 216.58.215.228:443
2018-10-21 00:41:071fd5cc1d4e9cd89756af71a2c633d7e1Virustotal results 13/67 (19.40%) 216.58.212.164:443
2018-10-21 00:41:041fd5cc1d4e9cd89756af71a2c633d7e1Virustotal results 13/67 (19.40%) 172.217.20.67:443
2018-10-12 02:22:0502340aab7ac9b9305a88ddaec71ce18cVirustotal results 36/69 (52.17%) 216.58.207.67:443
2018-10-12 02:22:0502340aab7ac9b9305a88ddaec71ce18cVirustotal results 36/69 (52.17%) 172.217.18.163:443
2018-10-12 02:22:0502340aab7ac9b9305a88ddaec71ce18cVirustotal results 36/69 (52.17%) 216.58.207.35:443
2018-10-12 02:22:0402340aab7ac9b9305a88ddaec71ce18cVirustotal results 36/69 (52.17%) 216.58.208.36:443
2018-10-06 21:18:5230c8c6dcedc4026aba05bd3c5bfbe735Virustotal results 15/69 (21.74%) 172.217.16.164:443
2018-10-06 21:18:4630c8c6dcedc4026aba05bd3c5bfbe735Virustotal results 15/69 (21.74%) 172.217.22.3:443
2018-10-03 23:13:41a679fc33cd540373f39838d4d6dfdca8Virustotal results 35/69 (50.72%) 74.125.90.100:443
2018-10-03 23:13:34a679fc33cd540373f39838d4d6dfdca8Virustotal results 35/69 (50.72%) 216.58.209.99:443
2018-09-25 22:09:05bedc6c35189f81de5267b375ad149324Virustotal results 33/68 (48.53%) 216.58.212.132:443
2018-09-25 22:09:04bedc6c35189f81de5267b375ad149324Virustotal results 33/68 (48.53%) 216.58.212.131:443
2018-09-20 18:15:11796bb5e276868b24442c1012aa278ea3Virustotal results 37/68 (54.41%) 74.125.193.147:443
2018-09-20 18:15:08796bb5e276868b24442c1012aa278ea3Virustotal results 37/68 (54.41%) 74.125.206.94:443
2018-09-13 00:16:0906d81a8d18d6f05175dfeed32b7a6af1Virustotal results 42/68 (61.76%) 216.58.213.195:443
2018-09-12 16:58:419d053d0bb4530d61ee925c7aa9613b97Virustotal results 41/68 (60.29%) 74.125.193.147:443
2018-09-12 16:58:409d053d0bb4530d61ee925c7aa9613b97Virustotal results 41/68 (60.29%) 74.125.193.94:443
2018-09-08 08:36:42ebd6d9e598b593e72bc70b3eef9379e2Virustotal results 37/68 (54.41%) 74.125.193.99:443
2018-09-08 08:36:36ebd6d9e598b593e72bc70b3eef9379e2Virustotal results 37/68 (54.41%) 74.125.206.94:443
2018-08-31 06:19:478d8565ef2a9c4dcf35cf2308a2a7b9c2Virustotal results 38/67 (56.72%) 216.58.213.196:443
2018-08-31 06:19:388d8565ef2a9c4dcf35cf2308a2a7b9c2Virustotal results 38/67 (56.72%) 216.58.212.131:443
2018-08-21 23:46:5559b2d88d5704527cccbdf1993f6b964cVirustotal results 40/68 (58.82%) 74.125.206.94:443
2018-08-09 10:38:300698b8a5dd53932b8c749f54edea4711Virustotal results 26/68 (38.24%) 74.125.206.94:443
2018-08-06 08:59:00649fc8890551e35ba8d1e38e0cf0088cVirustotal results 42/68 (61.76%) 172.217.18.3:443
2018-08-04 23:26:51d407e629d933030739dfc629142ff8deVirustotal results 35/68 (51.47%) 216.58.198.35:443
2018-07-26 08:16:37a7c2938007e612d13d2cfb16c587929eVirustotal results 41/68 (60.29%) 74.125.206.106:443
2018-07-26 08:16:37a7c2938007e612d13d2cfb16c587929eVirustotal results 41/68 (60.29%) 216.58.211.164:443
2018-07-26 08:16:37a7c2938007e612d13d2cfb16c587929eVirustotal results 41/68 (60.29%) 216.58.211.163:443
2018-07-11 09:35:061f58e92e4a3086ea4e7a108a5399c6c4Virustotal results 47/64 (73.44%) 216.58.205.227:443
2018-06-24 19:33:05b615ff689101509b760415b534294205Virustotal results 13/68 (19.12%) 216.58.208.35:443
2018-06-24 19:33:05b615ff689101509b760415b534294205Virustotal results 13/68 (19.12%) 216.58.205.227:443
2018-06-24 10:50:47dfc2c1eb453fe2eed4597512fc07d307Virustotal results 43/64 (67.19%) 74.125.206.106:443
2018-06-24 10:50:47dfc2c1eb453fe2eed4597512fc07d307Virustotal results 43/64 (67.19%) 74.125.206.94:443
2018-06-18 05:36:31ffa80eac6121446f6f68479db5630f8dVirustotal results 13/68 (19.12%) 216.58.215.228:443
2018-06-18 05:36:31ffa80eac6121446f6f68479db5630f8dVirustotal results 13/68 (19.12%) 172.217.168.68:443
2018-06-18 05:36:31ffa80eac6121446f6f68479db5630f8dVirustotal results 13/68 (19.12%) 172.217.168.35:443
2018-06-18 05:27:13c58ae4f7d153e4d5d14a0996b9935fbcVirustotal results 15/68 (22.06%) 64.233.167.94:443
2018-06-15 17:43:23a31e3a9d03cf2bdfb00a0f537e98fdcfVirustotal results 14/68 (20.59%) 216.58.205.206:443
2018-06-15 17:43:23a31e3a9d03cf2bdfb00a0f537e98fdcfVirustotal results 14/68 (20.59%) 216.58.198.35:443
2018-06-15 11:13:073fd70935da41d9e5ca28977d877d0bc8Virustotal results 37/66 (56.06%) 216.58.198.3:443
2018-06-13 06:20:28106c7b4f0f82ffa17c33e82b33cad573Virustotal results 14/67 (20.90%) 216.58.205.238:443
2018-06-13 06:20:28106c7b4f0f82ffa17c33e82b33cad573Virustotal results 14/67 (20.90%) 216.58.208.35:443
2018-06-09 11:40:0408b5bce1b4510fd3c94d5a5ee1a7716bVirustotal results 36/68 (52.94%) 216.58.205.46:443
2018-06-09 11:40:0408b5bce1b4510fd3c94d5a5ee1a7716bVirustotal results 36/68 (52.94%) 216.58.206.3:443
2018-06-09 11:40:0408b5bce1b4510fd3c94d5a5ee1a7716bVirustotal results 36/68 (52.94%) 216.58.207.78:443
2018-06-09 11:40:0408b5bce1b4510fd3c94d5a5ee1a7716bVirustotal results 36/68 (52.94%) 216.58.198.3:443
2018-05-25 14:18:26e3fbb1c0bcded3ad9f3f29dd85a6e95fVirustotal results 26/66 (39.39%) 209.85.203.100:443
2018-05-25 14:18:26e3fbb1c0bcded3ad9f3f29dd85a6e95fVirustotal results 26/66 (39.39%) 209.85.203.94:443
2018-05-25 12:00:375a4819761ceea110be9ac4c4e997d6f8Virustotal results 40/66 (60.61%) 172.217.22.142:443
2018-05-25 12:00:375a4819761ceea110be9ac4c4e997d6f8Virustotal results 40/66 (60.61%) 216.58.204.99:443
2018-04-17 06:49:39befa52ffe6be7030fd76158fd6452c0dVirustotal results 52/69 (75.36%) 172.217.22.78:443
2018-04-17 06:49:39befa52ffe6be7030fd76158fd6452c0dVirustotal results 52/69 (75.36%) 216.58.206.3:443
2018-04-15 16:40:293291ff1f01b66a09acd89c15d10631eeVirustotal results 53/68 (77.94%) 216.58.198.46:443
2018-04-15 16:40:293291ff1f01b66a09acd89c15d10631eeVirustotal results 53/68 (77.94%) 216.58.198.3:443
2018-04-12 01:52:02b32a55d26693c6c9fa732a84cd50accaVirustotal results 46/67 (68.66%) 216.58.210.227:443
2018-04-11 02:35:00bb42deca695a73372bc2a5cb49608940Virustotal results 13/65 (20.00%) 216.58.213.174:443
2018-04-11 02:35:00bb42deca695a73372bc2a5cb49608940Virustotal results 13/65 (20.00%) 172.217.22.131:443
2018-04-10 19:28:14b4ecb57dd07f9ca72f448edeffdbde0eVirustotal results 34/68 (50.00%) 172.217.22.46:443
2018-04-10 19:28:14b4ecb57dd07f9ca72f448edeffdbde0eVirustotal results 34/68 (50.00%) 172.217.23.131:443
2018-04-10 17:14:30d39dd93679df1c51ee2b64dfb2385a97Virustotal results 28/66 (42.42%) 216.58.198.206:443
2018-04-10 17:14:30d39dd93679df1c51ee2b64dfb2385a97Virustotal results 28/66 (42.42%) 216.58.206.227:443
2018-04-10 10:07:15e06dbe52a1816f36e9c7bca255335ab2Virustotal results 43/67 (64.18%) 172.217.22.46:443
2018-04-10 10:07:15e06dbe52a1816f36e9c7bca255335ab2Virustotal results 43/67 (64.18%) 172.217.23.131:443
2018-04-09 16:53:11bb558ec021e8624fb305cf3e71503b66Virustotal results 39/58 (67.24%) 172.217.18.227:443
2018-04-09 16:53:11bb558ec021e8624fb305cf3e71503b66Virustotal results 39/58 (67.24%) 216.58.210.195:443
2018-04-09 16:53:11bb558ec021e8624fb305cf3e71503b66Virustotal results 39/58 (67.24%) 216.58.210.206:443
2018-04-09 10:16:12ad01d10af1c6ef4809d493074f2fc0a3Virustotal results 44/67 (65.67%) 216.58.206.238:443
2018-04-09 10:16:12ad01d10af1c6ef4809d493074f2fc0a3Virustotal results 44/67 (65.67%) 216.58.204.131:443
2018-03-29 03:35:32def57c78e9f7bf731042ebe57c83eeaeVirustotal results 47/66 (71.21%) 172.217.22.142:443
2018-03-29 03:35:32def57c78e9f7bf731042ebe57c83eeaeVirustotal results 47/66 (71.21%) 216.58.204.99:443
2018-03-27 01:38:55dfe612bfcd5ac1ef7a04ba3f9ce46085Virustotal results 39/58 (67.24%) 172.217.18.238:443
2018-03-27 01:38:55dfe612bfcd5ac1ef7a04ba3f9ce46085Virustotal results 39/58 (67.24%) 216.58.210.195:443
2018-03-20 04:49:47dd785c35d7fb102564f95c53416fc1e8Virustotal results 36/66 (54.55%) 172.217.19.46:443
2018-03-20 04:49:47dd785c35d7fb102564f95c53416fc1e8Virustotal results 36/66 (54.55%) 172.217.19.35:443
2018-03-19 23:24:59d8e100d56993791b159f36c842544adaVirustotal results 43/68 (63.24%) 216.58.204.99:443

# of entries: 81 (max: 100)