JA3 Fingerprints

You can find further information about the JA3 fingerprint 9f62c4f26b90d3d757bea609e82f2eaf, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:9f62c4f26b90d3d757bea609e82f2eaf
First seen:2018-03-13 06:23:41 UTC
Last seen:2019-05-14 01:23:20 UTC
Status:Blacklisted
Malware samples:439
Destination IPs:117
Malware:Tofsee -
Listing date:2018-11-14 00:00:00

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2019-05-14 01:23:20e9137b0752e8b99dd1c90e49e2a90d1dn/a172.217.16.35:443
2019-05-11 23:17:41dac2bc3481a7b0b7740fb59dfd0caf5bn/a172.217.16.36:443
2019-05-11 05:53:10db3e2a66ee697352936983220504c72bn/a216.58.215.99:443
2019-05-11 05:53:10db3e2a66ee697352936983220504c72bn/a172.217.16.36:443
2019-05-09 09:14:006f9ee02afa7b8942daebd4d0d516ee57n/a172.217.16.36:443
2019-05-09 09:13:596f9ee02afa7b8942daebd4d0d516ee57n/a216.58.215.99:443
2019-04-27 13:18:5304189c076555294cb7bf7968927b5444n/a172.217.20.99:443
2019-04-25 06:47:592f5baa0f0b3d24c792ad901ebcaf9181Virustotal results 19/67 (28.36%) 172.217.168.228:443
2019-04-25 05:51:33536eb0fcbd82a4ae171ab3ef9c519a70Virustotal results 20/67 (29.85%) 172.217.17.36:443
2019-04-22 15:35:470a56cd95d117876de53abccd3f7966abn/a216.58.215.227:443
2019-04-22 15:35:460a56cd95d117876de53abccd3f7966abn/a172.217.168.67:443
2019-04-20 05:05:19385622c40b99b7dfbcad474a75ffc200n/a172.217.168.35:443
2019-04-18 17:39:39c2a36fb57f1f2c955dfd8f39b64d592fn/a172.217.168.68:443
2019-04-17 11:42:1061138763d767a244bdd401ab133cc68cn/a172.217.168.36:443
2019-04-15 16:07:48ca40674eeaa5daba6c5da021c954e3a2n/a172.217.168.3:443
2019-04-15 16:07:48ca40674eeaa5daba6c5da021c954e3a2n/a172.217.168.68:443
2019-04-15 00:09:282c771d9f779225a0fcf288d9e2adbbf8Virustotal results 24/70 (34.29%) 172.217.168.36:443
2019-04-14 14:30:4238d45c3da0d13826466e73a6713af23bn/a216.58.215.227:443
2019-04-13 07:11:29dc01b7fce9a08332ab428b4e9970276cn/a172.217.168.67:443
2019-04-12 12:05:12cc89735d61ea4bdb9eef360dd8825dban/a172.217.168.36:443
2019-04-12 08:57:42d119a419ff4cb26e4faef25eb8bbc190Virustotal results 19/72 (26.39%) 172.217.168.67:443
2019-04-11 04:54:48f1c4d05c8c0764c2267b56d9f7d33b25n/a172.217.168.35:443
2019-04-09 19:22:5635673840cff39a3ee467f98297198dd4n/a172.217.168.36:443
2019-04-07 10:58:42dfd2884b93775c662c3a057487f3da27Virustotal results 35/68 (51.47%) 172.217.168.36:443
2019-04-04 17:11:01f6ff62266948c8a9516f4c49d6421a52n/a172.217.168.35:443
2019-04-03 23:05:57010fda264262943eff357af31f3499a3Virustotal results 20/66 (30.30%) 172.217.168.36:443
2019-04-03 10:54:19a533ced14733741ef560d78619d26806n/a172.217.168.67:443
2019-04-03 09:24:477e8f9bfbe01acf6196bb16fd4cdb3413Virustotal results 27/68 (39.71%) 172.217.168.36:443
2019-04-03 06:34:300fba4b08cce1ba318e281253d25fcb8eVirustotal results 44/67 (65.67%) 216.58.215.227:443
2019-03-30 13:16:0632af06c16db062c54d91523b9373266eVirustotal results 44/65 (67.69%) 172.217.168.68:443
2019-02-01 06:05:00bf48ca1801b7e61f545ffee07ff44f68Virustotal results 41/71 (57.75%) 108.177.127.94:443
2019-01-14 14:36:2647d980700322d3005dbfafeebc9e41feVirustotal results 34/70 (48.57%) 173.194.69.94:443
2018-12-11 15:36:300ddb54791d2232498e2b25ed65484c89Virustotal results 24/70 (34.29%) 172.217.20.99:443
2018-12-10 23:44:03dac816d1c7b4ac33bc491a2c26ef83c2n/a172.217.168.228:443
2018-12-09 00:59:4399baca5d78a6427843dba64a5fc0c083Virustotal results 39/71 (54.93%) 172.217.168.227:443
2018-12-05 06:15:27f0a3e4eca113df7d09bbff6c3678ff27Virustotal results 35/69 (50.72%) 216.58.209.227:443
2018-12-05 06:15:27f0a3e4eca113df7d09bbff6c3678ff27Virustotal results 35/69 (50.72%) 216.58.205.4:443
2018-12-03 10:27:382859f008ada0a06ef6a1f635730c35f1Virustotal results 37/70 (52.86%) 216.58.209.227:443
2018-11-30 04:59:53f103fceb4d81aa1ff904dcd8a28fcc04Virustotal results 34/68 (50.00%) 216.58.208.195:443
2018-11-30 04:59:53f103fceb4d81aa1ff904dcd8a28fcc04Virustotal results 34/68 (50.00%) 216.58.204.132:443
2018-11-29 20:46:04020b08c9f4ece0ca858b702b57b5b6eeVirustotal results 37/69 (53.62%) 172.217.18.196:443
2018-11-29 13:40:24ebbc767e8d1540a8614e05da97a398f7Virustotal results 33/70 (47.14%) 172.217.18.196:443
2018-11-23 14:10:55ece47340d919cbe7e059016cf52127ecVirustotal results 35/66 (53.03%) 216.58.204.99:443
2018-11-23 04:28:05162c6f6b1e73f0733e3a932d8b07dc2eVirustotal results 37/68 (54.41%) 172.217.19.228:443
2018-11-20 05:30:27be5155baf905961fbff0caf07902ce62Virustotal results 27/66 (40.91%) 216.58.213.131:443
2018-11-18 19:19:38bc95c3f699cea00f31cc288e669d9bd3Virustotal results 18/67 (26.87%) 172.217.19.228:443
2018-11-17 05:17:221eeae4203ca29b93116321481964bafeVirustotal results 28/68 (41.18%) 216.58.209.227:443
2018-11-14 04:38:22d867341d9d23eb614a4c266d70405f40Virustotal results 33/68 (48.53%) 216.58.208.228:443
2018-11-11 10:31:303159bed9fa80ab6ca9f84f960fbb5af5Virustotal results 20/67 (29.85%) 216.58.204.100:443
2018-11-08 13:47:40284d85486387649bbf48e5dfa9aec8b0Virustotal results 37/67 (55.22%) 216.58.201.228:443
2018-11-08 13:47:39284d85486387649bbf48e5dfa9aec8b0Virustotal results 37/67 (55.22%) 216.58.205.3:443
2018-11-08 00:20:28488771b31d7e237c4db5233da7d51768Virustotal results 33/68 (48.53%) 108.177.127.104:443
2018-11-08 00:20:24488771b31d7e237c4db5233da7d51768Virustotal results 33/68 (48.53%) 216.58.205.3:443
2018-11-03 17:13:37a29cd5d99141ceeb10e7c4ef4f41668bVirustotal results 31/67 (46.27%) 172.217.22.131:443
2018-11-03 12:33:5685993c66a193d6d8d3b8d79d9a95dd0cVirustotal results 35/68 (51.47%) 172.217.18.196:443
2018-10-21 00:41:081fd5cc1d4e9cd89756af71a2c633d7e1Virustotal results 13/67 (19.40%) 216.58.206.68:443
2018-10-17 18:03:00dc60735ad158c5d4dce7a104a0b9696dVirustotal results 45/67 (67.16%) 172.217.23.3:443
2018-10-16 12:12:4373a64357b0e9883add0c6aec3ef440edVirustotal results 14/68 (20.59%) 216.58.201.35:443
2018-10-15 22:30:23bd9639044643025556c8fbd6271fe5e5Virustotal results 27/67 (40.30%) 216.58.201.35:443
2018-10-15 06:28:015f783acdf0e680cb05df27c9101090ean/a216.58.201.35:443
2018-10-15 06:28:005f783acdf0e680cb05df27c9101090ean/a216.58.214.4:443
2018-10-15 06:27:575f783acdf0e680cb05df27c9101090ean/a216.58.210.35:443
2018-10-14 19:55:48b9a775c3da28cd0006378f0ca253211fVirustotal results 16/68 (23.53%) 216.58.210.36:443
2018-10-14 10:35:55da4a56f9db3ccef32e88ad2e5c616a1aVirustotal results 18/67 (26.87%) 216.58.201.36:443
2018-09-18 00:29:11354d64aadc25bb7899922a5dfee32643Virustotal results 36/68 (52.94%) 216.58.213.228:443
2018-09-18 00:29:01354d64aadc25bb7899922a5dfee32643Virustotal results 36/68 (52.94%) 172.217.16.67:443
2018-09-16 06:13:566510fd8ff7d4a666410c67c565b0b6ebVirustotal results 38/68 (55.88%) 172.217.16.67:443
2018-09-13 14:23:548401f2510cb4991370a4512068f77870Virustotal results 40/68 (58.82%) 172.217.16.67:443
2018-09-13 14:23:538401f2510cb4991370a4512068f77870Virustotal results 40/68 (58.82%) 172.217.19.68:443
2018-09-13 00:16:2906d81a8d18d6f05175dfeed32b7a6af1Virustotal results 42/68 (61.76%) 172.217.16.67:443
2018-09-12 15:48:16bc7a3c5657467dad62c314d63cc2ae99Virustotal results 37/68 (54.41%) 172.217.21.35:443
2018-09-08 08:36:44ebd6d9e598b593e72bc70b3eef9379e2Virustotal results 37/68 (54.41%) 172.217.22.227:443
2018-09-08 08:36:34ebd6d9e598b593e72bc70b3eef9379e2Virustotal results 37/68 (54.41%) 172.217.21.4:443
2018-09-07 22:22:08e69649ff2b811dfdce5ba9d42f500cf4Virustotal results 39/68 (57.35%) 172.217.22.228:443
2018-09-03 15:44:09f042cf528243c35922e4e5eeaf60e03dVirustotal results 40/68 (58.82%) 172.217.21.99:443
2018-09-02 07:19:40f0f80754de8de70676d06ad03beb2b4bVirustotal results 41/68 (60.29%) 172.217.21.3:443
2018-09-02 06:53:12e9077f398aac1ea2261c0d1114a0fc06Virustotal results 29/68 (42.65%) 216.58.207.132:443
2018-09-02 06:53:08e9077f398aac1ea2261c0d1114a0fc06Virustotal results 29/68 (42.65%) 172.217.17.228:443
2018-09-02 06:53:06e9077f398aac1ea2261c0d1114a0fc06Virustotal results 29/68 (42.65%) 172.217.21.3:443
2018-08-31 06:19:378d8565ef2a9c4dcf35cf2308a2a7b9c2Virustotal results 38/67 (56.72%) 172.217.17.227:443
2018-08-30 23:44:32eb46194457d0cbe8b70979d8b7adaee0Virustotal results 40/68 (58.82%) 216.58.201.100:443
2018-08-30 20:07:08cfe5ff15b6f6a375ab796edb90dc17e5Virustotal results 20/67 (29.85%) 172.217.23.227:443
2018-08-30 20:07:07cfe5ff15b6f6a375ab796edb90dc17e5Virustotal results 20/67 (29.85%) 172.217.17.227:443
2018-08-30 19:17:30e25471edb3d5380d30769478b5736d3eVirustotal results 39/67 (58.21%) 216.58.201.100:443
2018-08-30 19:17:29e25471edb3d5380d30769478b5736d3eVirustotal results 39/67 (58.21%) 172.217.23.227:443
2018-08-29 13:43:170523f161aee22fcac58a16d478aeb305Virustotal results 42/67 (62.69%) 172.217.23.196:443
2018-08-27 23:22:33bc346d0e973fedec461f0c4db651df12Virustotal results 36/67 (53.73%) 172.217.23.227:443
2018-08-26 20:06:05d21f1bff8d6ade12305e25511a2f1f1eVirustotal results 34/66 (51.52%) 172.217.23.227:443
2018-08-26 03:25:28104b66e2ff9ccd28ef2e0590b7b046a4Virustotal results 36/68 (52.94%) 172.217.23.227:443
2018-08-25 20:12:224f71903d3ed000d661988c05245725dfVirustotal results 20/67 (29.85%) 172.217.23.227:443
2018-08-24 15:14:288820060303e2fdcfe558f54cc298a039Virustotal results 38/68 (55.88%) 172.217.23.227:443
2018-08-22 06:04:48654fe47faa6909830c3d7d79c1001e30Virustotal results 42/68 (61.76%) 172.217.23.227:443
2018-08-21 23:46:5559b2d88d5704527cccbdf1993f6b964cVirustotal results 40/68 (58.82%) 172.217.23.227:443
2018-08-21 23:46:5559b2d88d5704527cccbdf1993f6b964cVirustotal results 40/68 (58.82%) 216.58.201.100:443
2018-08-17 06:35:3071ef8a5f0aa3b2d9c514e4b7f1e3e5c1Virustotal results 18/68 (26.47%) 172.217.23.228:443
2018-08-15 04:37:251149ff3d2997bbd5bbd00def2c1929c6Virustotal results 38/68 (55.88%) 172.217.23.196:443
2018-08-15 00:47:42e34fe65dfc76446e220adefca067a130Virustotal results 30/67 (44.78%) 216.58.201.100:443
2018-08-15 00:47:42e34fe65dfc76446e220adefca067a130Virustotal results 30/67 (44.78%) 172.217.23.227:443
2018-08-09 10:38:300698b8a5dd53932b8c749f54edea4711Virustotal results 26/68 (38.24%) 216.58.201.100:443
2018-08-09 10:38:300698b8a5dd53932b8c749f54edea4711Virustotal results 26/68 (38.24%) 172.217.23.227:443

# of entries: 100 (max: 100)