JA3 Fingerprints

You can find further information about the JA3 fingerprint 9f62c4f26b90d3d757bea609e82f2eaf, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:9f62c4f26b90d3d757bea609e82f2eaf
First seen:2018-03-13 06:23:41 UTC
Last seen:2019-01-14 14:36:26 UTC
Status:Blacklisted
Malware samples:412
Destination IPs:108
Malware:Tofsee -
Listing date:2018-11-14 00:00:00

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2019-01-14 14:36:2647d980700322d3005dbfafeebc9e41feVirustotal results 34/70 (48.57%) 173.194.69.94:443
2018-12-11 15:36:300ddb54791d2232498e2b25ed65484c89Virustotal results 24/70 (34.29%) 172.217.20.99:443
2018-12-10 23:44:03dac816d1c7b4ac33bc491a2c26ef83c2n/a172.217.168.228:443
2018-12-09 00:59:4399baca5d78a6427843dba64a5fc0c083Virustotal results 39/71 (54.93%) 172.217.168.227:443
2018-12-05 06:15:27f0a3e4eca113df7d09bbff6c3678ff27Virustotal results 35/69 (50.72%) 216.58.209.227:443
2018-12-05 06:15:27f0a3e4eca113df7d09bbff6c3678ff27Virustotal results 35/69 (50.72%) 216.58.205.4:443
2018-12-03 10:27:382859f008ada0a06ef6a1f635730c35f1Virustotal results 37/70 (52.86%) 216.58.209.227:443
2018-11-30 04:59:53f103fceb4d81aa1ff904dcd8a28fcc04Virustotal results 34/68 (50.00%) 216.58.208.195:443
2018-11-30 04:59:53f103fceb4d81aa1ff904dcd8a28fcc04Virustotal results 34/68 (50.00%) 216.58.204.132:443
2018-11-29 20:46:04020b08c9f4ece0ca858b702b57b5b6eeVirustotal results 37/69 (53.62%) 172.217.18.196:443
2018-11-29 13:40:24ebbc767e8d1540a8614e05da97a398f7Virustotal results 33/70 (47.14%) 172.217.18.196:443
2018-11-23 14:10:55ece47340d919cbe7e059016cf52127ecVirustotal results 35/66 (53.03%) 216.58.204.99:443
2018-11-23 04:28:05162c6f6b1e73f0733e3a932d8b07dc2eVirustotal results 37/68 (54.41%) 172.217.19.228:443
2018-11-20 05:30:27be5155baf905961fbff0caf07902ce62Virustotal results 27/66 (40.91%) 216.58.213.131:443
2018-11-18 19:19:38bc95c3f699cea00f31cc288e669d9bd3Virustotal results 18/67 (26.87%) 172.217.19.228:443
2018-11-17 05:17:221eeae4203ca29b93116321481964bafeVirustotal results 28/68 (41.18%) 216.58.209.227:443
2018-11-14 04:38:22d867341d9d23eb614a4c266d70405f40Virustotal results 33/68 (48.53%) 216.58.208.228:443
2018-11-11 10:31:303159bed9fa80ab6ca9f84f960fbb5af5Virustotal results 20/67 (29.85%) 216.58.204.100:443
2018-11-08 13:47:40284d85486387649bbf48e5dfa9aec8b0Virustotal results 37/67 (55.22%) 216.58.201.228:443
2018-11-08 13:47:39284d85486387649bbf48e5dfa9aec8b0Virustotal results 37/67 (55.22%) 216.58.205.3:443
2018-11-08 00:20:28488771b31d7e237c4db5233da7d51768Virustotal results 33/68 (48.53%) 108.177.127.104:443
2018-11-08 00:20:24488771b31d7e237c4db5233da7d51768Virustotal results 33/68 (48.53%) 216.58.205.3:443
2018-11-03 17:13:37a29cd5d99141ceeb10e7c4ef4f41668bVirustotal results 31/67 (46.27%) 172.217.22.131:443
2018-11-03 12:33:5685993c66a193d6d8d3b8d79d9a95dd0cVirustotal results 35/68 (51.47%) 172.217.18.196:443
2018-10-21 00:41:081fd5cc1d4e9cd89756af71a2c633d7e1Virustotal results 13/67 (19.40%) 216.58.206.68:443
2018-10-17 18:03:00dc60735ad158c5d4dce7a104a0b9696dVirustotal results 45/67 (67.16%) 172.217.23.3:443
2018-10-16 12:12:4373a64357b0e9883add0c6aec3ef440edVirustotal results 14/68 (20.59%) 216.58.201.35:443
2018-10-15 22:30:23bd9639044643025556c8fbd6271fe5e5Virustotal results 27/67 (40.30%) 216.58.201.35:443
2018-10-15 06:28:015f783acdf0e680cb05df27c9101090ean/a216.58.201.35:443
2018-10-15 06:28:005f783acdf0e680cb05df27c9101090ean/a216.58.214.4:443
2018-10-15 06:27:575f783acdf0e680cb05df27c9101090ean/a216.58.210.35:443
2018-10-14 19:55:48b9a775c3da28cd0006378f0ca253211fVirustotal results 16/68 (23.53%) 216.58.210.36:443
2018-10-14 10:35:55da4a56f9db3ccef32e88ad2e5c616a1aVirustotal results 18/67 (26.87%) 216.58.201.36:443
2018-09-18 00:29:11354d64aadc25bb7899922a5dfee32643Virustotal results 36/68 (52.94%) 216.58.213.228:443
2018-09-18 00:29:01354d64aadc25bb7899922a5dfee32643Virustotal results 36/68 (52.94%) 172.217.16.67:443
2018-09-16 06:13:566510fd8ff7d4a666410c67c565b0b6ebVirustotal results 38/68 (55.88%) 172.217.16.67:443
2018-09-13 14:23:548401f2510cb4991370a4512068f77870Virustotal results 40/68 (58.82%) 172.217.16.67:443
2018-09-13 14:23:538401f2510cb4991370a4512068f77870Virustotal results 40/68 (58.82%) 172.217.19.68:443
2018-09-13 00:16:2906d81a8d18d6f05175dfeed32b7a6af1Virustotal results 42/68 (61.76%) 172.217.16.67:443
2018-09-12 15:48:16bc7a3c5657467dad62c314d63cc2ae99Virustotal results 37/68 (54.41%) 172.217.21.35:443
2018-09-08 08:36:44ebd6d9e598b593e72bc70b3eef9379e2Virustotal results 37/68 (54.41%) 172.217.22.227:443
2018-09-08 08:36:34ebd6d9e598b593e72bc70b3eef9379e2Virustotal results 37/68 (54.41%) 172.217.21.4:443
2018-09-07 22:22:08e69649ff2b811dfdce5ba9d42f500cf4Virustotal results 39/68 (57.35%) 172.217.22.228:443
2018-09-03 15:44:09f042cf528243c35922e4e5eeaf60e03dVirustotal results 40/68 (58.82%) 172.217.21.99:443
2018-09-02 07:19:40f0f80754de8de70676d06ad03beb2b4bVirustotal results 41/68 (60.29%) 172.217.21.3:443
2018-09-02 06:53:12e9077f398aac1ea2261c0d1114a0fc06Virustotal results 29/68 (42.65%) 216.58.207.132:443
2018-09-02 06:53:08e9077f398aac1ea2261c0d1114a0fc06Virustotal results 29/68 (42.65%) 172.217.17.228:443
2018-09-02 06:53:06e9077f398aac1ea2261c0d1114a0fc06Virustotal results 29/68 (42.65%) 172.217.21.3:443
2018-08-31 06:19:378d8565ef2a9c4dcf35cf2308a2a7b9c2Virustotal results 38/67 (56.72%) 172.217.17.227:443
2018-08-30 23:44:32eb46194457d0cbe8b70979d8b7adaee0Virustotal results 40/68 (58.82%) 216.58.201.100:443
2018-08-30 20:07:08cfe5ff15b6f6a375ab796edb90dc17e5Virustotal results 20/67 (29.85%) 172.217.23.227:443
2018-08-30 20:07:07cfe5ff15b6f6a375ab796edb90dc17e5Virustotal results 20/67 (29.85%) 172.217.17.227:443
2018-08-30 19:17:30e25471edb3d5380d30769478b5736d3eVirustotal results 39/67 (58.21%) 216.58.201.100:443
2018-08-30 19:17:29e25471edb3d5380d30769478b5736d3eVirustotal results 39/67 (58.21%) 172.217.23.227:443
2018-08-29 13:43:170523f161aee22fcac58a16d478aeb305Virustotal results 42/67 (62.69%) 172.217.23.196:443
2018-08-27 23:22:33bc346d0e973fedec461f0c4db651df12Virustotal results 36/67 (53.73%) 172.217.23.227:443
2018-08-26 20:06:05d21f1bff8d6ade12305e25511a2f1f1eVirustotal results 34/66 (51.52%) 172.217.23.227:443
2018-08-26 03:25:28104b66e2ff9ccd28ef2e0590b7b046a4Virustotal results 36/68 (52.94%) 172.217.23.227:443
2018-08-25 20:12:224f71903d3ed000d661988c05245725dfVirustotal results 20/67 (29.85%) 172.217.23.227:443
2018-08-24 15:14:288820060303e2fdcfe558f54cc298a039Virustotal results 38/68 (55.88%) 172.217.23.227:443
2018-08-22 06:04:48654fe47faa6909830c3d7d79c1001e30Virustotal results 42/68 (61.76%) 172.217.23.227:443
2018-08-21 23:46:5559b2d88d5704527cccbdf1993f6b964cVirustotal results 40/68 (58.82%) 172.217.23.227:443
2018-08-21 23:46:5559b2d88d5704527cccbdf1993f6b964cVirustotal results 40/68 (58.82%) 216.58.201.100:443
2018-08-17 06:35:3071ef8a5f0aa3b2d9c514e4b7f1e3e5c1Virustotal results 18/68 (26.47%) 172.217.23.228:443
2018-08-15 04:37:251149ff3d2997bbd5bbd00def2c1929c6Virustotal results 38/68 (55.88%) 172.217.23.196:443
2018-08-15 00:47:42e34fe65dfc76446e220adefca067a130Virustotal results 30/67 (44.78%) 216.58.201.100:443
2018-08-15 00:47:42e34fe65dfc76446e220adefca067a130Virustotal results 30/67 (44.78%) 172.217.23.227:443
2018-08-09 10:38:300698b8a5dd53932b8c749f54edea4711Virustotal results 26/68 (38.24%) 216.58.201.100:443
2018-08-09 10:38:300698b8a5dd53932b8c749f54edea4711Virustotal results 26/68 (38.24%) 172.217.23.227:443
2018-08-07 19:53:365aa41bee21e519b59ef6654fffdcd83cVirustotal results 36/68 (52.94%) 216.58.201.100:443
2018-08-06 08:59:00649fc8890551e35ba8d1e38e0cf0088cVirustotal results 42/68 (61.76%) 216.58.201.100:443
2018-08-04 23:26:51d407e629d933030739dfc629142ff8deVirustotal results 35/68 (51.47%) 172.217.23.227:443
2018-08-04 23:26:51d407e629d933030739dfc629142ff8deVirustotal results 35/68 (51.47%) 216.58.201.100:443
2018-08-04 20:10:201c3fca8e3015013020f4bbc131e55c83Virustotal results 41/68 (60.29%) 172.217.23.227:443
2018-08-03 00:45:287a74d80ac6b4cec14a43dbd9434cf37eVirustotal results 37/67 (55.22%) 216.58.201.100:443
2018-08-01 11:13:037bc29ec429894305af39db1655f21bebVirustotal results 25/68 (36.76%) 172.217.23.227:443
2018-08-01 11:13:037bc29ec429894305af39db1655f21bebVirustotal results 25/68 (36.76%) 216.58.201.100:443
2018-07-31 12:37:51ca81e461a2def19fdf3f3801019635f7Virustotal results 40/68 (58.82%) 172.217.23.227:443
2018-07-31 12:37:51ca81e461a2def19fdf3f3801019635f7Virustotal results 40/68 (58.82%) 216.58.201.100:443
2018-07-29 10:13:12260233e99f6c8d4df7260ac1ff33f023Virustotal results 37/68 (54.41%) 172.217.23.227:443
2018-07-29 10:13:12260233e99f6c8d4df7260ac1ff33f023Virustotal results 37/68 (54.41%) 216.58.201.100:443
2018-07-29 09:02:49b0e660a771ff4d8610fdab236e48ba7aVirustotal results 43/67 (64.18%) 216.58.201.100:443
2018-07-29 09:02:49b0e660a771ff4d8610fdab236e48ba7aVirustotal results 43/67 (64.18%) 172.217.23.227:443
2018-07-29 07:38:1327c67a7d1b63da485ed0657fe471a47aVirustotal results 17/68 (25.00%) 216.58.201.100:443
2018-07-28 01:26:023c5fbdb5a263876d9482d1c4adc5d204Virustotal results 12/68 (17.65%) 216.58.201.100:443
2018-07-28 01:16:004e54ffa4c784f8ede408e2b9a62d777eVirustotal results 41/68 (60.29%) 216.58.201.100:443
2018-07-28 01:16:004e54ffa4c784f8ede408e2b9a62d777eVirustotal results 41/68 (60.29%) 172.217.23.227:443
2018-07-27 17:36:11aac07176d713985cdcacf633439827c3Virustotal results 36/68 (52.94%) 216.58.201.100:443
2018-07-26 16:31:53484aa1f03c28f2ea90e05e605d16e1abVirustotal results 25/55 (45.45%) 216.58.201.100:443
2018-07-26 08:16:37a7c2938007e612d13d2cfb16c587929eVirustotal results 41/68 (60.29%) 216.58.201.100:443
2018-07-25 08:16:36068e6e8296236bebf99600db12b790c0Virustotal results 42/68 (61.76%) 216.58.201.100:443
2018-07-22 13:34:02daa2add7dab260c50a0d16649b090a6dVirustotal results 34/68 (50.00%) 216.58.201.99:443
2018-07-21 02:22:2015c3c95d4c6765750646e458a9e30df7Virustotal results 29/68 (42.65%) 216.58.201.99:443
2018-07-20 20:18:073f46fb3a6e9e307c90325f3dcab161f9Virustotal results 27/68 (39.71%) 172.217.23.228:443
2018-07-20 20:18:073f46fb3a6e9e307c90325f3dcab161f9Virustotal results 27/68 (39.71%) 216.58.201.99:443
2018-07-20 16:37:4655a97c31945e1fb2c9d1d2f2beb8d975Virustotal results 41/67 (61.19%) 216.58.201.99:443
2018-07-20 16:37:4655a97c31945e1fb2c9d1d2f2beb8d975Virustotal results 41/67 (61.19%) 172.217.23.227:443
2018-07-19 13:53:418dabb336e7b87f33b1e25050044b34d7Virustotal results 42/67 (62.69%) 172.217.23.227:443
2018-07-19 13:53:418dabb336e7b87f33b1e25050044b34d7Virustotal results 42/67 (62.69%) 172.217.23.228:443
2018-07-19 13:53:418dabb336e7b87f33b1e25050044b34d7Virustotal results 42/67 (62.69%) 172.217.23.196:443

# of entries: 100 (max: 100)