JA3 Fingerprints

You can find further information about the JA3 fingerprint b90bdbe961a648f0427db21aaa6ccb59, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:b90bdbe961a648f0427db21aaa6ccb59
First seen:2018-03-11 10:37:43 UTC
Last seen:2019-01-20 14:31:39 UTC
Status:Blacklisted
Malware samples:463
Destination IPs:265
Malware:Tofsee -
Listing date:2018-11-14 00:00:00

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2019-01-20 14:31:399e6df0e4d260e0e5bf7f23c150e82a4bVirustotal results 34/71 (47.89%) 216.58.201.227:443
2019-01-13 11:15:379de56070017d8a3f08d96259d3dbc4e9Virustotal results 36/71 (50.70%) 77.88.55.66:443
2019-01-13 11:15:379de56070017d8a3f08d96259d3dbc4e9Virustotal results 36/71 (50.70%) 216.58.211.131:443
2019-01-13 11:15:369de56070017d8a3f08d96259d3dbc4e9Virustotal results 36/71 (50.70%) 216.58.211.132:443
2019-01-05 19:56:33a26dd9ab29f62033ad37ebc874a20a7cn/a216.58.207.196:443
2019-01-05 19:56:33a26dd9ab29f62033ad37ebc874a20a7cn/a216.58.209.131:443
2018-12-28 01:43:12117f62878ac1929ddd9526463de87b72n/a172.217.17.99:443
2018-12-28 01:43:12117f62878ac1929ddd9526463de87b72n/a172.217.168.228:443
2018-12-24 22:19:08424f7b8edf5d150c7a248ad789512bc4Virustotal results 39/69 (56.52%) 216.58.209.131:443
2018-12-24 22:19:08424f7b8edf5d150c7a248ad789512bc4Virustotal results 39/69 (56.52%) 216.58.207.196:443
2018-12-24 22:19:08424f7b8edf5d150c7a248ad789512bc4Virustotal results 39/69 (56.52%) 172.217.22.163:443
2018-12-19 20:54:5861f4fa70b33c54bb2e9e049359c3a03en/a172.217.19.227:443
2018-12-16 20:17:5678c050980246f58ecc5dfc373d81c6f8Virustotal results 37/71 (52.11%) 172.217.16.3:443
2018-12-16 20:17:5678c050980246f58ecc5dfc373d81c6f8Virustotal results 37/71 (52.11%) 172.217.20.195:443
2018-12-16 20:17:5678c050980246f58ecc5dfc373d81c6f8Virustotal results 37/71 (52.11%) 172.217.20.163:443
2018-12-16 20:17:5678c050980246f58ecc5dfc373d81c6f8Virustotal results 37/71 (52.11%) 172.217.16.4:443
2018-12-16 20:17:5678c050980246f58ecc5dfc373d81c6f8Virustotal results 37/71 (52.11%) 216.58.215.68:443
2018-12-15 23:29:4806ab498eb864a937fc7f0ea4908e0731Virustotal results 37/71 (52.11%) 216.58.211.99:443
2018-12-15 23:29:4806ab498eb864a937fc7f0ea4908e0731Virustotal results 37/71 (52.11%) 172.217.17.131:443
2018-12-15 23:29:4806ab498eb864a937fc7f0ea4908e0731Virustotal results 37/71 (52.11%) 172.217.19.195:443
2018-12-15 23:29:4806ab498eb864a937fc7f0ea4908e0731Virustotal results 37/71 (52.11%) 216.58.211.100:443
2018-12-11 15:36:300ddb54791d2232498e2b25ed65484c89Virustotal results 24/70 (34.29%) 172.217.16.4:443
2018-12-11 15:36:300ddb54791d2232498e2b25ed65484c89Virustotal results 24/70 (34.29%) 216.58.215.99:443
2018-12-10 23:44:03dac816d1c7b4ac33bc491a2c26ef83c2n/a216.58.209.131:443
2018-12-09 00:59:4399baca5d78a6427843dba64a5fc0c083Virustotal results 39/71 (54.93%) 216.58.215.99:443
2018-12-09 00:59:4399baca5d78a6427843dba64a5fc0c083Virustotal results 39/71 (54.93%) 172.217.16.3:443
2018-12-09 00:59:4399baca5d78a6427843dba64a5fc0c083Virustotal results 39/71 (54.93%) 172.217.16.4:443
2018-12-09 00:59:4399baca5d78a6427843dba64a5fc0c083Virustotal results 39/71 (54.93%) 216.58.215.100:443
2018-12-08 11:55:1754aaa042e75d20b5b9b22763639024b8Virustotal results 39/70 (55.71%) 172.217.20.100:443
2018-12-08 11:55:1754aaa042e75d20b5b9b22763639024b8Virustotal results 39/70 (55.71%) 216.58.211.99:443
2018-12-08 11:55:1654aaa042e75d20b5b9b22763639024b8Virustotal results 39/70 (55.71%) 108.177.15.94:443
2018-12-05 07:04:196a9c5dea5eed27a993cd13041c567fe2Virustotal results 39/70 (55.71%) 108.177.98.94:443
2018-12-05 06:15:27f0a3e4eca113df7d09bbff6c3678ff27Virustotal results 35/69 (50.72%) 172.217.168.36:443
2018-12-05 06:15:27f0a3e4eca113df7d09bbff6c3678ff27Virustotal results 35/69 (50.72%) 216.58.215.227:443
2018-12-05 06:15:27f0a3e4eca113df7d09bbff6c3678ff27Virustotal results 35/69 (50.72%) 172.217.168.196:443
2018-12-05 06:15:26f0a3e4eca113df7d09bbff6c3678ff27Virustotal results 35/69 (50.72%) 172.217.17.35:443
2018-12-03 10:27:382859f008ada0a06ef6a1f635730c35f1Virustotal results 37/70 (52.86%) 74.125.206.94:443
2018-12-03 10:27:382859f008ada0a06ef6a1f635730c35f1Virustotal results 37/70 (52.86%) 172.217.20.100:443
2018-11-26 08:28:408c2a233173810d4f53df1cc5de624d50Virustotal results 35/70 (50.00%) 74.125.206.94:443
2018-11-26 08:28:398c2a233173810d4f53df1cc5de624d50Virustotal results 35/70 (50.00%) 74.125.206.104:443
2018-11-25 13:38:34fb997d885b5e1094b56672648e1e99b4Virustotal results 35/69 (50.72%) 216.58.211.99:443
2018-11-22 16:18:18a3f0d4f18f1b20f8931f07a2658edcf7Virustotal results 34/67 (50.75%) 74.125.142.105:443
2018-11-22 16:18:18a3f0d4f18f1b20f8931f07a2658edcf7Virustotal results 34/67 (50.75%) 108.177.98.94:443
2018-11-22 16:18:16a3f0d4f18f1b20f8931f07a2658edcf7Virustotal results 34/67 (50.75%) 74.125.142.106:443
2018-11-18 19:19:39bc95c3f699cea00f31cc288e669d9bd3Virustotal results 18/67 (26.87%) 173.194.76.94:443
2018-11-18 09:28:437fd59b6093f5554080de55353270554cVirustotal results 43/68 (63.24%) 216.58.215.68:443
2018-11-18 09:28:417fd59b6093f5554080de55353270554cVirustotal results 43/68 (63.24%) 216.58.215.67:443
2018-11-17 05:17:191eeae4203ca29b93116321481964bafeVirustotal results 28/68 (41.18%) 216.58.215.67:443
2018-11-14 04:38:23d867341d9d23eb614a4c266d70405f40Virustotal results 33/68 (48.53%) 172.217.18.195:443
2018-11-14 04:38:22d867341d9d23eb614a4c266d70405f40Virustotal results 33/68 (48.53%) 216.58.208.228:443
2018-11-11 10:31:313159bed9fa80ab6ca9f84f960fbb5af5Virustotal results 20/67 (29.85%) 216.58.215.227:443
2018-11-11 10:31:293159bed9fa80ab6ca9f84f960fbb5af5Virustotal results 20/67 (29.85%) 172.217.17.100:443
2018-11-11 10:31:293159bed9fa80ab6ca9f84f960fbb5af5Virustotal results 20/67 (29.85%) 172.217.16.68:443
2018-11-11 10:31:273159bed9fa80ab6ca9f84f960fbb5af5Virustotal results 20/67 (29.85%) 216.58.215.228:443
2018-11-11 10:31:263159bed9fa80ab6ca9f84f960fbb5af5Virustotal results 20/67 (29.85%) 172.217.19.67:443
2018-11-11 10:31:263159bed9fa80ab6ca9f84f960fbb5af5Virustotal results 20/67 (29.85%) 172.217.168.195:443
2018-11-11 10:31:253159bed9fa80ab6ca9f84f960fbb5af5Virustotal results 20/67 (29.85%) 172.217.168.196:443
2018-11-11 10:31:223159bed9fa80ab6ca9f84f960fbb5af5Virustotal results 20/67 (29.85%) 172.217.17.35:443
2018-11-09 18:57:13801bc8bf351d8ff76ee6bd9cf75e377bVirustotal results 36/68 (52.94%) 74.125.142.103:443
2018-11-09 18:57:06801bc8bf351d8ff76ee6bd9cf75e377bVirustotal results 36/68 (52.94%) 74.125.197.94:443
2018-11-09 16:30:022ea7ef3d2b87c2d677122e821bf8a89fVirustotal results 14/67 (20.90%) 172.217.17.99:443
2018-11-08 20:46:106b37b21fd88278a5311d8a780ba0f081Virustotal results 33/68 (48.53%) 172.217.18.164:443
2018-11-08 20:46:106b37b21fd88278a5311d8a780ba0f081Virustotal results 33/68 (48.53%) 172.217.16.195:443
2018-11-08 13:47:38284d85486387649bbf48e5dfa9aec8b0Virustotal results 37/67 (55.22%) 216.58.211.99:443
2018-11-08 00:20:28488771b31d7e237c4db5233da7d51768Virustotal results 33/68 (48.53%) 172.217.20.35:443
2018-11-08 00:20:27488771b31d7e237c4db5233da7d51768Virustotal results 33/68 (48.53%) 172.217.20.36:443
2018-11-08 00:20:25488771b31d7e237c4db5233da7d51768Virustotal results 33/68 (48.53%) 216.58.207.227:443
2018-11-03 17:13:38a29cd5d99141ceeb10e7c4ef4f41668bVirustotal results 31/67 (46.27%) 216.58.208.228:443
2018-11-03 17:13:37a29cd5d99141ceeb10e7c4ef4f41668bVirustotal results 31/67 (46.27%) 216.58.208.227:443
2018-11-03 17:13:37a29cd5d99141ceeb10e7c4ef4f41668bVirustotal results 31/67 (46.27%) 216.58.204.132:443
2018-11-03 15:59:1303fe25b72e3ec087d90409b482d31985Virustotal results 36/68 (52.94%) 74.125.20.103:443
2018-11-03 15:59:1303fe25b72e3ec087d90409b482d31985Virustotal results 36/68 (52.94%) 74.125.20.147:443
2018-11-03 15:59:1203fe25b72e3ec087d90409b482d31985Virustotal results 36/68 (52.94%) 74.125.195.94:443
2018-10-21 00:41:061fd5cc1d4e9cd89756af71a2c633d7e1Virustotal results 13/67 (19.40%) 216.58.212.164:443
2018-10-21 00:41:031fd5cc1d4e9cd89756af71a2c633d7e1Virustotal results 13/67 (19.40%) 172.217.168.195:443
2018-10-15 22:30:23bd9639044643025556c8fbd6271fe5e5Virustotal results 27/67 (40.30%) 216.58.201.227:443
2018-10-15 22:30:22bd9639044643025556c8fbd6271fe5e5Virustotal results 27/67 (40.30%) 172.217.18.196:443
2018-10-15 06:27:595f783acdf0e680cb05df27c9101090ean/a172.217.23.163:443
2018-10-15 06:27:565f783acdf0e680cb05df27c9101090ean/a216.58.206.4:443
2018-10-14 19:55:48b9a775c3da28cd0006378f0ca253211fVirustotal results 16/68 (23.53%) 216.58.211.100:443
2018-10-14 19:55:47b9a775c3da28cd0006378f0ca253211fVirustotal results 16/68 (23.53%) 216.58.212.132:443
2018-10-14 11:14:12b6eaeba05d7773789cae8999e0ecb122Virustotal results 12/66 (18.18%) 172.217.17.36:443
2018-10-14 10:35:55da4a56f9db3ccef32e88ad2e5c616a1aVirustotal results 18/67 (26.87%) 216.58.211.4:443
2018-10-08 04:26:380afa975d799b02214776fece33adc91bVirustotal results 13/69 (18.84%) 216.58.198.196:443
2018-10-08 04:26:380afa975d799b02214776fece33adc91bVirustotal results 13/69 (18.84%) 216.58.204.132:443
2018-10-08 04:26:350afa975d799b02214776fece33adc91bVirustotal results 13/69 (18.84%) 172.217.19.228:443
2018-10-08 04:26:350afa975d799b02214776fece33adc91bVirustotal results 13/69 (18.84%) 172.217.18.196:443
2018-10-08 04:26:350afa975d799b02214776fece33adc91bVirustotal results 13/69 (18.84%) 216.58.206.228:443
2018-10-08 04:26:340afa975d799b02214776fece33adc91bVirustotal results 13/69 (18.84%) 216.58.204.131:443
2018-10-07 04:15:29c5a4ab3875d8acd2fe09d4775be60ba4Virustotal results 43/69 (62.32%) 172.217.11.163:443
2018-10-07 01:19:20b1673c284cbf1b313434609d8a9221b7Virustotal results 40/69 (57.97%) 172.217.20.164:443
2018-10-07 01:19:04b1673c284cbf1b313434609d8a9221b7Virustotal results 40/69 (57.97%) 172.217.20.163:443
2018-10-05 23:45:11ed5a7dbe69f6ee8cd00cbce2a9ec39d7Virustotal results 14/69 (20.29%) 172.217.14.99:443
2018-10-05 22:21:29614ffc059fc2ecbbd09cac491a27f25dVirustotal results 35/69 (50.72%) 216.58.211.3:443
2018-10-05 21:11:03a2c265dcda4b8c63343326368a7edd9aVirustotal results 36/67 (53.73%) 216.58.205.196:443
2018-10-05 21:11:02a2c265dcda4b8c63343326368a7edd9aVirustotal results 36/67 (53.73%) 216.58.198.35:443
2018-10-05 21:10:58a2c265dcda4b8c63343326368a7edd9aVirustotal results 36/67 (53.73%) 172.217.168.67:443
2018-10-04 05:34:58b0912e893eb8ae3551e5e08ee1dbeb3aVirustotal results 26/67 (38.81%) 216.58.198.4:443
2018-10-04 05:34:48b0912e893eb8ae3551e5e08ee1dbeb3aVirustotal results 26/67 (38.81%) 172.217.168.67:443
2018-10-03 23:13:40a679fc33cd540373f39838d4d6dfdca8Virustotal results 35/69 (50.72%) 74.125.90.100:443

# of entries: 100 (max: 100)