JA3 Fingerprints

You can find further information about the JA3 fingerprint d18a4da84af59e1108862a39bae7c9d4, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:d18a4da84af59e1108862a39bae7c9d4
First seen:2018-04-03 00:40:51 UTC
Last seen:2018-04-26 10:29:34 UTC
Status:Blacklisted
Malware samples:32
Destination IPs:14
Malware:Tofsee -
Listing date:2018-11-14 12:51:08

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2018-04-26 10:29:34ce4b4a80b4d2aa880d5d44b72d797492Virustotal results 48/67 (71.64%) 209.206.41.33:443
2018-04-25 20:00:490bf4e7ebdea9dd95fa5f307621358f15Virustotal results 47/67 (70.15%) 209.206.41.33:443
2018-04-25 20:00:490bf4e7ebdea9dd95fa5f307621358f15Virustotal results 47/67 (70.15%) 209.206.41.26:443
2018-04-17 14:24:2201ce99c1fdd97f746d43792b5c4e4257Virustotal results 39/67 (58.21%) 8.42.96.132:443
2018-04-17 14:24:2201ce99c1fdd97f746d43792b5c4e4257Virustotal results 39/67 (58.21%) 8.42.96.39:443
2018-04-17 14:24:2201ce99c1fdd97f746d43792b5c4e4257Virustotal results 39/67 (58.21%) 209.206.41.47:443
2018-04-17 14:24:2201ce99c1fdd97f746d43792b5c4e4257Virustotal results 39/67 (58.21%) 8.42.96.136:443
2018-04-15 16:59:128af5573193fccdd23ee8ab4ec6f1030dVirustotal results 14/65 (21.54%) 8.42.96.30:443
2018-04-13 05:28:2214587f387748738734bea6b4eb73e829Virustotal results 22/66 (33.33%) 209.206.41.46:443
2018-04-13 05:28:2214587f387748738734bea6b4eb73e829Virustotal results 22/66 (33.33%) 8.42.96.42:443
2018-04-13 05:28:2214587f387748738734bea6b4eb73e829Virustotal results 22/66 (33.33%) 8.42.96.136:443
2018-04-13 05:28:2214587f387748738734bea6b4eb73e829Virustotal results 22/66 (33.33%) 8.42.96.25:443
2018-04-13 05:28:2214587f387748738734bea6b4eb73e829Virustotal results 22/66 (33.33%) 8.42.96.138:443
2018-04-12 13:12:37b86ac124469b5440dcb9f39effb92fe3Virustotal results 51/68 (75.00%) 8.42.96.42:443
2018-04-12 13:12:37b86ac124469b5440dcb9f39effb92fe3Virustotal results 51/68 (75.00%) 8.42.96.30:443
2018-04-12 13:12:37b86ac124469b5440dcb9f39effb92fe3Virustotal results 51/68 (75.00%) 8.42.96.132:443
2018-04-12 13:12:37b86ac124469b5440dcb9f39effb92fe3Virustotal results 51/68 (75.00%) 8.42.96.39:443
2018-04-12 13:12:37b86ac124469b5440dcb9f39effb92fe3Virustotal results 51/68 (75.00%) 209.206.41.48:443
2018-04-11 18:58:10029951d316f148f9505cfdd19521a001Virustotal results 40/67 (59.70%) 8.42.96.30:443
2018-04-11 18:58:10029951d316f148f9505cfdd19521a001Virustotal results 40/67 (59.70%) 8.42.96.39:443
2018-04-11 18:58:10029951d316f148f9505cfdd19521a001Virustotal results 40/67 (59.70%) 8.42.96.134:443
2018-04-11 15:49:58c58f378003b3fad4b6da5f9b661134e7Virustotal results 19/68 (27.94%) 8.42.96.134:443
2018-04-11 15:49:58c58f378003b3fad4b6da5f9b661134e7Virustotal results 19/68 (27.94%) 8.42.96.138:443
2018-04-11 15:49:58c58f378003b3fad4b6da5f9b661134e7Virustotal results 19/68 (27.94%) 8.42.96.132:443
2018-04-11 05:08:30704f823717c19c07666a464057d11a92Virustotal results 17/67 (25.37%) 8.42.96.136:443
2018-04-11 05:08:30704f823717c19c07666a464057d11a92Virustotal results 17/67 (25.37%) 8.42.96.42:443
2018-04-11 05:08:30704f823717c19c07666a464057d11a92Virustotal results 17/67 (25.37%) 8.42.96.30:443
2018-04-11 05:08:30704f823717c19c07666a464057d11a92Virustotal results 17/67 (25.37%) 8.42.96.39:443
2018-04-11 05:08:30704f823717c19c07666a464057d11a92Virustotal results 17/67 (25.37%) 8.42.96.25:443
2018-04-11 02:23:06ae726080b4dd2ecaea054214e97223b8Virustotal results 50/68 (73.53%) 209.206.41.46:443
2018-04-10 02:10:1911ab2e8582039a444b330956cb7ea76bVirustotal results 35/63 (55.56%) 8.42.96.136:443
2018-04-10 02:10:1911ab2e8582039a444b330956cb7ea76bVirustotal results 35/63 (55.56%) 209.206.41.48:443
2018-04-10 02:00:235c3550574945d7427da9457aeb98d9acVirustotal results 36/66 (54.55%) 8.42.96.134:443
2018-04-10 02:00:235c3550574945d7427da9457aeb98d9acVirustotal results 36/66 (54.55%) 8.42.96.25:443
2018-04-10 02:00:235c3550574945d7427da9457aeb98d9acVirustotal results 36/66 (54.55%) 8.42.96.39:443
2018-04-10 00:22:102cbe26285ee16335ac4f0d16e35a9307Virustotal results 48/67 (71.64%) 8.42.96.30:443
2018-04-10 00:22:102cbe26285ee16335ac4f0d16e35a9307Virustotal results 48/67 (71.64%) 8.42.96.136:443
2018-04-10 00:22:102cbe26285ee16335ac4f0d16e35a9307Virustotal results 48/67 (71.64%) 8.42.96.25:443
2018-04-10 00:22:102cbe26285ee16335ac4f0d16e35a9307Virustotal results 48/67 (71.64%) 8.42.96.134:443
2018-04-10 00:22:102cbe26285ee16335ac4f0d16e35a9307Virustotal results 48/67 (71.64%) 8.42.96.42:443
2018-04-10 00:22:102cbe26285ee16335ac4f0d16e35a9307Virustotal results 48/67 (71.64%) 8.42.96.132:443
2018-04-09 23:49:01486902e15220dbd0bf14dab73d319452Virustotal results 48/67 (71.64%) 8.42.96.136:443
2018-04-09 22:31:518c140a190a55f23e3cb81e4da866705fVirustotal results 47/67 (70.15%) 8.42.96.30:443
2018-04-09 22:31:518c140a190a55f23e3cb81e4da866705fVirustotal results 47/67 (70.15%) 8.42.96.42:443
2018-04-09 22:06:049681eaddffd63b1361cf0e0710c977b0Virustotal results 55/67 (82.09%) 8.42.96.39:443
2018-04-09 22:06:049681eaddffd63b1361cf0e0710c977b0Virustotal results 55/67 (82.09%) 8.42.96.136:443
2018-04-09 22:06:049681eaddffd63b1361cf0e0710c977b0Virustotal results 55/67 (82.09%) 8.42.96.42:443
2018-04-09 22:06:049681eaddffd63b1361cf0e0710c977b0Virustotal results 55/67 (82.09%) 8.42.96.138:443
2018-04-09 22:06:049681eaddffd63b1361cf0e0710c977b0Virustotal results 55/67 (82.09%) 8.42.96.134:443
2018-04-09 22:06:049681eaddffd63b1361cf0e0710c977b0Virustotal results 55/67 (82.09%) 8.42.96.30:443
2018-04-09 21:04:1720f0a425d4dd52db90681cfa88eb2841Virustotal results 54/67 (80.60%) 8.42.96.138:443
2018-04-09 21:04:1720f0a425d4dd52db90681cfa88eb2841Virustotal results 54/67 (80.60%) 8.42.96.134:443
2018-04-09 21:04:1720f0a425d4dd52db90681cfa88eb2841Virustotal results 54/67 (80.60%) 209.206.41.47:443
2018-04-09 21:04:1720f0a425d4dd52db90681cfa88eb2841Virustotal results 54/67 (80.60%) 8.42.96.132:443
2018-04-09 21:04:1720f0a425d4dd52db90681cfa88eb2841Virustotal results 54/67 (80.60%) 8.42.96.25:443
2018-04-09 21:04:1720f0a425d4dd52db90681cfa88eb2841Virustotal results 54/67 (80.60%) 8.42.96.42:443
2018-04-09 21:04:1720f0a425d4dd52db90681cfa88eb2841Virustotal results 54/67 (80.60%) 8.42.96.39:443
2018-04-09 21:04:1720f0a425d4dd52db90681cfa88eb2841Virustotal results 54/67 (80.60%) 8.42.96.136:443
2018-04-06 07:47:03f911dbd0d4c1e82240e0b6962b785422Virustotal results 43/67 (64.18%) 209.206.41.49:443
2018-04-06 07:47:03f911dbd0d4c1e82240e0b6962b785422Virustotal results 43/67 (64.18%) 8.42.96.42:443
2018-04-06 07:47:03f911dbd0d4c1e82240e0b6962b785422Virustotal results 43/67 (64.18%) 8.42.96.132:443
2018-04-06 07:47:03f911dbd0d4c1e82240e0b6962b785422Virustotal results 43/67 (64.18%) 8.42.96.30:443
2018-04-06 07:47:03f911dbd0d4c1e82240e0b6962b785422Virustotal results 43/67 (64.18%) 8.42.96.136:443
2018-04-06 07:47:03f911dbd0d4c1e82240e0b6962b785422Virustotal results 43/67 (64.18%) 8.42.96.134:443
2018-04-04 16:24:20b8db1fca57fcf71af0922d01467a744eVirustotal results 44/67 (65.67%) 8.42.96.132:443
2018-04-04 16:24:20b8db1fca57fcf71af0922d01467a744eVirustotal results 44/67 (65.67%) 8.42.96.42:443
2018-04-04 16:24:20b8db1fca57fcf71af0922d01467a744eVirustotal results 44/67 (65.67%) 8.42.96.134:443
2018-04-04 16:24:20b8db1fca57fcf71af0922d01467a744eVirustotal results 44/67 (65.67%) 8.42.96.30:443
2018-04-04 14:59:35b08e1f14f68e94f2a6d639a96274630eVirustotal results 48/65 (73.85%) 8.42.96.25:443
2018-04-04 14:59:35b08e1f14f68e94f2a6d639a96274630eVirustotal results 48/65 (73.85%) 8.42.96.134:443
2018-04-04 14:59:35b08e1f14f68e94f2a6d639a96274630eVirustotal results 48/65 (73.85%) 209.206.41.48:443
2018-04-04 14:59:35b08e1f14f68e94f2a6d639a96274630eVirustotal results 48/65 (73.85%) 8.42.96.138:443
2018-04-04 14:59:35b08e1f14f68e94f2a6d639a96274630eVirustotal results 48/65 (73.85%) 8.42.96.136:443
2018-04-04 14:59:35b08e1f14f68e94f2a6d639a96274630eVirustotal results 48/65 (73.85%) 209.206.41.47:443
2018-04-04 14:59:35b08e1f14f68e94f2a6d639a96274630eVirustotal results 48/65 (73.85%) 8.42.96.132:443
2018-04-04 14:59:35b08e1f14f68e94f2a6d639a96274630eVirustotal results 48/65 (73.85%) 8.42.96.42:443
2018-04-04 05:25:20eb190e1256a0fec6c5119bfd6213b2d3n/a8.42.96.42:443
2018-04-04 04:35:24d200df2031b0887bdc29f7c747f1ab6an/a8.42.96.132:443
2018-04-04 04:35:24d200df2031b0887bdc29f7c747f1ab6an/a8.42.96.138:443
2018-04-04 04:35:24d200df2031b0887bdc29f7c747f1ab6an/a209.206.41.48:443
2018-04-04 04:35:24d200df2031b0887bdc29f7c747f1ab6an/a8.42.96.25:443
2018-04-04 04:35:24d200df2031b0887bdc29f7c747f1ab6an/a8.42.96.39:443
2018-04-03 23:03:36d33b3e2d0fb5b478c4621de95e7f9775n/a8.42.96.30:443
2018-04-03 23:03:36d33b3e2d0fb5b478c4621de95e7f9775n/a8.42.96.136:443
2018-04-03 23:03:36d33b3e2d0fb5b478c4621de95e7f9775n/a209.206.41.48:443
2018-04-03 23:03:36d33b3e2d0fb5b478c4621de95e7f9775n/a8.42.96.132:443
2018-04-03 23:03:36d33b3e2d0fb5b478c4621de95e7f9775n/a8.42.96.134:443
2018-04-03 23:03:36d33b3e2d0fb5b478c4621de95e7f9775n/a8.42.96.39:443
2018-04-03 23:03:36d33b3e2d0fb5b478c4621de95e7f9775n/a8.42.96.42:443
2018-04-03 19:52:28d1aabce153d9fd56318f5a1d56305f36Virustotal results 45/63 (71.43%) 209.206.41.47:443
2018-04-03 19:52:28d1aabce153d9fd56318f5a1d56305f36Virustotal results 45/63 (71.43%) 8.42.96.138:443
2018-04-03 19:52:28d1aabce153d9fd56318f5a1d56305f36Virustotal results 45/63 (71.43%) 8.42.96.30:443
2018-04-03 19:52:28d1aabce153d9fd56318f5a1d56305f36Virustotal results 45/63 (71.43%) 209.206.41.46:443
2018-04-03 19:52:28d1aabce153d9fd56318f5a1d56305f36Virustotal results 45/63 (71.43%) 8.42.96.25:443
2018-04-03 19:52:28d1aabce153d9fd56318f5a1d56305f36Virustotal results 45/63 (71.43%) 8.42.96.136:443
2018-04-03 19:52:28d1aabce153d9fd56318f5a1d56305f36Virustotal results 45/63 (71.43%) 8.42.96.134:443
2018-04-03 11:20:49305f33c563560164f4a2f42f072ef07dVirustotal results 49/67 (73.13%) 8.42.96.136:443
2018-04-03 11:20:49305f33c563560164f4a2f42f072ef07dVirustotal results 49/67 (73.13%) 209.206.41.46:443
2018-04-03 11:20:49305f33c563560164f4a2f42f072ef07dVirustotal results 49/67 (73.13%) 8.42.96.132:443
2018-04-03 11:20:49305f33c563560164f4a2f42f072ef07dVirustotal results 49/67 (73.13%) 8.42.96.25:443

# of entries: 100 (max: 100)