JA3 Fingerprints

You can find further information about the JA3 fingerprint d18a4da84af59e1108862a39bae7c9d4, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:d18a4da84af59e1108862a39bae7c9d4
First seen:2018-04-03 00:40:51 UTC
Last seen:2021-02-06 01:53:12 UTC
Status:Blacklisted
Malware samples:110
Destination IPs:45
Malware:Tofsee -
Listing date:2018-11-14 12:51:08

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2023-08-07 15:23:513a2fffded769bace9850a1ace78f25e4n/a172.217.168.78:443
2023-08-07 15:23:513a2fffded769bace9850a1ace78f25e4n/a185.199.108.153:443
2023-07-28 15:52:5524dc28354412607dbe3e8e579e7521b1Virustotal results 2 / 69 (2.90%) 185.199.111.133:443
2023-07-28 15:52:5524dc28354412607dbe3e8e579e7521b1Virustotal results 2 / 69 (2.90%) 140.82.121.3:443
2023-07-28 05:18:494d07eed20777cd155c3708089d0aaf1an/a185.199.111.153:443
2023-07-25 00:29:364375b03938ac8048f16ec15973085b30n/a18.165.183.88:443
2023-07-22 23:41:38b494cbfff8f6d983ced8104f015ed81cn/a216.58.215.238:443
2023-07-22 23:41:37b494cbfff8f6d983ced8104f015ed81cn/a185.199.108.153:443
2023-07-20 19:14:4709c29797bae7a8e05e623553efd25415Virustotal results 1 / 71 (1.41%) 18.165.183.88:443
2022-11-20 06:50:380871bf121991e15e9f58f01d4158478dn/a52.72.172.158:443
2022-10-17 13:02:08690e38c3049c7abe8edd1bc9df35f2f7n/a142.250.185.78:443
2022-10-17 13:02:08690e38c3049c7abe8edd1bc9df35f2f7n/a142.250.185.77:443
2022-10-12 19:40:184555e058c3f846730f45b6e3d616efaen/a20.224.186.212:443
2022-08-17 04:28:58d8bcad6d70400c4b798451295d9ec2dan/a95.143.172.170:443
2022-08-16 20:06:26b2a011144841893accb0bd3abaff9545n/a95.143.172.170:443
2022-05-23 01:37:37cd79edc7304276161ddb36b2ec4d693an/a95.143.172.170:443
2022-05-18 18:27:21c32b97185c230fc6838f628d5d47f1f7n/a95.143.172.170:443
2022-05-18 17:36:080f411b184480feecfbbafe5aa31d89f2n/a95.143.172.170:443
2022-05-18 17:35:020cfdd572f8ae03ac9332e0ceb322ac3an/a95.143.172.170:443
2022-05-18 17:22:494d22343fb2151796c793bb98e678933cVirustotal results 1 / 69 (1.45%) 95.143.172.170:443
2022-05-18 17:13:08145dac3bf976db3bc03529db98db19f3Virustotal results 0 / 67 (0.00%) 95.143.172.170:443
2022-05-18 09:46:391d314d77d6fe01fa33d2788201586f6en/a95.143.172.170:443
2022-04-23 04:14:1164166399442b52d87184a4063ad45991n/a74.125.34.46:443
2022-04-21 04:57:43e11ee37e1c70ba57f88c251f5ef4f15an/a95.143.172.170:443
2022-03-04 19:53:260fac031efef802bd82a736e7ea998448Virustotal results 1 / 66 (1.52%) 95.143.172.170:443
2022-01-29 06:43:30d34e9dbbb3140ba461ac91583825d254Virustotal results 7 / 64 (10.94%) 95.143.172.170:443
2021-12-31 21:18:14a3cf408945b7d20a3e32f2caeb1fc97aVirustotal results 0 / 68 (0.00%) 95.143.172.170:443
2021-12-29 13:32:27b178e23c92d5b00fcc595dbc59c84c22Virustotal results 0 / 66 (0.00%) 95.143.172.170:443
2021-12-29 06:15:35b0b79899717881085027afac59fca1b3n/a95.143.172.170:443
2021-12-01 02:33:18f6154869a2203b93bbfc9bba271c971cn/a95.143.172.170:443
2021-12-01 00:05:26e5e6b516e9aaece920fd88f7bcd28ab1n/a52.216.245.78:443
2021-09-26 16:29:54cd4c8768f0e21429fbc7f844ed54e330n/a145.239.231.17:443
2021-09-26 16:29:54cd4c8768f0e21429fbc7f844ed54e330n/a142.250.203.110:443
2021-09-21 06:46:40d51c971722f64dededb8410a537c47d3n/a52.72.172.158:443
2021-09-11 08:44:07969deb37aac55eb8ee385aca27102dd2n/a62.141.38.176:443
2021-08-25 10:17:047394d2f799e6d9336a14ea64fa4e5d1fn/a212.82.100.76:587
2021-08-22 04:40:18344e9bddcd948c865df4b7fa0199dc34n/a151.101.112.84:443
2021-02-06 01:53:120a025b1367a36afa7f91b4a3b52d3824Virustotal results 3 / 70 (4.29%) 52.216.98.125:443
2021-02-06 01:53:120a025b1367a36afa7f91b4a3b52d3824Virustotal results 3 / 70 (4.29%) 52.216.98.125:443
2021-01-02 15:41:11098c76eda17b5d738cc591adf8c17df9Virustotal results 0 / 69 (0.00%) 140.82.121.3:443
2021-01-02 15:41:11098c76eda17b5d738cc591adf8c17df9Virustotal results 0 / 69 (0.00%) 185.199.108.153:443
2021-01-02 15:41:11098c76eda17b5d738cc591adf8c17df9Virustotal results 0 / 69 (0.00%) 52.217.12.36:443
2021-01-02 15:41:11098c76eda17b5d738cc591adf8c17df9Virustotal results 0 / 69 (0.00%) 95.143.172.170:443
2021-01-02 15:41:11098c76eda17b5d738cc591adf8c17df9Virustotal results 0 / 69 (0.00%) 140.82.121.3:443
2021-01-02 15:41:11098c76eda17b5d738cc591adf8c17df9Virustotal results 0 / 69 (0.00%) 185.199.108.153:443
2021-01-02 15:41:11098c76eda17b5d738cc591adf8c17df9Virustotal results 0 / 69 (0.00%) 52.217.12.36:443
2021-01-02 15:41:11098c76eda17b5d738cc591adf8c17df9Virustotal results 0 / 69 (0.00%) 95.143.172.170:443
2020-11-11 00:58:38aabf3a244725176bcca17e5d488524b6Virustotal results 10 / 73 (13.70%) 136.243.106.42:443
2020-11-11 00:58:38aabf3a244725176bcca17e5d488524b6Virustotal results 10 / 73 (13.70%) 136.243.106.42:443
2020-09-28 13:39:260500b295b20e26546ffede81edf77476Virustotal results 6 / 71 (8.45%) 216.58.208.110:443
2020-09-28 13:39:260500b295b20e26546ffede81edf77476Virustotal results 6 / 71 (8.45%) 216.58.208.110:443
2020-08-01 04:06:140cf4c7388038b31f8e68cf35cc8d5e31Virustotal results 0 / 69 (0.00%) 95.143.172.170:443
2020-08-01 04:06:140cf4c7388038b31f8e68cf35cc8d5e31Virustotal results 0 / 69 (0.00%) 140.82.118.4:443
2020-08-01 04:06:140cf4c7388038b31f8e68cf35cc8d5e31Virustotal results 0 / 69 (0.00%) 52.216.205.251:443
2020-08-01 04:06:140cf4c7388038b31f8e68cf35cc8d5e31Virustotal results 0 / 69 (0.00%) 185.199.109.153:443
2020-08-01 04:06:140cf4c7388038b31f8e68cf35cc8d5e31Virustotal results 0 / 69 (0.00%) 95.143.172.170:443
2020-08-01 04:06:140cf4c7388038b31f8e68cf35cc8d5e31Virustotal results 0 / 69 (0.00%) 140.82.118.4:443
2020-08-01 04:06:140cf4c7388038b31f8e68cf35cc8d5e31Virustotal results 0 / 69 (0.00%) 52.216.205.251:443
2020-08-01 04:06:140cf4c7388038b31f8e68cf35cc8d5e31Virustotal results 0 / 69 (0.00%) 185.199.109.153:443
2020-06-24 09:30:52a175008436819971840f555f09231365Virustotal results 48 / 73 (65.75%) 74.125.34.46:443
2020-06-24 09:30:52a175008436819971840f555f09231365Virustotal results 48 / 73 (65.75%) 74.125.34.46:443
2020-06-24 02:36:1328093a90e265c0637fec95a5e42101a7Virustotal results 49 / 74 (66.22%) 74.125.34.46:443
2020-06-24 02:36:1328093a90e265c0637fec95a5e42101a7Virustotal results 49 / 74 (66.22%) 74.125.34.46:443
2020-06-22 13:46:247a1ea0844eb1a246222c9e7a8902e0a4Virustotal results 50 / 74 (67.57%) 74.125.34.46:443
2020-06-22 13:46:247a1ea0844eb1a246222c9e7a8902e0a4Virustotal results 50 / 74 (67.57%) 74.125.34.46:443
2020-06-22 12:48:4875f4c7a207e9c18a7c4ceadb3a141193Virustotal results 49 / 73 (67.12%) 74.125.34.46:443
2020-06-22 12:48:4875f4c7a207e9c18a7c4ceadb3a141193Virustotal results 49 / 73 (67.12%) 74.125.34.46:443
2020-06-22 08:22:3462ebe9aea87177ecc9a3970e451d041fVirustotal results 47 / 71 (66.20%) 74.125.34.46:443
2020-06-22 08:22:3462ebe9aea87177ecc9a3970e451d041fVirustotal results 47 / 71 (66.20%) 74.125.34.46:443
2020-06-22 07:11:5853c9c22b014af328d91a181df86517f1Virustotal results 53 / 74 (71.62%) 74.125.34.46:443
2020-06-22 07:11:5853c9c22b014af328d91a181df86517f1Virustotal results 53 / 74 (71.62%) 74.125.34.46:443
2020-06-21 23:33:153ea69564e92429572ec12913ff874890Virustotal results 53 / 73 (72.60%) 74.125.34.46:443
2020-06-21 23:33:153ea69564e92429572ec12913ff874890Virustotal results 53 / 73 (72.60%) 74.125.34.46:443
2020-06-21 22:03:023892834957a893d4d71bdb79304d4e90Virustotal results 49 / 74 (66.22%) 74.125.34.46:443
2020-06-21 22:03:023892834957a893d4d71bdb79304d4e90Virustotal results 49 / 74 (66.22%) 74.125.34.46:443
2020-06-21 20:18:4930e99775eb975d88619dc0a5a27e9c64Virustotal results 50 / 74 (67.57%) 74.125.34.46:443
2020-06-21 20:18:4930e99775eb975d88619dc0a5a27e9c64Virustotal results 50 / 74 (67.57%) 74.125.34.46:443
2020-06-19 16:05:40a42f6d3a7f2982447256f001b639215eVirustotal results 48 / 72 (66.67%) 74.125.34.46:443
2020-06-19 16:05:40a42f6d3a7f2982447256f001b639215eVirustotal results 48 / 72 (66.67%) 74.125.34.46:443
2020-06-19 15:50:28a362c951b8984f0ee329b281e7e42bf7Virustotal results 49 / 74 (66.22%) 74.125.34.46:443
2020-06-19 15:50:28a362c951b8984f0ee329b281e7e42bf7Virustotal results 49 / 74 (66.22%) 74.125.34.46:443
2020-06-19 08:57:2126cd2845fa151ee4878a83df30326ff4Virustotal results 49 / 74 (66.22%) 74.125.34.46:443
2020-06-19 08:57:2126cd2845fa151ee4878a83df30326ff4Virustotal results 49 / 74 (66.22%) 74.125.34.46:443
2020-06-19 08:32:59258272c5b0480d36427cb70a5d3f6439Virustotal results 46 / 73 (63.01%) 74.125.34.46:443
2020-06-19 08:32:59258272c5b0480d36427cb70a5d3f6439Virustotal results 46 / 73 (63.01%) 74.125.34.46:443
2020-06-19 08:28:4525054ee2a25c0525d323dc5056a699e9Virustotal results 45 / 71 (63.38%) 74.125.34.46:443
2020-06-19 08:28:4525054ee2a25c0525d323dc5056a699e9Virustotal results 45 / 71 (63.38%) 74.125.34.46:443
2020-06-19 07:53:10229720affc72c6a624753774de23136bVirustotal results 49 / 74 (66.22%) 74.125.34.46:443
2020-06-19 07:53:10229720affc72c6a624753774de23136bVirustotal results 49 / 74 (66.22%) 74.125.34.46:443
2020-06-19 00:07:3007e485fc2889f1137b9a0754a567ec18Virustotal results 46 / 69 (66.67%) 74.125.34.46:443
2020-06-19 00:07:3007e485fc2889f1137b9a0754a567ec18Virustotal results 46 / 69 (66.67%) 74.125.34.46:443
2020-06-18 23:51:020811eb50b7b53520397b1a4645b5a7b6Virustotal results 50 / 73 (68.49%) 74.125.34.46:443
2020-06-18 23:51:020811eb50b7b53520397b1a4645b5a7b6Virustotal results 50 / 73 (68.49%) 74.125.34.46:443
2020-06-18 23:00:01035f2d2e8ef3ce5fd281776d5cf4cf15Virustotal results 48 / 73 (65.75%) 74.125.34.46:443
2020-06-18 23:00:01035f2d2e8ef3ce5fd281776d5cf4cf15Virustotal results 48 / 73 (65.75%) 74.125.34.46:443
2020-06-18 21:32:54143289687b08093df43de4e7d88d2ebfVirustotal results 48 / 72 (66.67%) 74.125.34.46:443
2020-06-18 21:32:54143289687b08093df43de4e7d88d2ebfVirustotal results 48 / 72 (66.67%) 74.125.34.46:443
2020-06-18 21:19:050e86068f86ee15f46329a0d2ed63b7b2Virustotal results 47 / 73 (64.38%) 74.125.34.46:443
2020-06-18 21:19:050e86068f86ee15f46329a0d2ed63b7b2Virustotal results 47 / 73 (64.38%) 74.125.34.46:443
2020-06-18 12:25:474bfa26be856487eceab1d55e43df1175Virustotal results 46 / 71 (64.79%) 74.125.34.46:443

# of entries: 100 (max: 100)