JA3 Fingerprints

You can find further information about the JA3 fingerprint da949afd9bd6df820730f8f171584a71, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:da949afd9bd6df820730f8f171584a71
First seen:2018-02-03 05:19:37 UTC
Last seen:2021-03-08 22:10:10 UTC
Status:Blacklisted
Malware samples:231
Destination IPs:26
Malware:Tofsee -
Listing date:2020-01-09 14:28:57

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2023-12-10 07:30:39b9922787936c8e2ed028b5bd652d7ee9n/a57.128.74.69:443
2023-12-10 07:30:37b9922787936c8e2ed028b5bd652d7ee9n/a104.16.183.69:8443
2021-03-08 22:10:100a6d0faaf9ebb396c8cbeb74a48e83abVirustotal results 39 / 71 (54.93%) 31.13.64.16:443
2021-03-08 22:10:100a6d0faaf9ebb396c8cbeb74a48e83abVirustotal results 39 / 71 (54.93%) 31.13.64.16:443
2021-03-06 05:47:37776fc552da154a0f3ddcd193928903deVirustotal results 46 / 69 (66.67%) 31.13.70.1:443
2021-03-06 05:47:37776fc552da154a0f3ddcd193928903deVirustotal results 46 / 69 (66.67%) 31.13.70.1:443
2021-02-26 23:47:5602fc191f86d2af8b1f2803b42c2eac70Virustotal results 50 / 71 (70.42%) 157.240.201.17:443
2021-02-26 23:47:5602fc191f86d2af8b1f2803b42c2eac70Virustotal results 50 / 71 (70.42%) 157.240.201.17:443
2021-02-26 01:08:5995b0c41fbffad6344ae07dd93582c443Virustotal results 40 / 70 (57.14%) 69.171.250.15:443
2021-02-26 01:08:5995b0c41fbffad6344ae07dd93582c443Virustotal results 40 / 70 (57.14%) 69.171.250.15:443
2021-02-25 00:20:04f551d85196beeb5945c2e48a14fdadf5n/a31.13.64.16:443
2021-02-25 00:20:04f551d85196beeb5945c2e48a14fdadf5n/a157.240.201.17:443
2021-02-25 00:20:04f551d85196beeb5945c2e48a14fdadf5n/a31.13.64.16:443
2021-02-25 00:20:04f551d85196beeb5945c2e48a14fdadf5n/a157.240.201.17:443
2021-02-24 09:58:36d248cd2d702bc7988fe9dd41a820fe0dVirustotal results 42 / 70 (60.00%) 157.240.201.17:443
2021-02-24 09:58:36d248cd2d702bc7988fe9dd41a820fe0dVirustotal results 42 / 70 (60.00%) 157.240.201.17:443
2021-02-21 05:20:43a0be572113313130a1b180cd2aa82358Virustotal results 54 / 70 (77.14%) 157.240.17.17:443
2021-02-21 05:20:43a0be572113313130a1b180cd2aa82358Virustotal results 54 / 70 (77.14%) 157.240.17.17:443
2021-02-21 04:15:35a20783d93c9105430e8831166bc9d807Virustotal results 50 / 71 (70.42%) 157.240.201.17:443
2021-02-21 04:15:35a20783d93c9105430e8831166bc9d807Virustotal results 50 / 71 (70.42%) 157.240.201.17:443
2021-02-19 20:04:4869ba966bbb3726208272a4eb02b69c57Virustotal results 44 / 70 (62.86%) 157.240.17.17:443
2021-02-19 20:04:4869ba966bbb3726208272a4eb02b69c57Virustotal results 44 / 70 (62.86%) 157.240.17.17:443
2021-02-07 22:13:0852aae4c278ee18ab06b6c28a8eafa931Virustotal results 41 / 71 (57.75%) 157.240.17.17:443
2021-02-07 22:13:0852aae4c278ee18ab06b6c28a8eafa931Virustotal results 41 / 71 (57.75%) 157.240.17.17:443
2021-02-07 21:46:241dfb214be4a2a9cebdfe9562e28c688bVirustotal results 51 / 70 (72.86%) 69.171.250.15:443
2021-02-07 21:46:241dfb214be4a2a9cebdfe9562e28c688bVirustotal results 51 / 70 (72.86%) 69.171.250.15:443
2021-02-07 21:20:2918adf070247d55ac36a5980fb0b05d7bVirustotal results 46 / 69 (66.67%) 157.240.17.17:443
2021-02-07 21:20:2918adf070247d55ac36a5980fb0b05d7bVirustotal results 46 / 69 (66.67%) 157.240.17.17:443
2021-02-07 21:07:4205a2ee33b36f4165f20c020ef97736f1n/a157.240.17.17:443
2021-02-07 21:07:4205a2ee33b36f4165f20c020ef97736f1n/a157.240.17.17:443
2021-02-06 02:43:445cbf4e70cee15ba43e807c772ff71a57Virustotal results 59 / 70 (84.29%) 31.13.64.16:443
2021-02-06 02:43:445cbf4e70cee15ba43e807c772ff71a57Virustotal results 59 / 70 (84.29%) 31.13.64.16:443
2021-02-06 02:43:435cbf4e70cee15ba43e807c772ff71a57Virustotal results 59 / 70 (84.29%) 157.240.201.17:443
2021-02-06 02:43:435cbf4e70cee15ba43e807c772ff71a57Virustotal results 59 / 70 (84.29%) 157.240.201.17:443
2021-02-02 21:01:1959d54b26e82e2d012f3185ed2e03c64eVirustotal results 46 / 69 (66.67%) 69.171.250.15:443
2021-02-02 21:01:1959d54b26e82e2d012f3185ed2e03c64eVirustotal results 46 / 69 (66.67%) 69.171.250.15:443
2021-01-28 05:08:24582d1101d6e6cfe1738476bb733c5c7dn/a157.240.17.17:443
2021-01-28 05:08:24582d1101d6e6cfe1738476bb733c5c7dn/a157.240.17.17:443
2021-01-27 23:26:002c16d67fe7e55b3db9e9086d94329110n/a185.60.216.15:443
2021-01-27 23:26:002c16d67fe7e55b3db9e9086d94329110n/a185.60.216.15:443
2021-01-27 22:05:001740be47930387f2746979dbb7300ef9Virustotal results 44 / 71 (61.97%) 157.240.201.17:443
2021-01-27 22:05:001740be47930387f2746979dbb7300ef9Virustotal results 44 / 71 (61.97%) 157.240.201.17:443
2021-01-24 23:17:204425e60bdc156c3db86b59f01d43fe79Virustotal results 29 / 69 (42.03%) 157.240.201.17:443
2021-01-24 23:17:204425e60bdc156c3db86b59f01d43fe79Virustotal results 29 / 69 (42.03%) 157.240.201.17:443
2021-01-21 00:12:37216ca87235237ee6ae6d829bdcd2f4d4Virustotal results 43 / 71 (60.56%) 157.240.201.17:443
2021-01-21 00:12:37216ca87235237ee6ae6d829bdcd2f4d4Virustotal results 43 / 71 (60.56%) 157.240.201.17:443
2021-01-18 22:34:326ac8f98d2c5c83e42312d931a87be340n/a157.240.17.17:443
2021-01-18 22:34:326ac8f98d2c5c83e42312d931a87be340n/a157.240.17.17:443
2021-01-18 22:13:344ef43faa3adbf8d4e3c53adde450f996n/a157.240.201.17:443
2021-01-18 22:13:344ef43faa3adbf8d4e3c53adde450f996n/a157.240.201.17:443
2021-01-18 21:56:2243d7b3679f9f651008001b7d270f215fVirustotal results 52 / 71 (73.24%) 69.171.250.15:443
2021-01-18 21:56:2243d7b3679f9f651008001b7d270f215fVirustotal results 52 / 71 (73.24%) 69.171.250.15:443
2021-01-13 22:52:41707eb59213ba0521f571f8323ef227a5n/a157.240.17.17:443
2021-01-13 22:52:41707eb59213ba0521f571f8323ef227a5n/a157.240.17.17:443
2021-01-12 22:20:355c9868179e3eb8462e9a0d5e12397f85n/a157.240.201.17:443
2021-01-12 22:20:355c9868179e3eb8462e9a0d5e12397f85n/a157.240.201.17:443
2021-01-12 22:20:345c9868179e3eb8462e9a0d5e12397f85n/a31.13.64.16:443
2021-01-12 22:20:345c9868179e3eb8462e9a0d5e12397f85n/a31.13.64.16:443
2021-01-12 22:15:405a73bef592342843bea78fd64a149873n/a157.240.201.17:443
2021-01-12 22:15:405a73bef592342843bea78fd64a149873n/a157.240.201.17:443
2021-01-10 20:43:316bf4a0860c22be5051f376ea26f4175cVirustotal results 49 / 70 (70.00%) 157.240.17.17:443
2021-01-10 20:43:316bf4a0860c22be5051f376ea26f4175cVirustotal results 49 / 70 (70.00%) 157.240.17.17:443
2021-01-10 19:29:3638d821fc09f75bcd236241ac99e9d417n/a157.240.17.17:443
2021-01-10 19:29:3638d821fc09f75bcd236241ac99e9d417n/a157.240.17.17:443
2020-12-30 06:27:1759d0ae79c53f5636a4f56775493b1deaVirustotal results 40 / 71 (56.34%) 69.171.250.15:443
2020-12-30 06:27:1759d0ae79c53f5636a4f56775493b1deaVirustotal results 40 / 71 (56.34%) 69.171.250.15:443
2020-12-26 16:58:492972cee58ed974fc8e02e6730f3417daVirustotal results 40 / 70 (57.14%) 69.171.250.15:443
2020-12-26 16:58:492972cee58ed974fc8e02e6730f3417daVirustotal results 40 / 70 (57.14%) 69.171.250.15:443
2020-12-15 01:07:031f19ae4f8277de86bd5db31572f2c2dfn/a69.171.250.15:443
2020-12-15 01:07:031f19ae4f8277de86bd5db31572f2c2dfn/a69.171.250.15:443
2020-12-06 09:52:14beb211923f9d8c600ded60fafbf1cad3n/a185.60.216.15:443
2020-12-06 09:52:14beb211923f9d8c600ded60fafbf1cad3n/a185.60.216.15:443
2020-12-04 09:08:32e02d605a15592184628007e0e6a378f0Virustotal results 51 / 70 (72.86%) 157.240.201.17:443
2020-12-04 09:08:32e02d605a15592184628007e0e6a378f0Virustotal results 51 / 70 (72.86%) 157.240.201.17:443
2020-11-26 09:31:002c6d407c29b549d0f9ac18e594657b9cVirustotal results 47 / 72 (65.28%) 31.13.70.5:443
2020-11-26 09:31:002c6d407c29b549d0f9ac18e594657b9cVirustotal results 47 / 72 (65.28%) 31.13.70.1:443
2020-11-26 09:31:002c6d407c29b549d0f9ac18e594657b9cVirustotal results 47 / 72 (65.28%) 31.13.70.5:443
2020-11-26 09:31:002c6d407c29b549d0f9ac18e594657b9cVirustotal results 47 / 72 (65.28%) 31.13.70.1:443
2020-03-29 19:14:456983ad9c106dc7b8052c63c52270266fn/a52.233.189.178:443
2020-03-29 19:14:456983ad9c106dc7b8052c63c52270266fn/a52.233.189.178:443
2020-03-14 16:48:031136b0aea806289da18041cb3af26aeen/a52.233.189.178:443
2020-03-14 16:48:031136b0aea806289da18041cb3af26aeen/a52.233.189.178:443
2020-03-04 14:40:586bc3b81c1fab85abf87e29aaf98d3712n/a52.233.189.178:443
2020-03-04 14:40:586bc3b81c1fab85abf87e29aaf98d3712n/a52.233.189.178:443
2020-02-24 15:02:10e914fb98bc6c4d1e6c9fddb335bfbd55n/a31.13.92.10:443
2020-02-24 15:02:10e914fb98bc6c4d1e6c9fddb335bfbd55n/a31.13.92.10:443
2020-02-07 07:44:15e9858a6d0b082cf51cfa898a5512d3c5n/a31.13.64.16:443
2020-02-07 07:44:15e9858a6d0b082cf51cfa898a5512d3c5n/a31.13.64.16:443
2020-01-29 19:05:2973f2a9009088d6956a29c4037238e01an/a157.240.11.17:443
2020-01-29 19:05:2973f2a9009088d6956a29c4037238e01an/a157.240.11.17:443
2020-01-23 15:26:59228aa3226df390a5dbf602fecdf2e414n/a31.13.92.10:443
2020-01-23 15:26:59228aa3226df390a5dbf602fecdf2e414n/a31.13.92.10:443
2020-01-07 02:26:08a49869dff1d93f0f5db1856195674ddcn/a31.13.70.1:443
2020-01-07 02:26:08a49869dff1d93f0f5db1856195674ddcn/a31.13.70.1:443
2020-01-05 21:02:51a9f00889009fbb4ca5328642a46567f0n/a31.13.70.1:443
2020-01-05 21:02:51a9f00889009fbb4ca5328642a46567f0n/a31.13.70.1:443
2019-12-30 11:15:03a102a979e0af9eda56cb891834290244Virustotal results 51 / 72 (70.83%) 31.13.64.16:443
2019-12-30 11:15:03a102a979e0af9eda56cb891834290244Virustotal results 51 / 72 (70.83%) 31.13.64.16:443
2019-12-22 17:29:58ad5b4ad0548e262d053406b3be0337f8n/a31.13.64.16:443
2019-12-22 17:29:58ad5b4ad0548e262d053406b3be0337f8n/a31.13.64.16:443

# of entries: 100 (max: 100)