JA3 Fingerprints

You can find further information about the JA3 fingerprint da949afd9bd6df820730f8f171584a71, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:da949afd9bd6df820730f8f171584a71
First seen:2018-02-03 05:19:37 UTC
Last seen:2020-03-29 19:14:45 UTC
Status:Blacklisted
Malware samples:196
Destination IPs:21
Malware:Tofsee -
Listing date:2020-01-09 14:28:57

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2020-03-29 19:14:456983ad9c106dc7b8052c63c52270266fn/a52.233.189.178:443
2020-03-14 16:48:031136b0aea806289da18041cb3af26aeen/a52.233.189.178:443
2020-03-04 14:40:586bc3b81c1fab85abf87e29aaf98d3712n/a52.233.189.178:443
2020-02-24 15:02:10e914fb98bc6c4d1e6c9fddb335bfbd55n/a31.13.92.10:443
2020-02-07 07:44:15e9858a6d0b082cf51cfa898a5512d3c5n/a31.13.64.16:443
2020-01-29 19:05:2973f2a9009088d6956a29c4037238e01an/a157.240.11.17:443
2020-01-23 15:26:59228aa3226df390a5dbf602fecdf2e414n/a31.13.92.10:443
2020-01-07 02:26:08a49869dff1d93f0f5db1856195674ddcn/a31.13.70.1:443
2020-01-05 21:02:51a9f00889009fbb4ca5328642a46567f0n/a31.13.70.1:443
2019-12-30 11:15:03a102a979e0af9eda56cb891834290244Virustotal results 51 / 72 (70.83%) 31.13.64.16:443
2019-12-22 17:29:58ad5b4ad0548e262d053406b3be0337f8n/a31.13.64.16:443
2019-12-20 12:30:29ab571d63c7404ba8ef547ed4431d38a8n/a157.240.21.16:443
2019-12-13 05:15:260a4f126107a05e2c27bd07ef48743232n/a157.240.21.16:443
2019-12-10 07:44:53ab7a1afe4a58ec48bc68b7fc00e59f5cn/a31.13.70.1:443
2019-12-09 04:15:04a2fb434588ebde780f4d56cd28b61c5aVirustotal results 52 / 72 (72.22%) 157.240.21.16:443
2019-12-09 03:45:580e460fc7ef8cd48cfb31e9f3ec541915n/a185.60.216.15:443
2019-12-05 20:28:4852d5261669d22cf9b9441511b46a6e4cVirustotal results 50 / 68 (73.53%) 157.240.21.16:443
2019-12-05 10:26:3049f2c2ceec9a55ec72a4d16bbc6139b2n/a31.13.90.2:443
2019-12-05 08:53:00fbf13b757be560670428923282ce840aVirustotal results 51 / 68 (75.00%) 157.240.20.15:443
2019-12-04 14:31:33c7761a93a0e140924c08e534b413e05cn/a157.240.11.17:443
2019-12-04 12:43:0627c14a5b0caba8d87c610d6d9c19d164n/a157.240.1.18:443
2019-12-03 13:12:11191d237c653eaf713c8208e9525a3329n/a185.60.216.15:443
2019-12-02 07:02:54b514f7ea6fd5a3c569e7e5122bb86fe2n/a157.240.21.16:443
2019-12-02 05:16:587f5c85f996a215923e84516266e71950n/a157.240.20.15:443
2019-11-29 14:37:257100cbbc57e68aa5261880d470d7b3cfVirustotal results 37 / 71 (52.11%) 157.240.11.17:443
2019-11-28 09:28:446445c76b4dd96a6fc4a24f3e7d9b8ec0n/a157.240.201.17:443
2019-11-27 16:58:31328d08e49c2fb776b9a2b4cc5b1f2549n/a157.240.21.16:443
2019-11-24 14:55:13a8fc52351fff07bb94f718c8c33f079cn/a157.240.21.16:443
2019-11-24 02:14:255b72a40febed89a2fc9d7f788b247f6fn/a31.13.81.9:443
2019-11-17 20:34:396b1f6104d51e3a9700fb1d929517c1c1Virustotal results 16 / 71 (22.54%) 157.240.20.15:443
2019-11-17 20:34:396b1f6104d51e3a9700fb1d929517c1c1Virustotal results 16 / 71 (22.54%) 185.60.216.15:443
2019-11-16 06:28:053236491a074129ee3ca1c947cb5d4e3fn/a157.240.20.15:443
2019-11-16 06:28:043236491a074129ee3ca1c947cb5d4e3fn/a185.60.216.15:443
2019-11-16 02:58:19fa321d4a0a5ffc16a9c01585e854386cn/a157.240.30.18:443
2019-11-12 10:10:041209ac4b347d1d5085f809b9a94c3d1bn/a185.60.216.15:443
2019-11-08 22:30:361ce1c0176cfe84808d70626f77e14130Virustotal results 54 / 71 (76.06%) 31.13.64.16:443
2019-11-07 11:47:573dec3b2403f95b3c807467c5c52c34a7n/a185.60.216.15:443
2019-11-06 09:10:372f2347cfc3573bb3cde73e1b2be91254n/a31.13.64.16:443
2019-11-06 09:05:59ecef373e4ede177713d67966099e388dn/a31.13.64.16:443
2019-11-04 13:00:0942469c9e93198487ba3aa7f631863b87n/a31.13.64.16:443
2019-11-04 12:43:486894e47b835e04b8676a24e0441ef092n/a157.240.20.15:443
2019-11-04 10:24:4812aba5a69afd70509f18fdcfc580b1bdn/a31.13.86.8:443
2019-11-04 10:01:3253ce967a92e6ba219a25b4189f5fd2e6n/a31.13.86.8:443
2019-11-03 10:27:413cb7d62f9d29d3d844be88b9eaeb7b56Virustotal results 25 / 70 (35.71%) 31.13.92.10:443
2019-11-03 03:19:13d8dc780a873d5bc30214938e6c23f8b3Virustotal results 45 / 71 (63.38%) 31.13.81.9:443
2019-10-31 10:03:16d56528d9bd44f4095d29f9d23304dce4Virustotal results 26 / 65 (40.00%) 31.13.64.16:443
2019-10-30 07:59:0207609992a98a0c5afb5fb21e6cf91ca6n/a185.60.216.15:443
2019-10-30 07:42:563865c8631f8c83f1459bcba8421d48bdn/a31.13.64.16:443
2019-10-30 05:44:38c6e407084c00793efde802124937da44n/a31.13.64.16:443
2019-10-30 05:03:09000d36797007466b97faad5f93cf6a09n/a157.240.20.15:443
2019-10-28 14:03:19950ee688de575fe3ead79750c1020a64Virustotal results 41 / 67 (61.19%) 185.60.216.15:443
2019-10-28 01:34:2314c9832f3f02bf865b400f39dba65d2en/a157.240.1.18:443
2019-10-28 01:34:208436649d2481604ce126d74440eb5004n/a157.240.11.17:443
2019-10-28 01:34:02fe3f9787da17d00753c75673776fd42en/a185.60.216.15:443
2019-10-27 13:46:36a3a7d50ca1b7cb3d2889372bab6afdafn/a185.60.216.15:443
2019-10-26 08:15:38cc8a66088fdfa389961a5a9bfbfbee08n/a31.13.86.8:443
2019-10-25 18:42:449daa43e736c4eedbb3b1adaca7851e01n/a31.13.86.8:443
2019-10-25 18:42:449daa43e736c4eedbb3b1adaca7851e01n/a185.60.216.15:443
2019-10-25 17:19:4500b29592ef22b361a6f7d0249d3f841aVirustotal results 33 / 69 (47.83%) 157.240.201.17:443
2019-10-25 16:34:002b760a45185076794cfcef68f9dbd804n/a31.13.86.8:443
2019-10-24 11:00:051c302d00e1d071cf0fc35cacb2990d03n/a185.60.216.15:443
2019-10-24 10:34:45b8f7bdcc16f842c722fac59cd969eea8n/a157.240.20.15:443
2019-10-21 13:25:35f4dc8e0493620ecf1325a7920cde3280Virustotal results 20 / 70 (28.57%) 31.13.70.1:443
2019-10-21 13:07:034e7dd906454ac4225ff626bc05589b5cn/a31.13.86.8:443
2019-10-21 13:00:270fd08982c3f08259a8def98f7136ef79n/a31.13.64.16:443
2019-10-21 12:54:50691b093195d7fd372576cc820a94e5f6n/a185.60.216.15:443
2019-10-21 10:40:511e06fba7666d65760f3347251ff24cd1n/a31.13.70.1:443
2019-10-21 09:38:41b976b47bbc53322860a369005315aae9n/a31.13.64.16:443
2019-10-21 09:38:39b976b47bbc53322860a369005315aae9n/a157.240.201.17:443
2019-10-21 09:17:3623a51563ccb8e20f7b98c3cb417280f5n/a31.13.86.8:443
2019-10-21 07:38:023ebc98da5c73bc386c5a6b5867036622n/a31.13.64.16:443
2019-10-21 07:26:46f051e3a417ca4a3fc7cf99c0c6815a18n/a31.13.64.16:443
2019-10-20 12:44:270231430212fcc8488c1f6549806cc30bn/a185.60.216.15:443
2019-10-20 12:37:36f0047c004d35b0512f7d1776e62b2478n/a185.60.216.15:443
2019-10-20 12:25:096cf0ddc077225e618dae2dee3ccb1932n/a31.13.64.16:443
2019-10-20 12:22:01767d66770c752eac63c34a1c78ae94c5n/a31.13.86.8:443
2019-10-19 12:07:481e99bac7f8f794697dd8db6c106db622n/a31.13.64.16:443
2019-10-18 14:44:37a3c103e37f1b563cb946f5648774800bn/a31.13.86.8:443
2019-10-18 11:03:47a0768a84dc9daea3f04798f332ccf58cn/a31.13.70.1:443
2019-10-18 10:58:54cf5da654b44384d47095e7aa13dca2fen/a31.13.86.8:443
2019-10-18 10:53:32e08523fa74d33cc020d77182ca3a401en/a31.13.64.16:443
2019-10-18 10:40:36e3de3080a9d4ff2411ce996b2c514cb0Virustotal results 49 / 70 (70.00%) 31.13.64.16:443
2019-10-16 23:03:1704bf6236f4168171c86fbeef62258e80n/a31.13.92.10:443
2019-10-16 22:58:27cd23363a39718038189b4b29ed902230n/a157.240.21.16:443
2019-10-16 22:49:09f5bc34142b36b74a5bfc25361706867dVirustotal results 49 / 68 (72.06%) 31.13.64.16:443
2019-10-13 21:25:00e10a1948140fb67565cd26c24fd9b8f6n/a185.60.216.15:443
2019-10-13 08:03:22d15f8a8c8c3983a551f8ed4437f5f75fVirustotal results 43 / 67 (64.18%) 31.13.64.16:443
2019-10-13 08:03:21d15f8a8c8c3983a551f8ed4437f5f75fVirustotal results 43 / 67 (64.18%) 157.240.201.17:443
2019-10-13 02:32:42c0877bc3574692c689b3eb0a358fb62eVirustotal results 30 / 64 (46.88%) 31.13.86.8:443
2019-10-11 00:18:2547ed3c419a09a4f19116f08157fc2975n/a185.60.216.15:443
2019-10-10 23:48:158461311fb0d45f3e7700ae7d236371deVirustotal results 48 / 70 (68.57%) 157.240.201.17:443
2019-10-10 23:48:148461311fb0d45f3e7700ae7d236371deVirustotal results 48 / 70 (68.57%) 31.13.64.16:443
2019-10-09 03:06:10a99353f586b29b6679ca3ccc1377c029n/a31.13.64.16:443
2019-10-05 18:42:45940ce6c481febb3437f391dfd6a3daa9n/a31.13.86.8:443
2019-10-05 18:38:542d43860752c8f2d8f800cadf8da52222n/a185.60.216.15:443
2019-10-03 22:03:30d4b1672fffa85cd40db6504f4843f5e3n/a185.60.216.15:443
2019-10-01 11:51:577ddd5d8f6024d20aed631cc64085ff09n/a185.60.216.15:443
2019-09-28 03:04:16fefa5abf86bdc92c689c27a54696969fn/a95.213.181.2:443
2019-09-27 17:47:57a166d32bd12b51db580bc47577eac591n/a157.240.201.17:443
2019-09-27 17:47:54a166d32bd12b51db580bc47577eac591n/a31.13.64.16:443

# of entries: 100 (max: 100)