JA3 Fingerprints

You can find further information about the JA3 fingerprint decfb48a53789ebe081b88aabb58ee34, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:decfb48a53789ebe081b88aabb58ee34
First seen:2018-12-21 09:06:16 UTC
Last seen:2019-03-21 13:17:45 UTC
Status:Blacklisted
Malware samples:89
Destination IPs:56
Malware:Adwind
Listing date:2018-12-31 07:25:54

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2019-03-21 13:17:45e70f134a0ef0853102b0ced7bafe00d1n/a192.3.24.248:3478
2019-03-21 11:21:209cc9ea9cc174d0ac3bfec904bfc1ef8en/a31.171.152.105:3602
2019-03-20 07:59:435884fcc02258bfd0795b84d0c2d98bd1n/a178.239.21.143:9801
2019-03-19 15:59:28156bc4e68e98c20a0714d5a555e92692n/a178.239.21.105:1955
2019-03-18 02:15:256dd5b03e63bc66d34df1eafe6780ac0dVirustotal results 2/57 (3.51%) 91.192.100.47:8332
2019-03-14 14:23:134f81a1af4dafcd38603614324f5a3fcdVirustotal results 13/57 (22.81%) 91.192.100.6:5050
2019-03-14 05:53:35f99ddbc03352cd00486dc5cb0b3e7ab9Virustotal results 15/57 (26.32%) 91.192.100.6:12201
2019-03-14 00:24:022b8327e704baff259d2ed738b5dc1d2fVirustotal results 3/59 (5.08%) 91.192.100.47:8332
2019-03-13 09:36:433dec8184bc92412a369adeb2489ea2d0n/a173.46.85.73:2556
2019-03-12 14:58:25c88ab40de73641f1b9b5bc6c6fe3cafen/a194.5.98.172:7788
2019-03-12 01:51:02334fa56a11dff73fc372e77d756f488dn/a5.135.43.178:4000
2019-03-11 06:59:1988d354c93a8b10f18dd177b4c4c39636n/a194.5.99.195:5244
2019-03-10 23:44:31f89d541137734b87084684cdfc99c3cfn/a194.5.99.71:5244
2019-03-05 04:08:0809d526fe4829495284a9fd67863f1ca8n/a178.239.21.105:1955
2019-03-03 23:38:4527de63eac9429062981fe858b9b0bfd1n/a31.171.152.106:2522
2019-03-01 10:20:56a3f7263870c0d518a31243e041fe1978Virustotal results 15/53 (28.30%) 185.236.203.181:4040
2019-02-25 02:53:512ed3aa66274af579f704edab87ce63c3n/a185.236.203.60:6767
2019-02-21 14:14:10acce3f9b99e017132d96702152e6d972Virustotal results 14/54 (25.93%) 185.236.203.181:4040
2019-02-21 09:41:3136dab64daaad5d5a2aaea9ed2242bfd0n/a185.165.153.106:5888
2019-02-19 05:32:28751c710b110a044dbfce9c1fc5a5caadn/a185.236.203.142:1717
2019-02-18 12:11:16d97f58aa8612347c4012833a23c27d65n/a91.192.100.14:1130
2019-02-18 07:51:104a433941f27f3c3257360684f98d4e7fn/a31.171.152.107:1966
2019-02-17 07:35:24df1e98a3d8554a1dd76c1f36cc8a4e22Virustotal results 10/59 (16.95%) 108.170.60.189:1010
2019-02-15 19:05:0534d3aa4f6e2bb22a0f2ca97d09c53e9dn/a185.244.30.120:1130
2019-02-15 14:18:51925a02c1f9a075aa1e03e7875becf57eVirustotal results 41/58 (70.69%) 5.206.225.115:5000
2019-02-13 07:59:114bee364cfee34530f32c8a7637542350n/a185.244.30.93:9888
2019-02-12 22:29:44395710e861c8a5426dde4b668cf08b16n/a194.5.99.194:1010
2019-02-12 09:25:32fcb66383a84f75213bd029d65c8c400en/a194.5.99.63:2556
2019-02-12 04:17:217429a2de61551f6f8166aae6c5f3695bn/a194.5.99.63:2556
2019-02-11 09:17:5575c76e5f5f97e5bee13b0285006db721n/a173.46.85.19:1996
2019-02-10 23:54:55455601273dbdd3ff017db1d42d0b459fVirustotal results 18/59 (30.51%) 23.227.207.244:1010
2019-02-10 01:50:0664771c2adefe0e5325b57e05977cc4e3Virustotal results 18/57 (31.58%) 185.236.203.60:6767
2019-02-08 06:18:106807f7cd0ea9aba975f87e58935c94dcn/a185.156.174.115:19741
2019-02-07 06:54:571158087ea236ae4ac66e5b13a32432ccn/a194.5.99.2:1995
2019-02-06 14:21:02ccbf019a6dd9768ec951e9b5d1a6e40cn/a194.5.99.63:2556
2019-02-06 14:04:23c3626916e68ac613e3f06634d98ff79an/a194.5.99.7:9000
2019-02-05 17:59:09dfaf552bcd45c7e6929d698f474b2579n/a144.76.215.117:5050
2019-02-05 17:46:41195d2565459b9805b3dcf0364d8fb071Virustotal results 3/59 (5.08%) 144.76.215.117:5050
2019-02-05 10:59:42d0ee8dec080edfe587b65c992f32e44an/a185.244.30.101:1985
2019-02-05 08:47:09c337d1332e6b664545501b9a64a87e36Virustotal results 3/60 (5.00%) 194.5.99.226:1785
2019-02-04 14:47:231b3b8d25df1ed1a93f4f578cd8e0225dVirustotal results 3/59 (5.08%) 185.244.30.101:1985
2019-02-04 09:43:3729047ad7b5e54a28ca29ff9fa63197f2n/a31.171.152.105:8892
2019-02-04 07:23:4957861e71cd315d1ed10a0ddbeeb7abe6n/a31.171.152.106:1313
2019-02-02 12:53:26971ba4e12660ffe3bee39aca9594521fn/a31.171.152.105:2888
2019-02-02 06:03:2772d04333cf384e3ef3fcfaf3133b6578n/a185.203.118.6:1010
2019-02-02 03:36:4083022d9ab21b4b39214131f053adde24n/a185.203.118.6:1010
2019-02-02 02:21:00f816f302aefb315d1f4f46f1327eeb27n/a185.203.118.6:1010
2019-02-02 02:21:00f816f302aefb315d1f4f46f1327eeb27n/a185.203.118.6:1020
2019-02-02 01:45:37c9d0360cc071760571d01f5b7e50feb1n/a212.73.150.215:1010
2019-02-02 01:38:3279d28614eb0879bc061da8ca271ea911Virustotal results 15/60 (25.00%) 185.141.62.213:1020
2019-02-02 01:38:3279d28614eb0879bc061da8ca271ea911Virustotal results 15/60 (25.00%) 185.141.62.213:1010
2019-02-01 14:28:522437949cc566bbe41ec7df6bd3ea3175n/a194.5.99.207:2888
2019-02-01 10:02:03617e0cce180652c8c5aed8d51affe1d6Virustotal results 7/60 (11.67%) 31.171.152.105:2888
2019-02-01 06:08:071f6b636c6cede877d244b23b69383525Virustotal results 10/60 (16.67%) 194.5.99.159:2121
2019-01-29 09:06:566690f78e7eef4d8714554c2d6f36f06bn/a185.244.30.101:1985
2019-01-29 08:12:227360b5bb80279841e7f024ae6ae41106n/a185.244.30.106:7799
2019-01-29 08:02:139b2a685e76f7c8c56ce79d85842adf45n/a185.244.30.106:7799
2019-01-29 08:01:491ee0c9c1e05d0b230e5eedc6fbba2c97n/a31.171.152.105:2888
2019-01-28 12:39:34610ef78f71c8c35846ce8fd5cd5d34deVirustotal results 7/59 (11.86%) 31.171.152.105:2888
2019-01-28 11:02:03ec53d8a2cd5812d8786d262fceaa4c71n/a185.125.205.78:8088
2019-01-28 09:48:310d393bf5770353056074d77f7cbaf861n/a185.244.30.113:7328
2019-01-27 16:40:204143f869cb0eb0896adc0ab7c4144bdfVirustotal results 20/58 (34.48%) 94.185.86.56:4000
2019-01-26 07:52:59f11f90324006b4e3c586e0d1a7a45f87n/a103.89.88.88:8898
2019-01-25 11:23:49def325c85b49491ec143d19d8b308025n/a31.171.152.105:2888
2019-01-25 07:01:24f4923886b3b5025d3727f7fdb0027737n/a212.73.150.215:1010
2019-01-24 08:06:4152593fea250ddd911398f98740304608n/a185.244.30.93:9888
2019-01-24 04:54:19172a820ce488df6c2d810fda4222d29fn/a213.152.161.138:55314
2019-01-23 09:44:34a3db6856c13795b0cdcdfd0d2bb52e94n/a46.183.220.12:7777
2019-01-23 09:23:35b48eec60c46a70108fa5b065dc1f34e7n/a103.89.88.88:8898
2019-01-23 02:00:324fa5953ee66badd9aba2b7f69ce0dffen/a185.125.205.78:8088
2019-01-22 11:45:198264a097cc03f82983cde03998a4b753Virustotal results 15/55 (27.27%) 103.89.88.88:8898
2019-01-22 10:05:23cf57d16645e62b13e151bf1abd4ba324n/a31.171.152.105:2888
2019-01-21 23:21:15d1105f252415010c0885addf80f6581cn/a46.183.223.10:7650
2019-01-21 09:18:41917bc68584fb2905ab7f2931254538a5n/a194.5.99.250:683
2019-01-21 09:08:19509837fb8b59228fc837527f6de47239n/a194.5.99.97:683
2019-01-21 07:38:10ab8ef4331edd4dd15e40763e0a4e2acfn/a31.171.152.105:2888
2019-01-21 07:35:193fea51c0db1709c7e459f7c9ff16d890n/a194.5.99.175:2112
2019-01-21 07:22:57d5cd7c3715cc211d1b6422382c746b67Virustotal results 4/58 (6.90%) 194.5.99.175:2112
2019-01-21 01:24:12c1a77fc9c9d2cb540432f36709524604n/a185.125.205.78:8088
2019-01-20 17:59:08c254a8737cef5fb2a3975b25f792b559n/a212.47.194.15:8898
2019-01-20 09:30:1237e2675feb16122a086bfdd37f2240fdVirustotal results 14/60 (23.33%) 195.123.212.149:4000
2019-01-19 19:33:15bc9787320c03d20f442cd8a03aac00dan/a173.254.223.115:3333
2019-01-16 09:12:55384abb38727a716c96914360b2883161Virustotal results 6/60 (10.00%) 31.171.152.106:1313
2019-01-15 22:20:16dc7121d7b2f979e7280710f3bc27c433n/a194.5.99.63:2556
2019-01-12 14:02:041fbfdefbdc0bd63eadd14b472fa9e667Virustotal results 6/58 (10.34%) 51.38.133.245:7777
2019-01-07 14:15:14d603a2e22566e434fbfe5b01e120ca8fVirustotal results 15/61 (24.59%) 181.215.247.224:9620
2019-01-04 07:27:10494eeb95f2894b4a477b4d38e56cee3eVirustotal results 23/59 (38.98%) 31.171.152.106:2522
2019-01-02 17:24:37422b85db857ea8bb41286273ef58d547n/a94.156.189.60:1010
2019-01-02 17:24:37422b85db857ea8bb41286273ef58d547n/a94.156.189.60:1020
2018-12-26 11:11:0464a229ddc5e01626b42c0327bd7a100eVirustotal results 10/59 (16.95%) 147.135.165.107:7777
2018-12-21 12:25:36abd43554b9b9e6dbc12e14dba7679f0bn/a188.215.229.26:3388
2018-12-21 09:06:1617dc7f3bac83c0f7673f26a2d81b726cn/a194.5.99.175:2112

# of entries: 92 (max: 100)