JA3 Fingerprints

You can find further information about the JA3 fingerprint df5c30e670dba99f9270ed36060cf054, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:df5c30e670dba99f9270ed36060cf054
First seen:2017-07-20 17:44:07 UTC
Last seen:2018-04-11 15:57:59 UTC
Status:Blacklisted
Malware samples:72
Destination IPs:23
Malware:Tofsee -
Listing date:2018-11-14 12:41:48

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2018-04-11 15:57:59d3ad89a56c6c2f01cd118766e0953de0Virustotal results 38/67 (56.72%) 136.243.102.167:443
2018-04-10 23:43:23e4dfbbef6ba6882ac2f58396d26d66e6Virustotal results 14/67 (20.90%) 136.243.102.154:443
2018-02-08 21:57:40b4dba2e2abaa3fd8065efa1bc81ee789Virustotal results 43/68 (63.24%) 2.19.77.81:443
2018-02-02 17:59:07d9a7d58c32a653804fd07eb9dbd0a525Virustotal results 25/67 (37.31%) 136.243.102.154:443
2018-01-31 19:14:2906c50214a4969953230ba3bca68c24a8Virustotal results 34/66 (51.52%) 88.99.142.163:443
2018-01-28 10:59:131c1eca06b5120575b5ffc88563cf6d4bVirustotal results 40/66 (60.61%) 88.99.142.163:443
2018-01-28 08:53:311529ad484ef9b2988e9a2d87b5db271cVirustotal results 11/64 (17.19%) 136.243.102.167:443
2018-01-27 23:22:27e5e68b77b689ffb31743f444af38bdb0Virustotal results 29/65 (44.62%) 136.243.102.154:443
2018-01-26 11:49:42a0d0bb16e6be75344535c318ff43243dVirustotal results 16/65 (24.62%) 94.130.143.162:443
2018-01-25 18:03:02d20a434c4623389a6badc01392962d22Virustotal results 21/66 (31.82%) 88.99.142.163:443
2018-01-25 05:31:22ed1f71cf6b771ba7246059b253684c03Virustotal results 26/67 (38.81%) 136.243.102.154:443
2018-01-22 19:26:32fcb0198de66ed257c0b4e2cc6be0427bVirustotal results 16/66 (24.24%) 88.99.142.163:443
2018-01-22 05:51:494b8ad84fe0d107036e2d4ed84c77408bVirustotal results 23/66 (34.85%) 136.243.102.154:443
2018-01-19 06:19:44f84bf49eab7ece9b4686a629025b2ac4Virustotal results 36/67 (53.73%) 94.130.143.162:443
2018-01-09 20:02:21f000a0a8ed40c8a24a2ff81442a519f2Virustotal results 28/68 (41.18%) 136.243.102.154:443
2018-01-07 05:23:26e1002b684f3e12a614fddd04d26c8c3cVirustotal results 20/68 (29.41%) 88.99.142.163:443
2017-12-11 10:47:502d852e408fd5638085162842af04cf3dVirustotal results 14/68 (20.59%) 104.25.50.101:443
2017-11-27 20:25:2970516841168f00862d7069732563d5d5Virustotal results 45/68 (66.18%) 104.25.50.101:443
2017-11-23 07:42:59d89acfa4fe201c6475f2cd8928060867Virustotal results 42/67 (62.69%) 2.17.227.183:443
2017-11-14 03:43:2265a7ec07a87f60705f47491db930e61cVirustotal results 9/68 (13.24%) 104.25.49.101:443
2017-11-14 02:34:086f6c6600531dfe15428ea47180e1ffa7n/a104.25.50.101:443
2017-11-13 13:05:03c5259f658191061d01f699af9fcee95eVirustotal results 14/68 (20.59%) 104.25.50.101:443
2017-11-13 13:04:34fdc5f21287145d0623a0bc3336f0a860Virustotal results 40/64 (62.50%) 104.25.49.101:443
2017-11-13 09:53:203d3073713a4d00477a4bb5c5663a266cn/a104.25.49.101:443
2017-11-13 08:19:18696084e07c70ff92dac6209ecfbfe09fVirustotal results 20/68 (29.41%) 104.25.49.101:443
2017-11-07 20:06:144e88ed99630e0153553ca0883e3158cbVirustotal results 14/68 (20.59%) 23.43.120.11:443
2017-10-30 07:55:07bee7480ef9a4f36cd1c01b3708c7493bVirustotal results 16/67 (23.88%) 23.201.250.90:443
2017-10-30 06:41:57f867893568fa7dab3fafa861f528c737Virustotal results 38/67 (56.72%) 92.122.65.18:443
2017-10-06 15:13:2307e7aaa178803206b6733581a392fdbcVirustotal results 41/66 (62.12%) 184.86.225.137:443
2017-10-05 17:14:1028ccbfc435d07801929b17e8e3544d75Virustotal results 31/66 (46.97%) 184.86.225.137:443
2017-09-29 07:21:30a0bdb6e9fe96ed131ad9411b815c2519Virustotal results 23/65 (35.38%) 104.124.128.162:443
2017-09-26 17:45:57a1e0d7039a14a13505dbc7553e0024c1Virustotal results 27/65 (41.54%) 104.124.128.162:443
2017-09-26 16:07:13585c5240556fed7386bca11084f1bf27Virustotal results 43/66 (65.15%) 104.124.128.162:443
2017-09-25 16:45:109fda0bf0ddab9fdc7f34bea60b7bbadfn/a104.124.128.162:443
2017-09-25 14:17:57bfde71425d2d22eb7b4a8be143f40f95Virustotal results 30/64 (46.88%) 104.124.128.162:443
2017-09-25 14:17:56196fc3b5861a607f838a37aa3d42e1b7Virustotal results 52/66 (78.79%) 104.124.128.162:443
2017-09-25 14:15:2606ba0ea8063ca50aae2d8468ba9ad058Virustotal results 39/66 (59.09%) 104.124.128.162:443
2017-09-25 14:09:054df49372d195f604caa6da3a7c2646e9Virustotal results 45/64 (70.31%) 104.124.128.162:443
2017-09-25 14:02:587d298e7e13228e0915cef89ba27ed848n/a104.124.128.162:443
2017-09-25 14:01:514e4b4c7f74ff434d7aa8f440cb55ee09n/a104.124.128.162:443
2017-09-25 02:48:435b713333699bc039ed1dce9b42c97267n/a104.124.128.162:443
2017-09-24 13:40:5824e89362241a2cd5d010d52ad844af4dVirustotal results 38/65 (58.46%) 104.124.128.162:443
2017-09-24 09:54:24defb62f72f12a536c311a7d39f576f8aVirustotal results 31/64 (48.44%) 23.43.120.11:443
2017-09-24 09:54:24defb62f72f12a536c311a7d39f576f8aVirustotal results 31/64 (48.44%) 104.124.128.162:443
2017-09-23 02:43:3555a13e60a5bb247955e08d018c018134Virustotal results 40/65 (61.54%) 95.100.49.148:443
2017-09-22 19:20:005d98ba1272a17e932af656df3c308830n/a104.94.20.152:443
2017-09-21 05:00:44a3d78caedb739e57633d4be691a8190eVirustotal results 37/65 (56.92%) 2.19.77.81:443
2017-09-20 20:03:06b96eace2e786e64f46279773530f1ddbn/a192.81.241.100:443
2017-09-20 17:18:2072c606b0d9ad5a839a44d43e20a5158bn/a104.109.107.107:443
2017-09-20 15:25:50fefb7a19262164e1185e6ca27fe7813cn/a104.94.20.152:443
2017-09-20 11:50:5391eebe1419d3bc2f2838f7cf835d9aden/a104.94.20.152:443
2017-09-20 11:25:49c9395284572f6e4e7c9cc86d69bfa36cn/a104.94.20.152:443
2017-09-20 10:32:04daba0b388f4d42647f8b2b47633ca158n/a95.100.49.148:443
2017-09-20 10:00:02b4fdc705e57bb29563f10a2eff0f9572Virustotal results 31/65 (47.69%) 95.100.49.148:443
2017-09-20 09:35:17ffa374960e541328f7067e0082443b62Virustotal results 36/64 (56.25%) 95.100.49.148:443
2017-09-20 08:28:31ade9891596256aeae69c92e25cf1fbe1Virustotal results 34/64 (53.12%) 104.108.66.58:443
2017-09-20 06:20:22c8bd75f01a010e1952be80a3dcc8e75fVirustotal results 45/63 (71.43%) 104.108.66.58:443
2017-09-20 06:19:3888ff5eaa382df8b6f2f76c45c10373can/a2.19.77.81:443
2017-09-20 03:20:4504171df4a5979e4933b612d08f0b3270n/a104.109.107.107:443
2017-09-18 20:57:15f4ed35ee55a6e4aabb0ddbb62c65198bVirustotal results 36/65 (55.38%) 104.81.104.99:443
2017-09-18 19:05:4828c9503622aa0d8b56e75a535770c5bcVirustotal results 43/65 (66.15%) 104.81.104.99:443
2017-09-18 07:42:05cf2cd3565a1c4da370ff5a7df166a8bdn/a23.35.100.45:443
2017-09-17 01:21:47c9b5685587f9edc0e9cd57f895fceb25n/a104.81.104.99:443
2017-09-16 00:45:372542415c51e2907923d8e173caace677Virustotal results 41/64 (64.06%) 2.19.77.81:443
2017-09-12 18:50:56cc08348bc863bec7f9ddcd61c11c8337Virustotal results 38/65 (58.46%) 23.62.133.237:443
2017-09-10 00:55:0088d21a7d7585a9b58cd1da00db35e881Virustotal results 36/64 (56.25%) 2.17.227.183:443
2017-09-09 15:46:01ddc8b1f6977c7e29131bc4da82dd4933Virustotal results 20/64 (31.25%) 104.81.104.99:443
2017-09-07 21:45:533c22876c161c0fc69d744ca90f684781n/a104.87.42.240:443
2017-08-20 00:34:210b8fa018b48ddaa63836f5278641791cn/a2.19.77.81:443
2017-07-31 03:07:53a08f9825cc37302ec9dde5a124d29789Virustotal results 10/64 (15.62%) 104.81.112.201:443
2017-07-28 20:09:05b22f883ef7eb371851e248a88e298f38Virustotal results 11/65 (16.92%) 184.86.225.137:443
2017-07-23 15:17:0990f5220aa4498f0e0cce69cc80fc1482Virustotal results 35/64 (54.69%) 104.81.112.201:443
2017-07-20 17:44:07859d8f0798520295b6d7e1784d6ffdcaVirustotal results 11/62 (17.74%) 104.81.112.201:443

# of entries: 73 (max: 100)