JA3 Fingerprints

You can find further information about the JA3 fingerprint df5c30e670dba99f9270ed36060cf054, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:df5c30e670dba99f9270ed36060cf054
First seen:2017-07-20 17:44:07 UTC
Last seen:2018-04-11 15:57:59 UTC
Status:Blacklisted
Malware samples:72
Destination IPs:23
Malware:Tofsee -
Listing date:2018-11-14 12:41:48

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2018-04-11 15:57:59d3ad89a56c6c2f01cd118766e0953de0Virustotal results 38/67 (56.72%) 136.243.102.167:443
2018-04-11 15:57:59d3ad89a56c6c2f01cd118766e0953de0Virustotal results 38/67 (56.72%) 136.243.102.167:443
2018-04-10 23:43:23e4dfbbef6ba6882ac2f58396d26d66e6Virustotal results 14/67 (20.90%) 136.243.102.154:443
2018-04-10 23:43:23e4dfbbef6ba6882ac2f58396d26d66e6Virustotal results 14/67 (20.90%) 136.243.102.154:443
2018-02-08 21:57:40b4dba2e2abaa3fd8065efa1bc81ee789Virustotal results 43/68 (63.24%) 2.19.77.81:443
2018-02-08 21:57:40b4dba2e2abaa3fd8065efa1bc81ee789Virustotal results 43/68 (63.24%) 2.19.77.81:443
2018-02-02 17:59:07d9a7d58c32a653804fd07eb9dbd0a525Virustotal results 25/67 (37.31%) 136.243.102.154:443
2018-02-02 17:59:07d9a7d58c32a653804fd07eb9dbd0a525Virustotal results 25/67 (37.31%) 136.243.102.154:443
2018-01-31 19:14:2906c50214a4969953230ba3bca68c24a8Virustotal results 34/66 (51.52%) 88.99.142.163:443
2018-01-31 19:14:2906c50214a4969953230ba3bca68c24a8Virustotal results 34/66 (51.52%) 88.99.142.163:443
2018-01-28 10:59:131c1eca06b5120575b5ffc88563cf6d4bVirustotal results 40/66 (60.61%) 88.99.142.163:443
2018-01-28 10:59:131c1eca06b5120575b5ffc88563cf6d4bVirustotal results 40/66 (60.61%) 88.99.142.163:443
2018-01-28 08:53:311529ad484ef9b2988e9a2d87b5db271cVirustotal results 11/64 (17.19%) 136.243.102.167:443
2018-01-28 08:53:311529ad484ef9b2988e9a2d87b5db271cVirustotal results 11/64 (17.19%) 136.243.102.167:443
2018-01-27 23:22:27e5e68b77b689ffb31743f444af38bdb0Virustotal results 29/65 (44.62%) 136.243.102.154:443
2018-01-27 23:22:27e5e68b77b689ffb31743f444af38bdb0Virustotal results 29/65 (44.62%) 136.243.102.154:443
2018-01-26 11:49:42a0d0bb16e6be75344535c318ff43243dVirustotal results 16/65 (24.62%) 94.130.143.162:443
2018-01-26 11:49:42a0d0bb16e6be75344535c318ff43243dVirustotal results 16/65 (24.62%) 94.130.143.162:443
2018-01-25 18:03:02d20a434c4623389a6badc01392962d22Virustotal results 21/66 (31.82%) 88.99.142.163:443
2018-01-25 18:03:02d20a434c4623389a6badc01392962d22Virustotal results 21/66 (31.82%) 88.99.142.163:443
2018-01-25 05:31:22ed1f71cf6b771ba7246059b253684c03Virustotal results 26/67 (38.81%) 136.243.102.154:443
2018-01-25 05:31:22ed1f71cf6b771ba7246059b253684c03Virustotal results 26/67 (38.81%) 136.243.102.154:443
2018-01-22 19:26:32fcb0198de66ed257c0b4e2cc6be0427bVirustotal results 16/66 (24.24%) 88.99.142.163:443
2018-01-22 19:26:32fcb0198de66ed257c0b4e2cc6be0427bVirustotal results 16/66 (24.24%) 88.99.142.163:443
2018-01-22 05:51:494b8ad84fe0d107036e2d4ed84c77408bVirustotal results 23/66 (34.85%) 136.243.102.154:443
2018-01-22 05:51:494b8ad84fe0d107036e2d4ed84c77408bVirustotal results 23/66 (34.85%) 136.243.102.154:443
2018-01-19 06:19:44f84bf49eab7ece9b4686a629025b2ac4Virustotal results 36/67 (53.73%) 94.130.143.162:443
2018-01-19 06:19:44f84bf49eab7ece9b4686a629025b2ac4Virustotal results 36/67 (53.73%) 94.130.143.162:443
2018-01-09 20:02:21f000a0a8ed40c8a24a2ff81442a519f2Virustotal results 28/68 (41.18%) 136.243.102.154:443
2018-01-09 20:02:21f000a0a8ed40c8a24a2ff81442a519f2Virustotal results 28/68 (41.18%) 136.243.102.154:443
2018-01-07 05:23:26e1002b684f3e12a614fddd04d26c8c3cVirustotal results 20/68 (29.41%) 88.99.142.163:443
2018-01-07 05:23:26e1002b684f3e12a614fddd04d26c8c3cVirustotal results 20/68 (29.41%) 88.99.142.163:443
2017-12-11 10:47:502d852e408fd5638085162842af04cf3dVirustotal results 14/68 (20.59%) 104.25.50.101:443
2017-12-11 10:47:502d852e408fd5638085162842af04cf3dVirustotal results 14/68 (20.59%) 104.25.50.101:443
2017-11-27 20:25:2970516841168f00862d7069732563d5d5Virustotal results 45/68 (66.18%) 104.25.50.101:443
2017-11-27 20:25:2970516841168f00862d7069732563d5d5Virustotal results 45/68 (66.18%) 104.25.50.101:443
2017-11-23 07:42:59d89acfa4fe201c6475f2cd8928060867Virustotal results 42/67 (62.69%) 2.17.227.183:443
2017-11-23 07:42:59d89acfa4fe201c6475f2cd8928060867Virustotal results 42/67 (62.69%) 2.17.227.183:443
2017-11-14 03:43:2265a7ec07a87f60705f47491db930e61cVirustotal results 9/68 (13.24%) 104.25.49.101:443
2017-11-14 03:43:2265a7ec07a87f60705f47491db930e61cVirustotal results 9/68 (13.24%) 104.25.49.101:443
2017-11-14 02:34:086f6c6600531dfe15428ea47180e1ffa7Virustotal results 28/68 (41.18%) 104.25.50.101:443
2017-11-14 02:34:086f6c6600531dfe15428ea47180e1ffa7Virustotal results 28/68 (41.18%) 104.25.50.101:443
2017-11-13 13:05:03c5259f658191061d01f699af9fcee95eVirustotal results 14/68 (20.59%) 104.25.50.101:443
2017-11-13 13:05:03c5259f658191061d01f699af9fcee95eVirustotal results 14/68 (20.59%) 104.25.50.101:443
2017-11-13 13:04:34fdc5f21287145d0623a0bc3336f0a860Virustotal results 40/64 (62.50%) 104.25.49.101:443
2017-11-13 13:04:34fdc5f21287145d0623a0bc3336f0a860Virustotal results 40/64 (62.50%) 104.25.49.101:443
2017-11-13 09:53:203d3073713a4d00477a4bb5c5663a266cVirustotal results 31/67 (46.27%) 104.25.49.101:443
2017-11-13 09:53:203d3073713a4d00477a4bb5c5663a266cVirustotal results 31/67 (46.27%) 104.25.49.101:443
2017-11-13 08:19:18696084e07c70ff92dac6209ecfbfe09fVirustotal results 20/68 (29.41%) 104.25.49.101:443
2017-11-13 08:19:18696084e07c70ff92dac6209ecfbfe09fVirustotal results 20/68 (29.41%) 104.25.49.101:443
2017-11-07 20:06:144e88ed99630e0153553ca0883e3158cbVirustotal results 14/68 (20.59%) 23.43.120.11:443
2017-11-07 20:06:144e88ed99630e0153553ca0883e3158cbVirustotal results 14/68 (20.59%) 23.43.120.11:443
2017-10-30 07:55:07bee7480ef9a4f36cd1c01b3708c7493bVirustotal results 16/67 (23.88%) 23.201.250.90:443
2017-10-30 07:55:07bee7480ef9a4f36cd1c01b3708c7493bVirustotal results 16/67 (23.88%) 23.201.250.90:443
2017-10-30 06:41:57f867893568fa7dab3fafa861f528c737Virustotal results 38/67 (56.72%) 92.122.65.18:443
2017-10-30 06:41:57f867893568fa7dab3fafa861f528c737Virustotal results 38/67 (56.72%) 92.122.65.18:443
2017-10-06 15:13:2307e7aaa178803206b6733581a392fdbcVirustotal results 41/66 (62.12%) 184.86.225.137:443
2017-10-06 15:13:2307e7aaa178803206b6733581a392fdbcVirustotal results 41/66 (62.12%) 184.86.225.137:443
2017-10-05 17:14:1028ccbfc435d07801929b17e8e3544d75Virustotal results 31/66 (46.97%) 184.86.225.137:443
2017-10-05 17:14:1028ccbfc435d07801929b17e8e3544d75Virustotal results 31/66 (46.97%) 184.86.225.137:443
2017-09-29 07:21:30a0bdb6e9fe96ed131ad9411b815c2519Virustotal results 23/65 (35.38%) 104.124.128.162:443
2017-09-29 07:21:30a0bdb6e9fe96ed131ad9411b815c2519Virustotal results 23/65 (35.38%) 104.124.128.162:443
2017-09-26 17:45:57a1e0d7039a14a13505dbc7553e0024c1Virustotal results 27/65 (41.54%) 104.124.128.162:443
2017-09-26 17:45:57a1e0d7039a14a13505dbc7553e0024c1Virustotal results 27/65 (41.54%) 104.124.128.162:443
2017-09-26 16:07:13585c5240556fed7386bca11084f1bf27Virustotal results 43/66 (65.15%) 104.124.128.162:443
2017-09-26 16:07:13585c5240556fed7386bca11084f1bf27Virustotal results 43/66 (65.15%) 104.124.128.162:443
2017-09-25 16:45:109fda0bf0ddab9fdc7f34bea60b7bbadfn/a104.124.128.162:443
2017-09-25 16:45:109fda0bf0ddab9fdc7f34bea60b7bbadfn/a104.124.128.162:443
2017-09-25 14:17:57bfde71425d2d22eb7b4a8be143f40f95Virustotal results 30/64 (46.88%) 104.124.128.162:443
2017-09-25 14:17:57bfde71425d2d22eb7b4a8be143f40f95Virustotal results 30/64 (46.88%) 104.124.128.162:443
2017-09-25 14:17:56196fc3b5861a607f838a37aa3d42e1b7Virustotal results 52/66 (78.79%) 104.124.128.162:443
2017-09-25 14:17:56196fc3b5861a607f838a37aa3d42e1b7Virustotal results 52/66 (78.79%) 104.124.128.162:443
2017-09-25 14:15:2606ba0ea8063ca50aae2d8468ba9ad058Virustotal results 39/66 (59.09%) 104.124.128.162:443
2017-09-25 14:15:2606ba0ea8063ca50aae2d8468ba9ad058Virustotal results 39/66 (59.09%) 104.124.128.162:443
2017-09-25 14:09:054df49372d195f604caa6da3a7c2646e9Virustotal results 45/64 (70.31%) 104.124.128.162:443
2017-09-25 14:09:054df49372d195f604caa6da3a7c2646e9Virustotal results 45/64 (70.31%) 104.124.128.162:443
2017-09-25 14:02:587d298e7e13228e0915cef89ba27ed848n/a104.124.128.162:443
2017-09-25 14:02:587d298e7e13228e0915cef89ba27ed848n/a104.124.128.162:443
2017-09-25 14:01:514e4b4c7f74ff434d7aa8f440cb55ee09n/a104.124.128.162:443
2017-09-25 14:01:514e4b4c7f74ff434d7aa8f440cb55ee09n/a104.124.128.162:443
2017-09-25 02:48:435b713333699bc039ed1dce9b42c97267n/a104.124.128.162:443
2017-09-25 02:48:435b713333699bc039ed1dce9b42c97267n/a104.124.128.162:443
2017-09-24 13:40:5824e89362241a2cd5d010d52ad844af4dVirustotal results 38/65 (58.46%) 104.124.128.162:443
2017-09-24 13:40:5824e89362241a2cd5d010d52ad844af4dVirustotal results 38/65 (58.46%) 104.124.128.162:443
2017-09-24 09:54:24defb62f72f12a536c311a7d39f576f8aVirustotal results 31/64 (48.44%) 104.124.128.162:443
2017-09-24 09:54:24defb62f72f12a536c311a7d39f576f8aVirustotal results 31/64 (48.44%) 23.43.120.11:443
2017-09-24 09:54:24defb62f72f12a536c311a7d39f576f8aVirustotal results 31/64 (48.44%) 104.124.128.162:443
2017-09-24 09:54:24defb62f72f12a536c311a7d39f576f8aVirustotal results 31/64 (48.44%) 23.43.120.11:443
2017-09-23 02:43:3555a13e60a5bb247955e08d018c018134Virustotal results 40/65 (61.54%) 95.100.49.148:443
2017-09-23 02:43:3555a13e60a5bb247955e08d018c018134Virustotal results 40/65 (61.54%) 95.100.49.148:443
2017-09-22 19:20:005d98ba1272a17e932af656df3c308830n/a104.94.20.152:443
2017-09-22 19:20:005d98ba1272a17e932af656df3c308830n/a104.94.20.152:443
2017-09-21 05:00:44a3d78caedb739e57633d4be691a8190eVirustotal results 37/65 (56.92%) 2.19.77.81:443
2017-09-21 05:00:44a3d78caedb739e57633d4be691a8190eVirustotal results 37/65 (56.92%) 2.19.77.81:443
2017-09-20 20:03:06b96eace2e786e64f46279773530f1ddbVirustotal results 41/65 (63.08%) 192.81.241.100:443
2017-09-20 20:03:06b96eace2e786e64f46279773530f1ddbVirustotal results 41/65 (63.08%) 192.81.241.100:443
2017-09-20 17:18:2072c606b0d9ad5a839a44d43e20a5158bn/a104.109.107.107:443
2017-09-20 17:18:2072c606b0d9ad5a839a44d43e20a5158bn/a104.109.107.107:443
2017-09-20 15:25:50fefb7a19262164e1185e6ca27fe7813cn/a104.94.20.152:443
2017-09-20 15:25:50fefb7a19262164e1185e6ca27fe7813cn/a104.94.20.152:443

# of entries: 100 (max: 100)