JA3 Fingerprints

You can find further information about the JA3 fingerprint dff8a0aa1c904aaea76c5bf624e88333, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:dff8a0aa1c904aaea76c5bf624e88333
First seen:2018-03-18 09:41:15 UTC
Last seen:2020-04-05 05:48:24 UTC
Status:Blacklisted
Malware samples:331
Destination IPs:15
Malware:Tofsee -
Listing date:2020-01-09 14:27:20

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2020-04-05 05:48:25b4356e66d34b310f0e007d80d7244081Virustotal results 40 / 71 (56.34%) 31.13.72.34:443
2020-04-05 05:48:24b4356e66d34b310f0e007d80d7244081Virustotal results 40 / 71 (56.34%) 157.240.194.34:443
2020-04-03 22:01:283f8474528ca3cb2887e4686ee403906en/a157.240.194.34:443
2020-04-03 21:24:563dc79f9ef9b3020de8df734864f9648fn/a31.13.72.34:443
2020-04-03 21:03:08114473afba7b60488dd1f3e141fbd888n/a185.60.216.32:443
2020-04-03 19:34:37eb834b42b7493884ac06f148f51fde0bn/a31.13.72.34:443
2020-04-03 19:29:01768a4e253da69ffa972dc1b0b9728993n/a185.60.216.32:443
2020-04-01 23:08:0304bf1c2794a8e0ea112dfa93f3374644n/a31.13.72.34:443
2020-03-31 08:38:35142e93b0e744a05d54382eb5675beeean/a31.13.72.34:443
2020-03-29 20:02:23326f2c90f50530e51ae7dc5458fe5d1en/a31.13.72.34:443
2020-03-29 20:02:22326f2c90f50530e51ae7dc5458fe5d1en/a157.240.194.34:443
2020-03-29 19:59:503fbdd253b9cf04880b507036cf4f7006n/a31.13.72.34:443
2020-03-29 19:45:25ff913329af3b334debcebc2e85adc713n/a31.13.72.34:443
2020-03-29 19:45:25ff913329af3b334debcebc2e85adc713n/a157.240.194.34:443
2020-03-29 19:27:4383c6fa49c906279907c4d1a8096acd10n/a157.240.194.34:443
2020-03-29 19:27:4383c6fa49c906279907c4d1a8096acd10n/a31.13.72.34:443
2020-03-29 19:22:58ada0c02090b54a98136b7c5caee43380Virustotal results 55 / 73 (75.34%) 31.13.72.34:443
2020-03-29 19:13:394f49bd76e941bfda0f2f44d06df8c855n/a31.13.72.34:443
2020-03-29 08:34:05c260b388b3a0a6a42d1dc18f67eb1b5eVirustotal results 31 / 72 (43.06%) 31.13.72.34:443
2020-03-29 00:54:11aabf7a7dfd185f1e3969712068f359a8Virustotal results 38 / 73 (52.05%) 31.13.72.34:443
2020-03-28 18:27:3929bab3886add948bb6983c0a74ddde81n/a31.13.92.33:443
2020-03-27 08:00:51cd0f9d101208331d0682a14607fb8935Virustotal results 55 / 73 (75.34%) 31.13.72.34:443
2020-03-25 19:14:10283379943f74ca13f4b8b68ce5555e34Virustotal results 55 / 73 (75.34%) 31.13.72.34:443
2020-03-25 19:14:09283379943f74ca13f4b8b68ce5555e34Virustotal results 55 / 73 (75.34%) 157.240.194.34:443
2020-03-25 18:08:06617757adfdd08f4de7bb1a7c763e1354n/a31.13.72.34:443
2020-03-25 18:08:05617757adfdd08f4de7bb1a7c763e1354n/a157.240.194.34:443
2020-03-25 17:48:467d99738ae0fbfe01e9b4e0b2734505b9n/a31.13.72.34:443
2020-03-25 08:25:51e4927c69ab20efd10f8ad729a209001cn/a31.13.72.34:443
2020-03-24 10:47:18015cf6ea89bb81b627974c9285d383a0Virustotal results 54 / 72 (75.00%) 31.13.72.34:443
2020-03-24 07:22:04fb5d99056bbec8b5c63a601e354fc338n/a31.13.72.34:443
2020-03-24 07:14:34f9838b48b76cd2e54b8a23f97eccd07fn/a31.13.72.34:443
2020-03-24 04:36:17b485bc0512c504cb7bbbc7376718970eVirustotal results 55 / 73 (75.34%) 31.13.72.34:443
2020-03-24 00:43:18498712c2e86e43156e61b25b00ff4391n/a157.240.194.34:443
2020-03-23 22:48:438d2e93b7521a348c90a0e3b24c3863e5n/a31.13.72.34:443
2020-03-22 12:32:35a61d1763c317f2f43e45ce868087c921Virustotal results 53 / 72 (73.61%) 31.13.72.34:443
2020-03-22 06:52:441e2b1f625c92dd88611fc31bfa9e2b85n/a157.240.194.34:443
2020-03-21 20:25:109a03c4f9e25dbfa5ac78054e57cfa2f2Virustotal results 37 / 71 (52.11%) 31.13.72.34:443
2020-03-21 17:31:18f2ec44dad34a8f0f3bd34b33d91989fbn/a31.13.72.34:443
2020-03-21 06:04:17a4bf21a69fb30c57ec8688cbd7e3cf89Virustotal results 54 / 73 (73.97%) 31.13.72.34:443
2020-03-20 20:16:29ae411dc63a6870e14d9a70460c5bf6c7Virustotal results 54 / 71 (76.06%) 31.13.72.34:443
2020-03-20 20:16:28ae411dc63a6870e14d9a70460c5bf6c7Virustotal results 54 / 71 (76.06%) 157.240.194.34:443
2020-03-20 20:15:55c4ad4b3e50d79114b98d52de20df0c00Virustotal results 54 / 72 (75.00%) 31.13.72.34:443
2020-03-20 18:47:55c839e7df2dd538ad2021e6a37bbcf8c0Virustotal results 57 / 73 (78.08%) 31.13.72.34:443
2020-03-20 07:41:4804c165a8c81caedda4674496bc402350n/a157.240.194.34:443
2020-03-20 07:41:4604c165a8c81caedda4674496bc402350n/a31.13.72.34:443
2020-03-20 06:01:46a24cc39c2dfeecb0c5f4b015ca3a2741n/a31.13.72.34:443
2020-03-20 06:01:46a24cc39c2dfeecb0c5f4b015ca3a2741n/a157.240.194.34:443
2020-02-05 07:20:09b04133c1e71fad436accb359e3aec931n/a31.13.72.34:443
2020-02-05 07:20:09b04133c1e71fad436accb359e3aec931n/a157.240.194.34:443
2020-02-05 02:05:08a1b8a7a27cd9f96176e00e0fd252ae02Virustotal results 21 / 73 (28.77%) 31.13.72.34:443
2020-02-04 22:04:56b35afd074427f4d202179d9118b323f5Virustotal results 24 / 72 (33.33%) 31.13.72.34:443
2020-02-04 02:41:29b89f57d9897574e8d98279ba9cad80efVirustotal results 23 / 72 (31.94%) 157.240.194.34:443
2020-02-03 04:16:50c1d4b12b9e490ecc797c3128bf042cc4Virustotal results 37 / 72 (51.39%) 157.240.194.34:443
2020-02-02 19:00:3717283e76cd01843f7f57f3bb33aeaf6an/a157.240.194.34:443
2020-02-02 18:47:25e4418ff0eed212b886b7306aab0c45b4n/a157.240.194.34:443
2020-02-02 18:46:4983d9239f1ed613e5352d7866a2280894Virustotal results 37 / 73 (50.68%) 157.240.194.34:443
2020-02-02 18:32:31bf1e50d2467c25212eaae0ec95f5a68eVirustotal results 52 / 72 (72.22%) 157.240.194.34:443
2020-02-02 18:11:2918d69f7477b4740521cec67cfdbf427an/a157.240.194.11:443
2020-02-02 15:18:48a7f12b9a22f7e78160790ee40d3e56deVirustotal results 35 / 72 (48.61%) 31.13.72.34:443
2020-02-02 04:18:45b93026fc047f76de9c6705d3ecf2024aVirustotal results 40 / 72 (55.56%) 31.13.72.34:443
2020-02-02 02:27:19b57cbeb92d0616b9ffcba3bc6e8fa118Virustotal results 36 / 72 (50.00%) 31.13.72.34:443
2020-02-01 19:20:10c0b087cfc9d25f07c24e6573dc61554dVirustotal results 56 / 72 (77.78%) 31.13.72.34:443
2020-01-31 05:43:07baaf59fd191dba8e3cf1739022762d36n/a31.13.72.34:443
2020-01-30 02:47:00b93bd5afb4c16a1fbc35ac886e0edf55Virustotal results 26 / 73 (35.62%) 157.240.194.34:443
2020-01-29 19:05:2973f2a9009088d6956a29c4037238e01an/a157.240.194.34:443
2020-01-29 00:50:2209da6e9e73b7f984f95a1d519989a0ebn/a31.13.72.34:443
2020-01-28 22:59:07813ff8603e0d6f3efc156b8bc3e51ba8n/a31.13.72.34:443
2020-01-28 19:58:05e2f5e01fea13da0e3a613b7d69748080Virustotal results 52 / 72 (72.22%) 31.13.72.34:443
2020-01-27 21:39:178cfebf7be908f13dfd040b2d92dc8cd3n/a157.240.194.34:443
2020-01-27 21:33:54b6c38b9479230aec5d7ac4649e5ab3a6Virustotal results 50 / 71 (70.42%) 31.13.72.34:443
2020-01-27 21:23:163aadc1e63cb4322c62ea3a21fd2085d9n/a31.13.72.34:443
2020-01-27 21:23:163aadc1e63cb4322c62ea3a21fd2085d9n/a157.240.194.34:443
2020-01-27 20:43:43e8be84e9c3c0ff659cefaf87848080cbn/a185.60.216.32:443
2020-01-26 21:04:1434ec30a89e236ba389fbbf486bccfca4n/a31.13.72.34:443
2020-01-26 03:28:40ae0278cc783ccac57eb44e0090d9d94cVirustotal results 21 / 73 (28.77%) 157.240.194.34:443
2020-01-25 11:52:03ad8e616c23e26c4f3b44b1b5420380feVirustotal results 41 / 71 (57.75%) 31.13.72.34:443
2020-01-25 01:54:33c224da006da02f446249ff5646f3baa4n/a31.13.72.34:443
2020-01-24 01:33:30adb4d406f1b5e554d25470afa7cf0c5dn/a157.240.194.34:443
2020-01-23 23:47:53c405156d8c14b0ce5fd69ec53cf0558bVirustotal results 52 / 72 (72.22%) 157.240.194.34:443
2020-01-23 23:47:52c405156d8c14b0ce5fd69ec53cf0558bVirustotal results 52 / 72 (72.22%) 31.13.72.34:443
2020-01-23 19:47:47dd2bca5a83940b0924e63685da29b228n/a31.13.72.34:443
2020-01-23 19:36:23c0dd23cd8dcbdc1a2d70218d8513587aVirustotal results 50 / 68 (73.53%) 157.240.194.34:443
2020-01-23 19:36:21c0dd23cd8dcbdc1a2d70218d8513587aVirustotal results 50 / 68 (73.53%) 31.13.72.5:443
2020-01-23 11:03:389e27507dc37e0b4c15ea9c447aa3b858n/a31.13.72.34:443
2020-01-23 08:39:55c20f0a0a647237136ce4269ce522dbc5Virustotal results 30 / 65 (46.15%) 31.13.72.34:443
2020-01-22 13:23:268779a8be485715775b78d262ba74d5b4n/a31.13.72.34:443
2020-01-21 14:03:48dd57360a56c9dc4219b09741ed6de556n/a31.13.72.34:443
2020-01-21 13:52:18b4d5592fac5e6d428a9b60c7191e58ebn/a31.13.72.34:443
2020-01-21 13:44:3215a442f75792addcfce4713841caf85fn/a31.13.72.34:443
2020-01-18 13:48:383df8d316815a3db82a63d877b51c1be6n/a31.13.72.34:443
2020-01-15 16:42:00a5217d78ec1fc4653b0a03aa81625e42n/a31.13.72.34:443
2020-01-13 08:49:41d8132df033a2b470e0013972a42da105n/a31.13.72.34:443
2020-01-12 17:50:03633ef6a38ac1478f017e2ce432d2a30en/a31.13.72.5:443
2020-01-12 17:50:03633ef6a38ac1478f017e2ce432d2a30en/a31.13.72.34:443
2020-01-12 17:19:03c12772934cd5e6ffcb0a6b527c723feeVirustotal results 55 / 73 (75.34%) 31.13.72.34:443
2020-01-12 11:54:11243019cfe23fd1dc4a337a724e1f6084n/a31.13.72.5:443
2020-01-12 11:54:10243019cfe23fd1dc4a337a724e1f6084n/a31.13.72.34:443
2020-01-11 22:42:43be1d6dcc7ae176ecd3446fe50b38a1f9n/a31.13.72.34:443
2020-01-11 21:58:03599fed32de5f88bc6dae0338e88416bdn/a31.13.72.34:443
2020-01-07 20:14:09a14c64a3fa84555ccbf50511be1b5ecdVirustotal results 48 / 70 (68.57%) 31.13.72.34:443

# of entries: 100 (max: 100)