JA3 Fingerprints

You can find further information about the JA3 fingerprint fd80fa9c6120cdeea8520510f3c644ac, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:fd80fa9c6120cdeea8520510f3c644ac
First seen:2018-03-11 09:34:30 UTC
Last seen:2020-03-28 11:16:40 UTC
Status:Blacklisted
Malware samples:671
Destination IPs:97
Malware:Tofsee -
Listing date:2018-11-14 00:00:00

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2020-03-28 11:16:40bce738cf74904dbfa53b1215641a42feVirustotal results 54 / 73 (73.97%) 104.27.167.5:443
2020-03-28 06:32:332fa08b5df03fa494f7ae182ca4019115n/a87.240.129.181:443
2020-03-27 16:37:09b54be699c6116daa8e13de5e04f5a893Virustotal results 45 / 73 (61.64%) 104.28.25.59:443
2020-03-27 14:51:53a01123f18c7ca7fad38e1b567105faedVirustotal results 51 / 73 (69.86%) 104.27.166.5:443
2020-03-27 14:51:53a01123f18c7ca7fad38e1b567105faedVirustotal results 51 / 73 (69.86%) 104.27.167.5:443
2020-03-27 14:27:13ae74f0578f701a15a43f727ebd60a207Virustotal results 39 / 72 (54.17%) 104.18.47.51:443
2020-03-27 14:25:01c19598944b84a2da72d0eb901aebc794Virustotal results 6 / 73 (8.22%) 104.18.47.51:443
2020-03-27 10:49:077ac5597f0220a23da4e94bead40c2904Virustotal results 25 / 71 (35.21%) 87.240.129.135:443
2020-03-27 08:26:08ac8ce53115cc31ff44337b3a66bff3caVirustotal results 58 / 73 (79.45%) 104.18.47.51:443
2020-03-27 08:26:08ac8ce53115cc31ff44337b3a66bff3caVirustotal results 58 / 73 (79.45%) 104.18.46.51:443
2020-03-27 08:06:4399b6fc26f6a4f013ae61cc3102e3a392n/a34.107.165.220:443
2020-03-27 08:00:199fbcc892773395183458ab838eacb662Virustotal results 24 / 73 (32.88%) 87.240.129.135:443
2020-03-27 07:58:32b17cda2bc153d988f8d7cc1494d6f22aVirustotal results 27 / 73 (36.99%) 104.18.47.51:443
2020-03-27 07:41:11b3877d335183bc214bd03bf03ce5dd7fVirustotal results 27 / 71 (38.03%) 104.18.47.51:443
2020-03-27 07:41:11b3877d335183bc214bd03bf03ce5dd7fVirustotal results 27 / 71 (38.03%) 104.18.46.51:443
2020-03-27 05:04:229e2cb3c7c941cff4a011d891955bcc98Virustotal results 28 / 71 (39.44%) 87.240.129.135:443
2020-03-27 03:24:27947b2614ccb0cc2ce4439d8cdfa6cfd4Virustotal results 22 / 71 (30.99%) 34.107.165.220:443
2020-03-26 21:13:42803c7e7340e9f2e3c492662eadc5afa6Virustotal results 22 / 73 (30.14%) 87.240.129.181:443
2020-03-26 21:13:39803c7e7340e9f2e3c492662eadc5afa6Virustotal results 22 / 73 (30.14%) 87.240.129.135:443
2020-03-26 19:49:31cdf6c5b37844378a0f1dfd0fcb89cda1Virustotal results 33 / 72 (45.83%) 87.240.129.135:443
2020-03-26 19:49:28cdf6c5b37844378a0f1dfd0fcb89cda1Virustotal results 33 / 72 (45.83%) 87.240.129.181:443
2020-03-26 19:49:26cdf6c5b37844378a0f1dfd0fcb89cda1Virustotal results 33 / 72 (45.83%) 146.158.48.2:443
2020-03-26 19:49:25cdf6c5b37844378a0f1dfd0fcb89cda1Virustotal results 33 / 72 (45.83%) 34.107.165.220:443
2020-03-26 19:16:060619175efa50887152aa01e9b06b96dcVirustotal results 21 / 72 (29.17%) 104.36.194.169:443
2020-03-26 10:07:470c923ba0498d2052f64b1fc4f7b2cfceVirustotal results 18 / 73 (24.66%) 87.240.129.181:443
2020-03-26 07:30:15ba8a503dbed78cb19f3f8b312d77489aVirustotal results 36 / 73 (49.32%) 104.18.46.51:443
2020-03-26 04:39:44a73f57111671de06df2bab5535a53630Virustotal results 37 / 72 (51.39%) 104.18.46.51:443
2020-03-26 03:27:49dc8f87f15cb39c308e162ca55a41d32fVirustotal results 22 / 71 (30.99%) 3.121.248.176:443
2020-03-26 03:27:45dc8f87f15cb39c308e162ca55a41d32fVirustotal results 22 / 71 (30.99%) 104.19.154.59:443
2020-03-26 03:27:44dc8f87f15cb39c308e162ca55a41d32fVirustotal results 22 / 71 (30.99%) 23.20.18.105:443
2020-03-26 02:48:09a244524aeaf7f6608d1d597108e31596Virustotal results 38 / 73 (52.05%) 104.18.47.51:443
2020-03-26 02:48:09a244524aeaf7f6608d1d597108e31596Virustotal results 38 / 73 (52.05%) 104.18.46.51:443
2020-03-25 23:58:1745fe5d497f1e8c73da075bcc4b1b532aVirustotal results 36 / 72 (50.00%) 104.18.46.51:443
2020-03-25 20:22:0389cad87512e0a5c7cfbe45175fa9774bVirustotal results 21 / 73 (28.77%) 104.18.44.214:443
2020-03-25 20:22:0289cad87512e0a5c7cfbe45175fa9774bVirustotal results 21 / 73 (28.77%) 104.18.45.214:443
2020-03-25 16:19:4839b961c13850e7910d07c9d1993b47a7Virustotal results 20 / 72 (27.78%) 3.121.248.176:443
2020-03-25 16:19:4839b961c13850e7910d07c9d1993b47a7Virustotal results 20 / 72 (27.78%) 178.128.254.4:443
2020-03-25 16:19:4739b961c13850e7910d07c9d1993b47a7Virustotal results 20 / 72 (27.78%) 87.240.129.135:443
2020-03-25 16:19:4739b961c13850e7910d07c9d1993b47a7Virustotal results 20 / 72 (27.78%) 104.19.154.59:443
2020-03-25 16:19:4539b961c13850e7910d07c9d1993b47a7Virustotal results 20 / 72 (27.78%) 103.55.148.32:443
2020-03-25 16:19:3739b961c13850e7910d07c9d1993b47a7Virustotal results 20 / 72 (27.78%) 104.17.49.74:443
2020-03-25 14:18:52c0d90be5de2fbba760a3ae94c4cdbf85Virustotal results 22 / 72 (30.56%) 146.158.48.2:443
2020-03-23 11:58:38b4a87f447cda32f02e924eca41fe96e4n/a104.27.167.5:443
2020-03-23 10:24:13b2a1dd8aee694f9e5e135e14e79b6e44n/a104.27.167.5:443
2020-03-23 09:39:17b692dbeb37b23e8eed8bd34dd6179e8dVirustotal results 31 / 73 (42.47%) 104.18.46.51:443
2020-03-23 09:39:17b692dbeb37b23e8eed8bd34dd6179e8dVirustotal results 31 / 73 (42.47%) 104.18.47.51:443
2020-03-22 08:09:04a8e7b78624e97af225aa2056ce556f0cVirustotal results 41 / 73 (56.16%) 104.18.46.51:443
2020-03-22 08:09:04a8e7b78624e97af225aa2056ce556f0cVirustotal results 41 / 73 (56.16%) 104.18.47.51:443
2020-03-21 22:41:32d77e5078cb6cf870b42b6dde785424e7Virustotal results 39 / 73 (53.42%) 104.18.46.51:443
2020-03-21 22:41:32d77e5078cb6cf870b42b6dde785424e7Virustotal results 39 / 73 (53.42%) 104.18.47.51:443
2020-03-21 20:29:14671343298150828cf8706eda0bca56cbVirustotal results 26 / 73 (35.62%) 13.224.102.100:443
2020-03-20 19:13:50b362e532303029494b23b59009913a75Virustotal results 21 / 73 (28.77%) 104.27.166.5:443
2020-03-20 12:43:337ffff8315d3b608248284289e8e41529Virustotal results 32 / 73 (43.84%) 99.86.157.42:443
2020-03-19 11:52:15befb63bc488d150f75adcc0005ebbc0bVirustotal results 27 / 73 (36.99%) 104.27.167.5:443
2020-03-19 00:56:33bcd101fcfe6b33e74bd6e9118d81cfafVirustotal results 45 / 68 (66.18%) 104.27.167.5:443
2020-03-19 00:56:33bcd101fcfe6b33e74bd6e9118d81cfafVirustotal results 45 / 68 (66.18%) 104.27.166.5:443
2020-03-19 00:29:276e381edc407e7150d77ade53bce5609eVirustotal results 37 / 72 (51.39%) 104.28.24.59:443
2020-03-19 00:29:266e381edc407e7150d77ade53bce5609eVirustotal results 37 / 72 (51.39%) 104.28.25.59:443
2020-03-17 10:51:47ba0dfa304ab95f8bb4c0838cef690762Virustotal results 33 / 73 (45.21%) 104.28.5.155:443
2020-03-17 10:51:46ba0dfa304ab95f8bb4c0838cef690762Virustotal results 33 / 73 (45.21%) 104.28.4.155:443
2020-03-16 15:48:5501751456f74257e8aaaa8d8f40cae181Virustotal results 42 / 73 (57.53%) 104.28.4.155:443
2020-03-16 15:48:5501751456f74257e8aaaa8d8f40cae181Virustotal results 42 / 73 (57.53%) 104.28.5.155:443
2020-03-15 07:12:05a67a92db519227d1a8b1762e0f0ad318Virustotal results 33 / 73 (45.21%) 104.28.5.155:443
2020-03-15 07:12:05a67a92db519227d1a8b1762e0f0ad318Virustotal results 33 / 73 (45.21%) 104.28.4.155:443
2020-03-15 06:41:15bcbf66c43293f9efb892dab7f94453c7Virustotal results 31 / 73 (42.47%) 104.28.4.155:443
2020-03-14 21:01:593c6b9ee0fc0e1aefaafb26bf2e219beeVirustotal results 56 / 73 (76.71%) 104.28.4.155:443
2020-03-14 21:01:593c6b9ee0fc0e1aefaafb26bf2e219beeVirustotal results 56 / 73 (76.71%) 104.28.5.155:443
2020-03-14 19:25:03a9e6f4467f77f93ee333ea2ae6ee8147Virustotal results 30 / 73 (41.10%) 104.28.4.155:443
2020-03-14 19:25:02a9e6f4467f77f93ee333ea2ae6ee8147Virustotal results 30 / 73 (41.10%) 104.28.5.155:443
2020-03-14 18:19:171ed6efb04ed0436c48a0b034b9326ff4Virustotal results 46 / 72 (63.89%) 104.28.4.155:443
2020-03-14 10:36:20242b3ab9aeeb479a8d02f436a6ebdda7Virustotal results 20 / 72 (27.78%) 104.28.5.155:443
2020-03-14 10:36:19242b3ab9aeeb479a8d02f436a6ebdda7Virustotal results 20 / 72 (27.78%) 104.28.4.155:443
2020-03-14 09:45:260e8187a6eba420c58f1608c9011a07efVirustotal results 40 / 73 (54.79%) 104.28.4.155:443
2020-03-14 09:45:260e8187a6eba420c58f1608c9011a07efVirustotal results 40 / 73 (54.79%) 104.28.5.155:443
2020-03-13 20:56:0831b29b270f02f737a519993f866c8dd8Virustotal results 27 / 73 (36.99%) 104.125.21.114:443
2020-03-13 20:03:4707e1d09bdb027ed3bd5beda7c81c733aVirustotal results 34 / 73 (46.58%) 104.28.4.155:443
2020-03-13 20:03:4707e1d09bdb027ed3bd5beda7c81c733aVirustotal results 34 / 73 (46.58%) 104.28.5.155:443
2020-03-13 16:47:47d8fe16e62f27ba7d966b7a474a1e436bVirustotal results 19 / 73 (26.03%) 87.240.129.181:443
2020-03-13 15:51:1487ddb4a46f4099cf156c9107e4bd3feaVirustotal results 19 / 72 (26.39%) 87.240.129.135:443
2020-03-13 15:51:1287ddb4a46f4099cf156c9107e4bd3feaVirustotal results 19 / 72 (26.39%) 87.240.129.181:443
2020-03-13 04:42:032e3249d404e1785a1bfa1914a75effcfVirustotal results 24 / 73 (32.88%) 146.158.48.2:443
2020-03-13 04:42:032e3249d404e1785a1bfa1914a75effcfVirustotal results 24 / 73 (32.88%) 87.240.129.181:443
2020-03-13 04:41:562e3249d404e1785a1bfa1914a75effcfVirustotal results 24 / 73 (32.88%) 87.240.129.135:443
2020-03-13 04:41:372e3249d404e1785a1bfa1914a75effcfVirustotal results 24 / 73 (32.88%) 185.89.12.132:443
2020-03-12 17:39:40976a090d05150678c5c42d68838d5b68Virustotal results 23 / 73 (31.51%) 195.201.228.108:443
2020-03-12 03:05:35af791ba48a5a36e1a697a359f91d37c6Virustotal results 13 / 68 (19.12%) 104.28.4.155:443
2020-03-12 03:05:35af791ba48a5a36e1a697a359f91d37c6Virustotal results 13 / 68 (19.12%) 104.28.5.155:443
2020-03-11 09:09:3519e2a5147a80e886fdd8c5bc6a5a0825Virustotal results 16 / 72 (22.22%) 13.224.102.77:443
2020-03-11 09:09:3519e2a5147a80e886fdd8c5bc6a5a0825Virustotal results 16 / 72 (22.22%) 13.224.102.128:443
2020-03-10 20:49:220f71e9ea62c11a1cd7f5e2f392caa814Virustotal results 37 / 73 (50.68%) 104.28.4.155:443
2020-03-10 20:49:220f71e9ea62c11a1cd7f5e2f392caa814Virustotal results 37 / 73 (50.68%) 104.28.5.155:443
2020-03-09 23:48:30c86afc2228425109f9d197b628874d89Virustotal results 37 / 73 (50.68%) 104.28.5.155:443
2020-03-09 23:48:30c86afc2228425109f9d197b628874d89Virustotal results 37 / 73 (50.68%) 104.28.4.155:443
2020-03-09 19:35:47d96f5a9f4e389f32390409713f005749Virustotal results 19 / 72 (26.39%) 54.192.87.92:443
2020-03-09 18:40:31a353a1f925cc05671fcf4c43a048f773Virustotal results 39 / 73 (53.42%) 104.28.4.155:443
2020-03-09 18:40:31a353a1f925cc05671fcf4c43a048f773Virustotal results 39 / 73 (53.42%) 104.28.5.155:443
2020-03-09 17:35:39893e272d0e38bcb48d7ce7437b36565fn/a104.121.113.125:443
2020-03-09 16:47:00980322fcc4ba63d32948f64dfffd3d0bn/a23.62.117.69:443
2020-03-09 15:28:11c61b09c484cc9f4b0ca8be4930e4b667Virustotal results 37 / 73 (50.68%) 104.28.5.155:443
2020-03-09 15:28:11c61b09c484cc9f4b0ca8be4930e4b667Virustotal results 37 / 73 (50.68%) 104.28.4.155:443

# of entries: 100 (max: 100)