JA3 Fingerprints

You can find further information about the JA3 fingerprint fd80fa9c6120cdeea8520510f3c644ac, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:fd80fa9c6120cdeea8520510f3c644ac
First seen:2018-03-11 09:34:30 UTC
Last seen:2021-08-11 12:34:00 UTC
Status:Blacklisted
Malware samples:6'887
Destination IPs:419
Malware:Tofsee -
Listing date:2018-11-14 00:00:00

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2021-10-22 09:13:16ad40a8c0b75804802dee772968eeb67fn/a172.67.152.176:443
2021-10-22 08:09:4095faed480a8f03a8a4457ae054def9dan/a172.67.152.176:443
2021-10-22 01:53:07a590eca41ea79dd63428c2e0a431e94cn/a172.67.152.176:443
2021-10-21 20:30:32838cab87d4e86f38e9e1f469dbcc5588n/a172.67.152.84:443
2021-10-21 11:56:14fc38abbf22aae67602371ee088202a6fn/a104.21.30.56:443
2021-10-21 11:43:01fae911145e85319a3aa3c4a0402dab0dn/a172.67.150.157:443
2021-10-21 10:56:57f7bc5a4e8acd9da0358066a12645a425n/a172.67.150.157:443
2021-10-21 10:44:27f6ed45e94d88144d7c3288319708d0e3n/a172.67.150.157:443
2021-10-21 10:39:23f68fb478f5105275af23ff8784260452n/a172.67.150.157:443
2021-10-21 10:05:18f5b3aadf960f9e8898e4b3ca02e5bd62n/a104.21.30.56:443
2021-10-21 09:10:25f0ad235f53e52df071fd9f7671c7f601n/a172.67.150.157:443
2021-10-21 08:34:33ee27906ef359e3d7b45ed1879d642588n/a104.21.30.56:443
2021-10-21 07:51:46ea612ce1e9ec617718136c8c68c86961n/a172.67.150.157:443
2021-10-21 07:02:08e5f8c0baa723ccdd1c22d305fff9255en/a172.67.150.157:443
2021-10-21 06:47:27e480da6f0346981b397337a462509195n/a172.67.152.176:443
2021-10-21 05:01:01d83d4126db81c97b234188f0ea84fb7an/a104.21.30.56:443
2021-10-21 04:19:19d175a3a30ac9d5e232abdbe34bbd0f9en/a172.67.222.123:443
2021-10-21 03:23:01c9f31f04be2c0ae64a1836d82d4a6ff1n/a172.67.150.157:443
2021-10-21 02:41:31c42c2ed07b9ce8bd3e28ec45eaa499a9n/a104.21.30.56:443
2021-10-21 02:40:33c40ba51615320f150a994af995bbebe3n/a172.67.150.157:443
2021-10-21 02:16:58c02935b4814eefbcd9769a031706546bn/a104.21.30.56:443
2021-10-21 01:40:06bafe423dded34af096a893ce2215e1c4n/a172.67.222.123:443
2021-10-21 01:36:04ba583bb78877c1f55f8aae54c0edf73en/a172.67.222.123:443
2021-10-21 01:14:08b6604ada9f95df084e4da796819f781bn/a104.21.30.56:443
2021-10-21 01:06:57b6688534df6bc4fe862eb64c7a09402cn/a172.67.150.157:443
2021-10-21 00:51:12b3a4b7052a2e2fbe5f445b0e5b362b0en/a172.67.222.98:443
2021-10-21 00:44:24b26983ce051a2e6f1a0f79bf93c0fb20n/a104.21.12.54:443
2021-10-21 00:44:24b26983ce051a2e6f1a0f79bf93c0fb20n/a172.67.193.175:443
2021-10-20 19:37:55a691661419fc005cd6a23cc27b61c034n/a172.67.152.176:443
2021-10-20 08:41:47a207fd55de16f9c80c8c7b36b6e9891an/a104.21.72.158:443
2021-10-20 05:16:58a068de0f9fdcae5b5c81c81310f8328an/a104.21.4.81:443
2021-10-20 04:22:05586d77a1ec8c58dce41a2bef7813f678Virustotal results 31 / 66 (46.97%) 172.67.152.176:443
2021-10-20 03:26:359a15910f1d441a40186cf5aafca044a1n/a172.67.152.84:443
2021-10-20 03:03:090d5160a9042e84c221186942905b9416Virustotal results 35 / 69 (50.72%) 104.21.70.96:443
2021-10-20 02:22:59643d5d765dfd96da8b6d329569a3568aVirustotal results 45 / 67 (67.16%) 172.67.131.206:443
2021-10-20 00:56:0303cf8acabf04bc1b78f8820fec45400dVirustotal results 32 / 67 (47.76%) 172.67.152.176:443
2021-10-20 00:12:3054585ec9359ad9b88d10a2fb28433b4cVirustotal results 32 / 66 (48.48%) 104.21.30.56:443
2021-10-19 23:44:2089ff34d653d240d544abf009a8023857n/a172.67.150.157:443
2021-10-19 23:28:118517969dce615c4646c5b9daf51abd33Virustotal results 36 / 67 (53.73%) 172.67.150.157:443
2021-10-19 20:30:3176b50a594c76b21fc269a5e46451c173n/a172.67.150.157:443
2021-10-19 20:30:2175eafb4fb8cee1e0984c5e847a3c8fdcn/a172.67.222.123:443
2021-10-19 20:07:426c69ef22e37cc3cd8299b6c11ce0b241n/a172.67.150.157:443
2021-10-19 19:49:21675a9aad7549bb6357e5f820fa3652dcn/a172.67.150.157:443
2021-10-19 19:45:20651d20cff9b5cc888e2696e29b7ba598n/a104.21.30.56:443
2021-10-19 19:20:2755f82b24f2f73a4865d03c55f8b1e44bn/a172.67.152.176:443
2021-10-19 18:24:395282ba84cb391d2228403b992db43536n/a172.67.152.176:443
2021-10-19 18:12:074ec70237b2a6020c7fd9e7b98ce06845n/a172.67.131.206:443
2021-10-19 16:27:502d94e930dcf3a04951d627e63e9bc808n/a104.21.30.56:443
2021-10-19 16:01:10256cca1f4df6502cdddfdcd9d5e569efn/a172.67.150.157:443
2021-10-19 15:54:49212f04a1cc3da645da684582d6f25bcbn/a172.67.150.157:443
2021-10-19 13:21:0206fef25d5b9bcee4f27aac140fef47dfn/a79.133.177.229:443
2021-10-19 10:35:0514236393ba52aab0d3d64c422f122946n/a104.21.72.158:443
2021-10-19 10:23:38026d7170e9e8be4b858f5ce43a67a7c9n/a104.21.72.158:443
2021-10-19 05:17:16029d84d6b6b2e5b24c24a4a3c2827852n/a104.21.72.158:443
2021-10-19 02:17:05df9be171d2d35a870f5f204e7251ef51n/a172.67.150.157:443
2021-10-19 02:07:17060f358768ff12c20ddf68f061cf88acn/a172.67.152.176:443
2021-10-19 00:49:000456d83d420161d6ed43367a86afe211n/a104.21.30.56:443
2021-10-18 22:34:0809560ce2ab30c4a8a478a55e32a539b4n/a104.21.30.56:443
2021-10-18 19:19:49b412bc56c262cf43049c102efc87688an/a172.67.150.157:443
2021-10-18 18:26:21b97074f1b9ef7154e233a96f59d8e158n/a104.21.30.56:443
2021-10-18 17:57:44bb897ca6509efff20d6a47d7f710d649n/a104.21.30.56:443
2021-10-18 06:28:35912c4b57769576ce7811f7933d81de16Virustotal results 27 / 60 (45.00%) 172.67.150.157:443
2021-10-18 02:29:41a9677ced6f0c3c08cb62d24aee9bc7ban/a104.21.30.56:443
2021-10-18 00:27:19a41e5582f1ee0330fcf1d6dc3b2667c7n/a79.133.177.232:443
2021-10-17 23:15:41a0f3c1403537932d7da2e3e27589c5e7Virustotal results 43 / 67 (64.18%) 172.67.152.84:443
2021-10-17 20:31:56724013560449193db1b31b32886e072fn/a172.67.222.123:443
2021-10-17 20:31:0172c3a23d1b4192b5c18870a5e026ab27n/a172.67.150.157:443
2021-10-17 19:51:316463eec99624bb70a251e6fa1c8f8515n/a172.67.222.123:443
2021-10-17 19:23:565c487ff0d1bfe5cdb7577d5f349bf0c1n/a172.67.222.123:443
2021-10-17 18:37:124b713ca17afff61ec6dce7cbf769af4en/a104.21.30.56:443
2021-10-17 18:16:5842fcda80a3633c71ce927a3d68650871n/a172.67.150.157:443
2021-10-17 17:57:233b4159d00df519744b6fe5d26cb99edcn/a172.67.150.157:443
2021-10-17 17:36:1831264210f6ab67bb0836809be16b4523n/a104.21.72.158:443
2021-10-17 16:08:091ece664314a1d8dd59bcb1e8affa6c6dVirustotal results 37 / 69 (53.62%) 104.21.30.56:443
2021-10-17 13:16:51f7aa6e0bd01f48a3c2f4e583cdeab1e5n/a104.21.30.56:443
2021-10-17 12:59:11f23f65964c9886762b7a23139f89a18fn/a172.67.222.123:443
2021-10-17 12:39:57eb3ed6ba0e20a4e250cd0a430f68a42dn/a172.67.131.206:443
2021-10-17 12:06:55e293665528f69fede6c54897947e1de2n/a104.21.70.96:443
2021-10-17 11:49:13dca2bd3ceb85c191a16ef20a66482dd0n/a172.67.222.98:443
2021-10-17 07:49:36b0f2ea2494e4285def6a6aec802896d5n/a104.21.30.56:443
2021-10-17 03:36:41a9c436008afed9dff9ef065a6f5a7028n/a104.21.30.56:443
2021-10-17 01:18:34a60bee5d44c2cbf5d35c320d94befeb3n/a104.21.30.56:443
2021-10-16 21:40:369422387f3acb2d53686a6c0c63e6be5cn/a104.21.30.56:443
2021-10-16 21:16:008f7d0dacc3f63b4b7c460a4c2f210695Virustotal results 36 / 67 (53.73%) 172.67.150.157:443
2021-10-16 20:33:1293b2458d3d73502eff1c6c866307d522n/a172.67.150.157:443
2021-10-16 20:09:480c5fd154a262868f9154ac8dab339f91Virustotal results 35 / 68 (51.47%) 104.21.30.56:443
2021-10-16 20:00:5588fb5ef1c8c54c31e480fb0284ef7b85n/a104.21.30.56:443
2021-10-16 19:58:273f23daebb9287303e7f6b255bcd9dd8eVirustotal results 31 / 66 (46.97%) 104.21.30.56:443
2021-10-16 19:50:47865e5691f84f60681006eb3c35acdc15n/a172.67.150.157:443
2021-10-16 18:32:4571b754225c5c929eed85fe9dbc12dc02n/a172.67.222.98:443
2021-10-16 18:28:19736dc864c7bbe156c1a417aff1fa6a82n/a172.67.193.175:443
2021-10-16 13:32:29ff823cde792d96c6645dabf898d1f101n/a104.21.70.96:443
2021-10-16 12:41:45feb14b7786f3a45ce2f4586475a554ddn/a104.21.30.56:443
2021-10-16 12:40:31fea77eadf95c0a0b45fb1aa6c7135708n/a172.67.152.84:443
2021-10-16 12:21:24fe5e5bf8a4683ddf0be280d8906e99f2n/a104.21.70.96:443
2021-10-16 11:14:26fd378acb57731c7e5f9da8da5aade145n/a104.21.70.96:443
2021-10-16 11:05:44fd01b409ce673343588529ff3272abb7n/a172.67.150.157:443
2021-10-16 07:07:19f8e858e122df2c0e1584bf51b909d907n/a172.67.150.157:443
2021-10-16 06:22:58b18b3a112af7f4d57380d3fda9ad7922n/a79.133.177.226:443
2021-10-16 06:21:50b27bfac81c30c58e472c85b5c5896825n/a172.67.152.176:443

# of entries: 100 (max: 100)