JA3 Fingerprints

You can find further information about the JA3 fingerprint fd80fa9c6120cdeea8520510f3c644ac, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:fd80fa9c6120cdeea8520510f3c644ac
First seen:2018-03-11 09:34:30 UTC
Last seen:2019-09-10 10:00:50 UTC
Status:Blacklisted
Malware samples:439
Destination IPs:56
Malware:Tofsee -
Listing date:2018-11-14 00:00:00

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2019-09-10 10:00:50bf38ec6f5357a6416f57fa1690e9852dVirustotal results 40 / 68 (58.82%) 104.27.187.184:443
2019-09-09 03:29:40d3e0dc2a11169395a1398ba55d2b848cVirustotal results 41 / 70 (58.57%) 104.27.187.184:443
2019-09-08 18:14:300fc42aa441bb0f290954fc0fd119572dn/a104.27.186.184:443
2019-09-08 17:37:46fe0e3d96233287f05b0d97e5069020aaVirustotal results 28 / 70 (40.00%) 104.27.186.184:443
2019-08-29 04:59:59742ccf084a1a6afc151d354e23b4be71Virustotal results 32 / 70 (45.71%) 104.27.187.184:443
2019-08-26 16:32:388658c32ac62efb9cab3b6208ace9fd62n/a87.240.129.135:443
2019-08-26 16:24:474cb964234a61935f587a19ce03ee5f4an/a87.240.129.135:443
2019-08-26 14:24:26660da2beb2dfa7abf64a03cb84216221n/a87.240.129.181:443
2019-08-26 13:55:51134137e7e564e7e325bbcfb66f2e8875n/a87.240.129.181:443
2019-08-26 13:15:05efcfdd799f6125c7d8e5967a70cbadcen/a87.240.129.135:443
2019-08-26 06:38:38bd0ac6088b3d592aac40a27ef519aecfn/a87.240.129.181:443
2019-08-26 05:54:2644bed7131090fe4f2e21b743bda1d91en/a87.240.129.181:443
2019-08-26 05:25:31fba59b27a3145edfaa4061fb199d29a7n/a87.240.129.135:443
2019-08-26 02:49:133c3581f01efb28d7f1e71afb2d29aed9n/a87.240.129.181:443
2019-08-26 02:40:497a25b766f65b2e4eaf5519831f09189dn/a87.240.129.135:443
2019-08-26 01:56:343e1fda8c9192a19980cb75ca6bbc7cccn/a87.240.129.181:443
2019-08-26 00:04:303b575ae43b1cb11501549ab2fdc85679n/a87.240.129.135:443
2019-08-25 23:42:5248c046e036adcc3a7fe3ba9fd6d4ac9dn/a87.240.129.135:443
2019-08-25 20:35:193c60da03b94b10eafa33ddd2b97ea387n/a87.240.129.135:443
2019-08-25 20:35:07f2cdf19b478c5de457f7bab9f4fc2e1bn/a87.240.129.181:443
2019-08-25 20:19:02b28d044c0d84107c1ec85224c4e98f92n/a87.240.129.181:443
2019-08-24 04:15:33f7575ef1f1475f559f36f90d1626c49cVirustotal results 62 / 68 (91.18%) 104.27.187.184:443
2019-08-22 20:16:546d978c8c98bd9e132cbc77adca4eb515Virustotal results 28 / 71 (39.44%) 104.27.186.184:443
2019-08-17 09:20:258b5c0bfc0778fd48ad844093c78cf0c2Virustotal results 29 / 66 (43.94%) 104.27.186.184:443
2019-08-16 09:10:320f9ee3afa0672dcb4f7f01027afe8133Virustotal results 31 / 66 (46.97%) 104.27.187.184:443
2019-08-16 09:10:320f9ee3afa0672dcb4f7f01027afe8133Virustotal results 31 / 66 (46.97%) 104.27.186.184:443
2019-08-10 13:43:35364913d5f7db89de1fd4c84001ce210dVirustotal results 22 / 66 (33.33%) 104.27.186.184:443
2019-08-10 13:43:35364913d5f7db89de1fd4c84001ce210dVirustotal results 22 / 66 (33.33%) 104.27.187.184:443
2019-08-10 01:23:031adf2d851a29e28788ea3ac234cad419Virustotal results 27 / 67 (40.30%) 104.27.186.184:443
2019-08-05 12:50:04b9cc10433add686ccae488692b4c2473Virustotal results 24 / 68 (35.29%) 104.27.187.184:443
2019-07-30 04:01:54121d2825eacdef780dc38eaadbc09261Virustotal results 59 / 69 (85.51%) 104.27.187.184:443
2019-07-09 17:28:32bd88dc6d2fedec6468452602a9da1ab8n/a54.174.88.98:443
2019-05-19 03:23:046b3656c5adf8f094f252455982c7f546Virustotal results 42/73 (57.53%) 35.186.213.138:443
2019-04-03 08:29:10296e6142d96056408775066fa1d1610fn/a104.27.168.6:443
2019-04-03 07:04:58f39205cd04903935e3463cc5463e4074n/a104.27.169.6:443
2019-02-12 17:41:332ca992d43dc292368b9b37ce9e9cb032Virustotal results 40/71 (56.34%) 104.18.46.159:443
2018-11-29 13:40:25ebbc767e8d1540a8614e05da97a398f7Virustotal results 33/70 (47.14%) 104.20.208.21:443
2018-11-22 16:18:20a3f0d4f18f1b20f8931f07a2658edcf7Virustotal results 34/67 (50.75%) 104.36.193.133:443
2018-11-22 16:18:17a3f0d4f18f1b20f8931f07a2658edcf7Virustotal results 34/67 (50.75%) 104.36.192.249:443
2018-11-20 23:29:1483a40a0417d7bc1addec11945d4f4acbVirustotal results 36/65 (55.38%) 104.36.192.191:443
2018-11-20 23:29:1383a40a0417d7bc1addec11945d4f4acbVirustotal results 36/65 (55.38%) 104.36.192.215:443
2018-11-20 05:30:33be5155baf905961fbff0caf07902ce62Virustotal results 27/66 (40.91%) 104.36.194.221:443
2018-11-20 05:30:30be5155baf905961fbff0caf07902ce62Virustotal results 27/66 (40.91%) 104.36.194.225:443
2018-11-20 05:30:30be5155baf905961fbff0caf07902ce62Virustotal results 27/66 (40.91%) 104.36.195.139:443
2018-11-20 05:30:28be5155baf905961fbff0caf07902ce62Virustotal results 27/66 (40.91%) 104.36.194.138:443
2018-11-18 09:28:477fd59b6093f5554080de55353270554cVirustotal results 43/68 (63.24%) 104.36.194.202:443
2018-11-18 09:28:457fd59b6093f5554080de55353270554cVirustotal results 43/68 (63.24%) 104.36.192.246:443
2018-11-18 09:28:447fd59b6093f5554080de55353270554cVirustotal results 43/68 (63.24%) 104.36.194.173:443
2018-08-02 06:13:15746eb72fe4d5096d836aefce59d06590Virustotal results 38/68 (55.88%) 159.53.224.16:443
2018-07-29 18:56:24d040f181a80d68fa1c4f743f8982a0deVirustotal results 28/68 (41.18%) 159.53.224.16:443
2018-07-28 01:26:023c5fbdb5a263876d9482d1c4adc5d204Virustotal results 12/68 (17.65%) 159.53.85.79:443
2018-07-28 01:26:023c5fbdb5a263876d9482d1c4adc5d204Virustotal results 12/68 (17.65%) 159.53.113.224:443
2018-07-24 01:04:58bb1ef3cfc6ed06a5467abb5ab0543566Virustotal results 29/67 (43.28%) 159.53.224.16:443
2018-07-20 19:40:2797eb18c3777a68e1bb5306391669f27fVirustotal results 43/68 (63.24%) 159.53.224.16:443
2018-06-28 00:12:39735300e6d74aee8cd4645a72a8310e63Virustotal results 15/69 (21.74%) 13.81.65.66:443
2018-06-14 16:48:31533d2f82043f73c0def377ebc2240b8eVirustotal results 42/68 (61.76%) 13.81.65.66:443
2018-06-13 00:36:0978a8905672e1ce08e0bde783701837c7Virustotal results 20/66 (30.30%) 13.93.161.37:443
2018-06-07 15:08:04e4dc03171de9820704f39c606a41bc16Virustotal results 35/68 (51.47%) 13.81.65.66:443
2018-06-07 15:08:04e4dc03171de9820704f39c606a41bc16Virustotal results 35/68 (51.47%) 131.253.61.98:443
2018-06-07 15:08:04e4dc03171de9820704f39c606a41bc16Virustotal results 35/68 (51.47%) 131.253.61.102:443
2018-06-07 15:08:04e4dc03171de9820704f39c606a41bc16Virustotal results 35/68 (51.47%) 2.16.124.231:443
2018-06-07 15:08:04e4dc03171de9820704f39c606a41bc16Virustotal results 35/68 (51.47%) 159.53.84.131:443
2018-06-07 15:08:04e4dc03171de9820704f39c606a41bc16Virustotal results 35/68 (51.47%) 159.53.62.96:443
2018-06-07 15:08:04e4dc03171de9820704f39c606a41bc16Virustotal results 35/68 (51.47%) 91.190.217.145:443
2018-06-07 15:08:04e4dc03171de9820704f39c606a41bc16Virustotal results 35/68 (51.47%) 131.253.61.64:443
2018-06-07 15:08:04e4dc03171de9820704f39c606a41bc16Virustotal results 35/68 (51.47%) 131.253.61.82:443
2018-06-07 15:08:04e4dc03171de9820704f39c606a41bc16Virustotal results 35/68 (51.47%) 131.253.61.100:443
2018-06-07 15:08:04e4dc03171de9820704f39c606a41bc16Virustotal results 35/68 (51.47%) 104.20.15.146:443
2018-06-07 15:08:04e4dc03171de9820704f39c606a41bc16Virustotal results 35/68 (51.47%) 52.138.209.16:443
2018-06-07 15:08:04e4dc03171de9820704f39c606a41bc16Virustotal results 35/68 (51.47%) 131.253.61.66:443
2018-06-07 15:08:04e4dc03171de9820704f39c606a41bc16Virustotal results 35/68 (51.47%) 104.20.14.146:443
2018-06-07 15:08:04e4dc03171de9820704f39c606a41bc16Virustotal results 35/68 (51.47%) 185.89.12.132:443
2018-06-07 15:08:04e4dc03171de9820704f39c606a41bc16Virustotal results 35/68 (51.47%) 131.253.61.96:443
2018-06-07 15:08:04e4dc03171de9820704f39c606a41bc16Virustotal results 35/68 (51.47%) 159.53.52.227:443
2018-06-03 16:30:095b922aaac0ee75c06fb8ec3c7498296bVirustotal results 13/65 (20.00%) 13.81.65.66:443
2018-06-03 10:28:50bb6bbbb072f6ec4e91f4d0426c7c91c9Virustotal results 31/66 (46.97%) 13.81.65.66:443
2018-06-03 10:28:50bb6bbbb072f6ec4e91f4d0426c7c91c9Virustotal results 31/66 (46.97%) 91.190.217.145:443
2018-06-03 10:28:50bb6bbbb072f6ec4e91f4d0426c7c91c9Virustotal results 31/66 (46.97%) 131.253.61.96:443
2018-06-03 09:46:18d6651dfa3f02270bc93cc3c1f6918d17Virustotal results 18/66 (27.27%) 13.81.65.66:443
2018-06-03 09:44:16a0d0807e8f6e34b7c262652dcb626138Virustotal results 13/66 (19.70%) 13.81.65.66:443
2018-06-03 02:18:070a6d5427970d2a9ac51dcace66cb56a2Virustotal results 22/66 (33.33%) 13.93.161.37:443
2018-06-01 20:03:007ec3ad772c87bd04c113459469c75f6fVirustotal results 45/67 (67.16%) 13.81.65.66:443
2018-05-31 20:24:44c107290225c7a938b78fb6c9b9cf6b96Virustotal results 40/67 (59.70%) 13.81.65.66:443
2018-05-31 16:16:574419de9cd68502b91acb38214ea4e411Virustotal results 35/66 (53.03%) 13.93.161.37:443
2018-05-30 20:14:45c8e5a6f0366801b54f4db6b15929222eVirustotal results 13/65 (20.00%) 13.81.65.66:443
2018-05-30 04:55:18ee18fade361542966b4691f15fa528d7Virustotal results 43/66 (65.15%) 91.190.217.145:443
2018-05-30 04:55:18ee18fade361542966b4691f15fa528d7Virustotal results 43/66 (65.15%) 13.81.65.66:443
2018-05-29 23:01:5059b8b09e8def0644b0c03c394796c4b4Virustotal results 28/64 (43.75%) 13.81.65.66:443
2018-05-29 07:13:39ec5594f16d9f4eef0688e974db48b515Virustotal results 42/64 (65.62%) 13.81.65.66:443
2018-05-29 07:13:39ec5594f16d9f4eef0688e974db48b515Virustotal results 42/64 (65.62%) 91.190.217.145:443
2018-05-29 03:18:0866862bfce12c9070427de52a91712c69Virustotal results 8/66 (12.12%) 91.190.217.145:443
2018-05-29 03:18:0866862bfce12c9070427de52a91712c69Virustotal results 8/66 (12.12%) 131.253.61.66:443
2018-05-29 03:18:0866862bfce12c9070427de52a91712c69Virustotal results 8/66 (12.12%) 131.253.61.98:443
2018-05-28 17:31:376d8371cd42322e64cd99141cc8f3e1d9Virustotal results 31/66 (46.97%) 104.20.14.146:443
2018-05-28 17:31:376d8371cd42322e64cd99141cc8f3e1d9Virustotal results 31/66 (46.97%) 185.89.12.132:443
2018-05-28 17:31:376d8371cd42322e64cd99141cc8f3e1d9Virustotal results 31/66 (46.97%) 13.81.65.66:443
2018-05-28 07:57:46c4e43db8e4974f53ed12418727323904Virustotal results 20/66 (30.30%) 52.138.209.16:443
2018-05-27 16:49:29776195c2c1b308a058b81eceed594120Virustotal results 48/66 (72.73%) 13.81.65.66:443
2018-05-27 16:49:29776195c2c1b308a058b81eceed594120Virustotal results 48/66 (72.73%) 52.138.209.16:443
2018-05-26 17:51:006fefeca48f284c1611265187b1c0436eVirustotal results 30/66 (45.45%) 13.81.65.66:443

# of entries: 100 (max: 100)