JA3 Fingerprints

You can find further information about the JA3 fingerprint fd80fa9c6120cdeea8520510f3c644ac, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:fd80fa9c6120cdeea8520510f3c644ac
First seen:2018-03-11 09:34:30 UTC
Last seen:2020-11-25 11:26:06 UTC
Status:Blacklisted
Malware samples:2'249
Destination IPs:245
Malware:Tofsee -
Listing date:2018-11-14 00:00:00

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2020-11-25 11:26:06d8ad7c73831bc5fcc17a891e47f93813Virustotal results 50 / 68 (73.53%) 104.27.167.5:443
2020-11-25 11:26:06d8ad7c73831bc5fcc17a891e47f93813Virustotal results 50 / 68 (73.53%) 172.67.136.89:443
2020-11-25 11:12:21d81929308a5c655550e1a744825d1d15n/a212.82.100.140:443
2020-11-25 11:12:21d81929308a5c655550e1a744825d1d15n/a31.13.72.36:443
2020-11-25 11:09:15d80fb9c68d2093a626490c8bc551cac4Virustotal results 53 / 68 (77.94%) 104.31.68.84:443
2020-11-25 11:04:41d784971f40e700c4d56f948d0160396eVirustotal results 53 / 71 (74.65%) 212.82.100.140:443
2020-11-25 11:04:41d784971f40e700c4d56f948d0160396eVirustotal results 53 / 71 (74.65%) 31.13.72.36:443
2020-11-25 10:54:44d775cc15f95ff18090a71677bd346409n/a172.67.219.32:443
2020-11-25 10:54:44d775cc15f95ff18090a71677bd346409n/a104.24.122.22:443
2020-11-25 10:52:09d74cc197f529ac279d385fd36e0ea5c3Virustotal results 47 / 69 (68.12%) 104.24.123.22:443
2020-11-25 10:52:09d74cc197f529ac279d385fd36e0ea5c3Virustotal results 47 / 69 (68.12%) 172.67.219.32:443
2020-11-25 10:50:11d7358921729c71733858353555fd7fc8Virustotal results 49 / 69 (71.01%) 172.67.219.32:443
2020-11-25 10:23:56d64b18cb4652309178530f6f0f12d70cn/a172.67.219.32:443
2020-11-25 10:01:06cf5166bf0247262a7852eecf46a47ecbVirustotal results 55 / 72 (76.39%) 31.13.72.36:443
2020-11-25 10:01:06cf5166bf0247262a7852eecf46a47ecbVirustotal results 55 / 72 (76.39%) 212.82.100.140:443
2020-11-25 09:47:07cf0457c2990075d04ae85e62dc1c06edVirustotal results 58 / 71 (81.69%) 212.82.100.140:443
2020-11-25 09:47:06cf0457c2990075d04ae85e62dc1c06edVirustotal results 58 / 71 (81.69%) 31.13.72.36:443
2020-11-25 09:41:54d224d1218bd66fd1c6eebaddb9599c63Virustotal results 29 / 69 (42.03%) 104.24.122.22:443
2020-11-25 09:41:54d224d1218bd66fd1c6eebaddb9599c63Virustotal results 29 / 69 (42.03%) 172.67.219.32:443
2020-11-25 08:23:11c6a04f650e41267d319e90c413933afbVirustotal results 38 / 61 (62.30%) 104.24.122.22:443
2020-11-25 08:23:11c6a04f650e41267d319e90c413933afbVirustotal results 38 / 61 (62.30%) 172.67.219.32:443
2020-11-25 07:44:36c00f0caac51db26ed3b24659c0a81e75Virustotal results 52 / 70 (74.29%) 172.67.219.32:443
2020-11-25 06:23:48b12a03841e31e2e3f6997277f7b35f72n/a104.28.14.61:443
2020-11-25 06:23:48b12a03841e31e2e3f6997277f7b35f72n/a104.28.15.61:443
2020-11-25 03:39:25aae32373dadf34f5e583ecd5f06cf9e6Virustotal results 46 / 70 (65.71%) 104.28.14.61:443
2020-11-25 03:39:25aae32373dadf34f5e583ecd5f06cf9e6Virustotal results 46 / 70 (65.71%) 104.28.15.61:443
2020-11-25 01:16:26a722d84fdcb05ab517fb96c7aef319afVirustotal results 56 / 70 (80.00%) 104.31.68.84:443
2020-11-25 01:16:26a722d84fdcb05ab517fb96c7aef319afVirustotal results 56 / 70 (80.00%) 172.67.205.170:443
2020-11-25 01:12:36a6fffc6eb460ad9307b375579f8b2450Virustotal results 51 / 69 (73.91%) 172.67.131.206:443
2020-11-25 01:12:36a6fffc6eb460ad9307b375579f8b2450Virustotal results 51 / 69 (73.91%) 104.28.15.61:443
2020-11-25 00:41:50a3f81a5a916e27b5eed6a2903a5b7532Virustotal results 49 / 71 (69.01%) 74.6.160.138:443
2020-11-25 00:41:50a3f81a5a916e27b5eed6a2903a5b7532Virustotal results 49 / 71 (69.01%) 45.60.53.141:443
2020-11-24 23:33:21a0b1da0c6f96cdaa20dd3e802089bbc3Virustotal results 45 / 70 (64.29%) 104.28.15.61:443
2020-11-24 23:33:21a0b1da0c6f96cdaa20dd3e802089bbc3Virustotal results 45 / 70 (64.29%) 172.67.131.206:443
2020-11-24 23:05:5894d81036179b84a17e86bd0bd0179b8bVirustotal results 44 / 69 (63.77%) 172.64.100.5:443
2020-11-24 23:05:10912cd9764ec0dac383267c73163147d8n/a172.64.100.5:443
2020-11-24 23:01:238b2d6c95d4115c635d1a8a2bca075d34n/a172.64.101.5:443
2020-11-24 23:01:238b2d6c95d4115c635d1a8a2bca075d34n/a172.64.100.5:443
2020-11-24 22:41:287639dca2807d0b0678669ae0dd20b4d4Virustotal results 50 / 72 (69.44%) 212.82.100.140:443
2020-11-24 22:34:4371953ecfe06140c14aaac297dfa52644Virustotal results 45 / 69 (65.22%) 172.64.101.5:443
2020-11-24 21:45:5446900e718d7abb61de6059c443f7c432Virustotal results 18 / 71 (25.35%) 172.64.101.5:443
2020-11-24 21:39:143f0ce49bbe596372fa2d5ddc21f62848n/a104.31.68.84:443
2020-11-24 21:39:143f0ce49bbe596372fa2d5ddc21f62848n/a104.31.69.84:443
2020-11-24 21:25:4026bc614a7c49f748771ced3ff6642232Virustotal results 51 / 71 (71.83%) 212.82.100.140:443
2020-11-24 21:18:33271994abb14675c7a67c7854a884d2bdVirustotal results 43 / 70 (61.43%) 172.64.101.5:443
2020-11-24 21:18:33271994abb14675c7a67c7854a884d2bdVirustotal results 43 / 70 (61.43%) 172.64.100.5:443
2020-11-24 21:13:2302837fa2fa5ed064ba1d9a9e52f1ec2en/a172.64.100.5:443
2020-11-24 21:13:2302837fa2fa5ed064ba1d9a9e52f1ec2en/a172.64.101.5:443
2020-11-24 21:11:261589333122c6e578080f65391807eaa2n/a172.67.205.170:443
2020-11-24 21:11:261589333122c6e578080f65391807eaa2n/a104.31.69.84:443
2020-11-24 21:01:312100cc4a8465ec536c9a42dcb5ef3344Virustotal results 50 / 72 (69.44%) 212.82.100.140:443
2020-11-24 21:01:312100cc4a8465ec536c9a42dcb5ef3344Virustotal results 50 / 72 (69.44%) 31.13.72.36:443
2020-11-24 21:01:302100cc4a8465ec536c9a42dcb5ef3344Virustotal results 50 / 72 (69.44%) 157.240.194.35:443
2020-11-24 20:51:121cb142cd2a85eff063ea413ca5332ff9n/a212.82.100.140:443
2020-11-24 20:47:46b0a256a4ac3afc1c9175603dd8aa42daVirustotal results 40 / 72 (55.56%) 212.82.100.140:443
2020-11-24 20:47:42b0a256a4ac3afc1c9175603dd8aa42daVirustotal results 40 / 72 (55.56%) 31.13.72.36:443
2020-11-24 20:46:040d1c0e17b29f0c414d71c3bd84ac47e8Virustotal results 48 / 70 (68.57%) 172.64.100.5:443
2020-11-24 20:45:16129a483b0ecba4ea903a9cd69cabbbe7Virustotal results 51 / 71 (71.83%) 104.28.14.61:443
2020-11-24 20:45:16129a483b0ecba4ea903a9cd69cabbbe7Virustotal results 51 / 71 (71.83%) 172.67.131.206:443
2020-11-24 19:09:03b41c1ed086a17f485c703763507867c8Virustotal results 41 / 72 (56.94%) 172.67.205.170:443
2020-11-24 19:09:02b41c1ed086a17f485c703763507867c8Virustotal results 41 / 72 (56.94%) 104.31.68.84:443
2020-11-23 21:35:556f0bb0ef5eb6e94c0e501f29444af877n/a104.28.14.61:443
2020-11-23 21:35:556f0bb0ef5eb6e94c0e501f29444af877n/a172.67.131.206:443
2020-11-23 21:12:535e799574662a6df3611b9200336c388cVirustotal results 49 / 72 (68.06%) 172.64.197.15:443
2020-11-23 20:56:3953b9c1165e7737448271a22d0089dc13Virustotal results 44 / 70 (62.86%) 172.64.196.15:443
2020-11-23 20:56:3953b9c1165e7737448271a22d0089dc13Virustotal results 44 / 70 (62.86%) 172.64.197.15:443
2020-11-23 20:08:3103003e0a32d48983e839a58c47ae3317Virustotal results 43 / 72 (59.72%) 172.64.196.15:443
2020-11-23 20:08:3003003e0a32d48983e839a58c47ae3317Virustotal results 43 / 72 (59.72%) 172.64.197.15:443
2020-11-23 20:01:0904c1b7ca98690f8dcd3ee047f6803364n/a172.64.196.15:443
2020-11-23 16:09:25a8f9b750911e0bb1098b0ccfb610c2f0Virustotal results 40 / 72 (55.56%) 104.28.5.155:443
2020-11-23 16:02:54a8b4fa4c274ec6d5572d1138b3c9a99en/a104.28.15.61:443
2020-11-23 04:11:04a2c03178d5c9f88ad8752bfb69b6c1abn/a104.24.123.22:443
2020-11-23 02:56:119d995b94ddaa01a9d1bd1fc5bc0e3c6bVirustotal results 58 / 72 (80.56%) 104.24.122.22:443
2020-11-23 02:51:589cb05a28ad49accdf8641a22ff088ea3n/a104.28.14.61:443
2020-11-23 02:51:589cb05a28ad49accdf8641a22ff088ea3n/a172.67.205.170:443
2020-11-23 02:51:589cb05a28ad49accdf8641a22ff088ea3n/a172.67.131.206:443
2020-11-23 02:38:38998da825df582fcfbb2c67cfd1a63bbcn/a172.67.219.32:443
2020-11-23 02:33:1196f21229be085c87414a53b1f17b9e81n/a104.28.5.155:443
2020-11-23 01:38:4383a160a453695f9b31a9347dddde04d0Virustotal results 54 / 71 (76.06%) 104.24.122.22:443
2020-11-23 01:38:4383a160a453695f9b31a9347dddde04d0Virustotal results 54 / 71 (76.06%) 104.24.123.22:443
2020-11-23 01:25:077edc0abf255f451d2e6e127d80af8570Virustotal results 46 / 71 (64.79%) 172.67.219.32:443
2020-11-23 01:25:067edc0abf255f451d2e6e127d80af8570Virustotal results 46 / 71 (64.79%) 104.24.123.22:443
2020-11-23 01:07:47779e04568981034b44a2962845893899n/a104.24.122.22:443
2020-11-23 01:07:47779e04568981034b44a2962845893899n/a104.24.123.22:443
2020-11-23 00:32:24689ea43e499b80bf9483f0975d4f9c15Virustotal results 28 / 69 (40.58%) 172.67.219.32:443
2020-11-23 00:32:24689ea43e499b80bf9483f0975d4f9c15Virustotal results 28 / 69 (40.58%) 104.24.122.22:443
2020-11-23 00:30:326906d8078921210e20092a4fec1fd9e2n/a104.24.123.22:443
2020-11-23 00:30:326906d8078921210e20092a4fec1fd9e2n/a172.67.219.32:443
2020-11-23 00:20:326546e9c4c877ec5c9bfd7d59da578069n/a104.28.14.61:443
2020-11-22 22:57:49459f9f48b1b46148232ab92b5371e3d3n/a104.24.122.22:443
2020-11-22 21:48:13381aabb877ba8aaee6a59d107814344cVirustotal results 51 / 70 (72.86%) 172.67.219.32:443
2020-11-22 21:48:13381aabb877ba8aaee6a59d107814344cVirustotal results 51 / 70 (72.86%) 104.24.122.22:443
2020-11-22 20:18:270dac04f4c57835525d31464bd3d58309n/a104.24.122.22:443
2020-11-22 20:18:270dac04f4c57835525d31464bd3d58309n/a172.67.219.32:443
2020-11-22 20:08:50080f2b61cdf8d14f68ee7934d0bb0402Virustotal results 41 / 69 (59.42%) 104.24.123.22:443
2020-11-22 20:08:50080f2b61cdf8d14f68ee7934d0bb0402Virustotal results 41 / 69 (59.42%) 172.67.219.32:443
2020-11-22 19:44:273434ea8c47a22cf4b59f550317579c6eVirustotal results 35 / 62 (56.45%) 172.64.196.15:443
2020-11-22 19:44:273434ea8c47a22cf4b59f550317579c6eVirustotal results 35 / 62 (56.45%) 172.64.197.15:443
2020-11-22 19:35:281fd7bf848f2650593d6ce75e64a69566Virustotal results 55 / 71 (77.46%) 104.31.69.84:443
2020-11-22 18:10:32c6d6a346ac3fe9a0d27b3346b4422ea6Virustotal results 46 / 72 (63.89%) 104.24.123.22:443

# of entries: 100 (max: 100)