JA3 Fingerprints

You can find further information about the JA3 fingerprint fd80fa9c6120cdeea8520510f3c644ac, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:fd80fa9c6120cdeea8520510f3c644ac
First seen:2018-03-11 09:34:30 UTC
Last seen:2020-07-07 19:50:13 UTC
Status:Blacklisted
Malware samples:1'354
Destination IPs:154
Malware:Tofsee -
Listing date:2018-11-14 00:00:00

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2020-07-07 19:50:13b831ca769c647c5f49fb93b4242336f1Virustotal results 41 / 73 (56.16%) 104.28.15.61:443
2020-07-07 12:29:50b34b1316ff4c4b635bca3e2342034405Virustotal results 41 / 73 (56.16%) 172.67.131.206:443
2020-07-07 06:25:57aefe797b0c593057abca3b00c5cc3531Virustotal results 41 / 73 (56.16%) 172.67.131.206:443
2020-07-07 06:25:57aefe797b0c593057abca3b00c5cc3531Virustotal results 41 / 73 (56.16%) 104.28.14.61:443
2020-07-07 05:29:50acc424ef96b17e7edbd80b7e25b89ed7Virustotal results 33 / 72 (45.83%) 172.67.131.206:443
2020-07-07 05:29:50acc424ef96b17e7edbd80b7e25b89ed7Virustotal results 33 / 72 (45.83%) 104.28.14.61:443
2020-07-05 22:48:07a35c81f592645fe0d5bc2fda9f13a88dVirustotal results 41 / 73 (56.16%) 104.28.15.61:443
2020-07-05 22:48:07a35c81f592645fe0d5bc2fda9f13a88dVirustotal results 41 / 73 (56.16%) 104.28.14.61:443
2020-06-30 07:18:29b72b431d4a6d4c87b2cdd417ee140984Virustotal results 16 / 72 (22.22%) 104.24.113.88:443
2020-06-30 07:07:09b5da8af9281f5d6794d2d8a019163127Virustotal results 42 / 73 (57.53%) 104.24.112.88:443
2020-06-30 07:07:09b5da8af9281f5d6794d2d8a019163127Virustotal results 42 / 73 (57.53%) 104.24.113.88:443
2020-06-30 06:16:48afe75081cb71f8eec454388e43fe60b9Virustotal results 47 / 73 (64.38%) 104.24.112.88:443
2020-06-30 05:53:35b04c98edbcb123a50975664822d94fc6Virustotal results 47 / 72 (65.28%) 104.24.112.88:443
2020-06-30 05:40:43afec3da7bba1f75182fdbff8a2d5e9d9Virustotal results 39 / 72 (54.17%) 104.24.113.88:443
2020-06-30 05:17:03b58a2605ccde36bdfb442cc72ee120afVirustotal results 46 / 72 (63.89%) 192.249.114.106:443
2020-06-30 05:17:03b58a2605ccde36bdfb442cc72ee120afVirustotal results 46 / 72 (63.89%) 198.71.232.15:443
2020-06-30 05:17:03b58a2605ccde36bdfb442cc72ee120afVirustotal results 46 / 72 (63.89%) 198.71.233.254:443
2020-06-30 05:17:03b58a2605ccde36bdfb442cc72ee120afVirustotal results 46 / 72 (63.89%) 35.184.78.1:443
2020-06-30 05:17:03b58a2605ccde36bdfb442cc72ee120afVirustotal results 46 / 72 (63.89%) 35.214.170.79:443
2020-06-30 05:17:03b58a2605ccde36bdfb442cc72ee120afVirustotal results 46 / 72 (63.89%) 172.106.170.133:443
2020-06-30 05:17:03b58a2605ccde36bdfb442cc72ee120afVirustotal results 46 / 72 (63.89%) 178.128.14.161:443
2020-06-30 05:17:02b58a2605ccde36bdfb442cc72ee120afVirustotal results 46 / 72 (63.89%) 198.46.134.245:443
2020-06-30 05:17:02b58a2605ccde36bdfb442cc72ee120afVirustotal results 46 / 72 (63.89%) 151.101.66.159:443
2020-06-29 16:01:12aeccf85a1961b0a1f7c1653c3203f205Virustotal results 44 / 74 (59.46%) 104.24.113.88:443
2020-06-29 16:01:12aeccf85a1961b0a1f7c1653c3203f205Virustotal results 44 / 74 (59.46%) 172.67.204.22:443
2020-06-29 04:20:10ad762207b2d557339c1793ecb4b8ff99Virustotal results 48 / 73 (65.75%) 172.67.204.22:443
2020-06-29 04:20:10ad762207b2d557339c1793ecb4b8ff99Virustotal results 48 / 73 (65.75%) 104.24.112.88:443
2020-06-29 03:42:29acfc4fdf75cc2f1f6e99fce020c820f2Virustotal results 40 / 67 (59.70%) 104.24.113.88:443
2020-06-29 03:42:29acfc4fdf75cc2f1f6e99fce020c820f2Virustotal results 40 / 67 (59.70%) 104.24.112.88:443
2020-06-28 12:22:2826e738c0aa7a82a70d5e82ad2ec07964Virustotal results 34 / 73 (46.58%) 104.24.112.88:443
2020-06-28 06:16:1814fc29cbed1208b2046a40d169d1122bVirustotal results 35 / 72 (48.61%) 104.24.112.88:443
2020-06-28 06:16:1714fc29cbed1208b2046a40d169d1122bVirustotal results 35 / 72 (48.61%) 104.24.113.88:443
2020-06-28 05:01:571153703a80f740171dbbf9a87990c423Virustotal results 36 / 71 (50.70%) 104.24.112.88:443
2020-06-28 05:01:571153703a80f740171dbbf9a87990c423Virustotal results 36 / 71 (50.70%) 172.67.204.22:443
2020-06-27 21:57:28a125e3e2a4e2328ed0affaed78fb6b5cVirustotal results 42 / 73 (57.53%) 104.24.113.88:443
2020-06-27 21:14:43ac63b500ecebab2ab5aafd5e496aae1dVirustotal results 41 / 73 (56.16%) 172.67.131.206:443
2020-06-27 21:14:43ac63b500ecebab2ab5aafd5e496aae1dVirustotal results 41 / 73 (56.16%) 104.24.112.88:443
2020-06-27 21:11:01a6bb73c5b2819dc6fa4c44b72b72d0d7Virustotal results 46 / 70 (65.71%) 104.24.112.88:443
2020-06-27 21:11:01a6bb73c5b2819dc6fa4c44b72b72d0d7Virustotal results 46 / 70 (65.71%) 104.24.113.88:443
2020-06-27 20:30:49abfa3d0f6bd31497e92a999ca2325859Virustotal results 38 / 72 (52.78%) 104.24.113.88:443
2020-06-27 20:30:49abfa3d0f6bd31497e92a999ca2325859Virustotal results 38 / 72 (52.78%) 104.24.112.88:443
2020-06-27 20:30:49ac8b6973fdc8a3bba4afefe2955d18f7Virustotal results 40 / 74 (54.05%) 172.67.204.22:443
2020-06-27 20:30:49ac8b6973fdc8a3bba4afefe2955d18f7Virustotal results 40 / 74 (54.05%) 104.24.113.88:443
2020-06-27 09:42:2036919dc8d7cafb0ef089e684fefd69ffVirustotal results 34 / 72 (47.22%) 104.24.112.88:443
2020-06-27 09:42:2036919dc8d7cafb0ef089e684fefd69ffVirustotal results 34 / 72 (47.22%) 172.67.204.22:443
2020-06-27 08:15:272efc1cf8ae77586cf9cf0893eca8d5d2Virustotal results 45 / 72 (62.50%) 104.28.24.59:443
2020-06-27 06:29:0428e889674e7fe1e728ae24e84b4a3b77Virustotal results 19 / 71 (26.76%) 172.67.204.22:443
2020-06-27 06:29:0428e889674e7fe1e728ae24e84b4a3b77Virustotal results 19 / 71 (26.76%) 104.24.112.88:443
2020-06-26 19:01:340847ca5cb2649c6e4cea28a2704e72d6Virustotal results 28 / 73 (38.36%) 104.24.112.88:443
2020-06-26 19:01:340847ca5cb2649c6e4cea28a2704e72d6Virustotal results 28 / 73 (38.36%) 172.67.204.22:443
2020-06-26 18:58:3002e7211a374a9e3268d0ce668692b186Virustotal results 37 / 74 (50.00%) 172.67.204.22:443
2020-06-26 18:47:150a1bf994a206b28bd310585caf85a877Virustotal results 29 / 73 (39.73%) 172.67.204.22:443
2020-06-26 18:47:150a1bf994a206b28bd310585caf85a877Virustotal results 29 / 73 (39.73%) 104.24.113.88:443
2020-06-26 15:59:56a1e3cea453da203ff0187a04d6c6efdbVirustotal results 41 / 73 (56.16%) 172.67.204.22:443
2020-06-26 15:59:56a1e3cea453da203ff0187a04d6c6efdbVirustotal results 41 / 73 (56.16%) 104.24.113.88:443
2020-06-26 15:15:28a0dd9b904166df361737765ce5ce6d36Virustotal results 47 / 72 (65.28%) 172.67.136.89:443
2020-06-26 15:15:28a0dd9b904166df361737765ce5ce6d36Virustotal results 47 / 72 (65.28%) 104.27.166.5:443
2020-06-26 13:21:4298e014e1a75d442d9e3fbc1cb861e6ddVirustotal results 45 / 73 (61.64%) 104.24.112.88:443
2020-06-26 13:21:4298e014e1a75d442d9e3fbc1cb861e6ddVirustotal results 45 / 73 (61.64%) 172.67.204.22:443
2020-06-26 07:51:383e54d41a1a94d7dc36b87fd0c8437318Virustotal results 39 / 72 (54.17%) 172.67.204.22:443
2020-06-26 07:51:383e54d41a1a94d7dc36b87fd0c8437318Virustotal results 39 / 72 (54.17%) 104.24.113.88:443
2020-06-26 06:52:311275af66bc6ed29deb842b29649c4251Virustotal results 48 / 73 (65.75%) 172.67.204.22:443
2020-06-26 06:52:311275af66bc6ed29deb842b29649c4251Virustotal results 48 / 73 (65.75%) 104.24.113.88:443
2020-06-26 06:29:0029153707db53303e05cab814e9c44bd3Virustotal results 33 / 72 (45.83%) 104.24.113.88:443
2020-06-26 06:26:392584c91f5b6600914286f74a3804ef74Virustotal results 41 / 74 (55.41%) 104.24.112.88:443
2020-06-26 06:26:392584c91f5b6600914286f74a3804ef74Virustotal results 41 / 74 (55.41%) 172.67.204.22:443
2020-06-25 23:55:531d8fe12b344edd6d5beb634f94b56194Virustotal results 46 / 70 (65.71%) 172.67.204.22:443
2020-06-25 23:55:531d8fe12b344edd6d5beb634f94b56194Virustotal results 46 / 70 (65.71%) 104.24.112.88:443
2020-06-25 16:56:5208ef6ea833345bb26aee32eea82b3244Virustotal results 7 / 72 (9.72%) 104.24.113.88:443
2020-06-25 16:56:5208ef6ea833345bb26aee32eea82b3244Virustotal results 7 / 72 (9.72%) 104.24.112.88:443
2020-06-25 16:16:320dcd083171bba67671d8d47d5131bca7n/a172.67.204.22:443
2020-06-25 14:05:54834f0d820514f870a1497b30dbe3aee5Virustotal results 49 / 73 (67.12%) 172.67.204.22:443
2020-06-25 13:34:5580ac36eb9967df51e07db1f73d3959deVirustotal results 38 / 73 (52.05%) 172.67.204.22:443
2020-06-25 13:34:5580ac36eb9967df51e07db1f73d3959deVirustotal results 38 / 73 (52.05%) 104.24.113.88:443
2020-06-25 13:16:167f0d4468aceef7045b631fc56b4c2c76Virustotal results 34 / 73 (46.58%) 104.24.113.88:443
2020-06-25 13:16:167f0d4468aceef7045b631fc56b4c2c76Virustotal results 34 / 73 (46.58%) 172.67.204.22:443
2020-06-25 12:06:18782f60758924f24557abb3b8d35ef13dVirustotal results 43 / 72 (59.72%) 104.24.113.88:443
2020-06-25 12:06:18782f60758924f24557abb3b8d35ef13dVirustotal results 43 / 72 (59.72%) 172.67.204.22:443
2020-06-25 11:59:1476471d534dfec97b01d1b87ddd5cf5eaVirustotal results 44 / 72 (61.11%) 104.24.113.88:443
2020-06-25 11:48:4275b8b598b765b9131914103cc44f2da2Virustotal results 33 / 72 (45.83%) 104.24.112.88:443
2020-06-25 08:45:49660d6f67b8a757e54fe9ddac14ec6d00Virustotal results 46 / 74 (62.16%) 104.24.112.88:443
2020-06-25 08:45:49660d6f67b8a757e54fe9ddac14ec6d00Virustotal results 46 / 74 (62.16%) 172.67.204.22:443
2020-06-25 07:25:545e97c020aadf7fcfaf05201b4912cc97Virustotal results 10 / 72 (13.89%) 172.67.204.22:443
2020-06-25 07:20:125cb1763645f858ce73ed1666b6fa9426Virustotal results 49 / 72 (68.06%) 104.24.113.88:443
2020-06-25 06:54:295ad7e1c8cf906306fcd512862ea8dfd9Virustotal results 44 / 74 (59.46%) 104.24.112.88:443
2020-06-25 06:54:295ad7e1c8cf906306fcd512862ea8dfd9Virustotal results 44 / 74 (59.46%) 172.67.204.22:443
2020-06-25 06:43:285a39f5438a6286309319b4c607686a6bVirustotal results 39 / 73 (53.42%) 104.24.112.88:443
2020-06-25 06:43:285a39f5438a6286309319b4c607686a6bVirustotal results 39 / 73 (53.42%) 172.67.204.22:443
2020-06-25 06:29:1057d524efa237bf296789fe684d27c108Virustotal results 43 / 74 (58.11%) 104.24.113.88:443
2020-06-25 06:29:1057d524efa237bf296789fe684d27c108Virustotal results 43 / 74 (58.11%) 104.24.112.88:443
2020-06-25 06:11:305778b6b7cb2222a9aca684a341d4c750Virustotal results 32 / 72 (44.44%) 172.67.204.22:443
2020-06-25 06:11:305778b6b7cb2222a9aca684a341d4c750Virustotal results 32 / 72 (44.44%) 104.24.112.88:443
2020-06-25 05:49:530569769f3d543e9f6ad6885505ad8194Virustotal results 10 / 73 (13.70%) 104.24.112.88:443
2020-06-25 05:49:530569769f3d543e9f6ad6885505ad8194Virustotal results 10 / 73 (13.70%) 172.67.204.22:443
2020-06-25 05:49:530569769f3d543e9f6ad6885505ad8194Virustotal results 10 / 73 (13.70%) 104.28.15.61:443
2020-06-25 05:42:092d2c712bb2556d574a2cedb30ab2db63Virustotal results 50 / 74 (67.57%) 172.67.204.22:443
2020-06-25 05:42:082d2c712bb2556d574a2cedb30ab2db63Virustotal results 50 / 74 (67.57%) 104.24.113.88:443
2020-06-25 05:42:082d2c712bb2556d574a2cedb30ab2db63Virustotal results 50 / 74 (67.57%) 104.24.112.88:443
2020-06-25 05:36:554234b91a13e1dbc56a9c251f726dbaacVirustotal results 12 / 72 (16.67%) 172.67.204.22:443
2020-06-25 05:36:554234b91a13e1dbc56a9c251f726dbaacVirustotal results 12 / 72 (16.67%) 104.24.113.88:443

# of entries: 100 (max: 100)