JA3 Fingerprints

You can find further information about the JA3 fingerprint ffefafdb86336d057eda5fdf02b3d5ce, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:ffefafdb86336d057eda5fdf02b3d5ce
First seen:2019-10-26 07:31:49 UTC
Last seen:2020-07-25 00:14:09 UTC
Status:Blacklisted
Malware samples:216
Destination IPs:1
Malware:Tofsee -
Listing date:2020-01-09 14:30:05

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2020-07-25 00:14:09ab42b14a93386100a6d3c22c58bf65f6Virustotal results 39 / 71 (54.93%) 87.250.250.22:443
2020-07-25 00:14:09ab42b14a93386100a6d3c22c58bf65f6Virustotal results 39 / 71 (54.93%) 87.250.250.22:443
2020-06-29 02:39:09ab37b193771e8c4535b64ebbe0f7993cVirustotal results 47 / 72 (65.28%) 87.250.250.22:443
2020-06-29 02:39:09ab37b193771e8c4535b64ebbe0f7993cVirustotal results 47 / 72 (65.28%) 87.250.250.22:443
2020-06-28 23:57:46a83933ec31b7222ae33a469c45b4da9dVirustotal results 44 / 72 (61.11%) 87.250.250.22:443
2020-06-28 23:57:46a83933ec31b7222ae33a469c45b4da9dVirustotal results 44 / 72 (61.11%) 87.250.250.22:443
2020-06-28 21:41:49a2fa9719e7360b92020071de01a4ead6n/a87.250.250.22:443
2020-06-28 21:41:49a2fa9719e7360b92020071de01a4ead6n/a87.250.250.22:443
2020-06-28 19:43:04904f2390d3a4d10eeb19447b2e9e485cVirustotal results 37 / 72 (51.39%) 87.250.250.22:443
2020-06-28 19:43:04904f2390d3a4d10eeb19447b2e9e485cVirustotal results 37 / 72 (51.39%) 87.250.250.22:443
2020-06-28 14:48:192f9d49672caecf4678107dd141929d32Virustotal results 48 / 71 (67.61%) 87.250.250.22:443
2020-06-28 14:48:192f9d49672caecf4678107dd141929d32Virustotal results 48 / 71 (67.61%) 87.250.250.22:443
2020-06-28 14:25:492e4f9a841ba39bfe8f179d5a51f1763eVirustotal results 45 / 71 (63.38%) 87.250.250.22:443
2020-06-28 14:25:492e4f9a841ba39bfe8f179d5a51f1763eVirustotal results 45 / 71 (63.38%) 87.250.250.22:443
2020-06-28 12:02:2425c6518c27bddeb20d75722a5cd7478eVirustotal results 40 / 73 (54.79%) 87.250.250.22:443
2020-06-28 12:02:2425c6518c27bddeb20d75722a5cd7478eVirustotal results 40 / 73 (54.79%) 87.250.250.22:443
2020-06-28 09:20:551d52c78c55e79394792d67acb028d86aVirustotal results 49 / 72 (68.06%) 87.250.250.22:443
2020-06-28 09:20:551d52c78c55e79394792d67acb028d86aVirustotal results 49 / 72 (68.06%) 87.250.250.22:443
2020-06-28 02:36:39088c33298b69677f9be20e8c97342336Virustotal results 49 / 72 (68.06%) 87.250.250.22:443
2020-06-28 02:36:39088c33298b69677f9be20e8c97342336Virustotal results 49 / 72 (68.06%) 87.250.250.22:443
2020-06-28 01:11:30044be4366976a7f0f82572f998fea8b1Virustotal results 49 / 74 (66.22%) 87.250.250.22:443
2020-06-28 01:11:30044be4366976a7f0f82572f998fea8b1Virustotal results 49 / 74 (66.22%) 87.250.250.22:443
2020-06-27 23:41:47040a89540e3eb35355fff47775577056Virustotal results 44 / 73 (60.27%) 87.250.250.22:443
2020-06-27 23:41:47040a89540e3eb35355fff47775577056Virustotal results 44 / 73 (60.27%) 87.250.250.22:443
2020-06-27 22:57:5101662a8183933774c4683405d9e59926Virustotal results 44 / 72 (61.11%) 87.250.250.22:443
2020-06-27 22:57:5101662a8183933774c4683405d9e59926Virustotal results 44 / 72 (61.11%) 87.250.250.22:443
2020-06-27 21:56:44abd4b505ef79f27e304b7c5620b5d30fVirustotal results 44 / 73 (60.27%) 87.250.250.22:443
2020-06-27 21:56:44abd4b505ef79f27e304b7c5620b5d30fVirustotal results 44 / 73 (60.27%) 87.250.250.22:443
2020-06-27 21:46:04ac46ae93a3ee6a471c96a7110ead1116Virustotal results 42 / 73 (57.53%) 87.250.250.22:443
2020-06-27 21:46:04ac46ae93a3ee6a471c96a7110ead1116Virustotal results 42 / 73 (57.53%) 87.250.250.22:443
2020-06-26 23:07:28110eb97222da8732c72c87659dd6d30dVirustotal results 53 / 73 (72.60%) 87.250.250.22:443
2020-06-26 23:07:28110eb97222da8732c72c87659dd6d30dVirustotal results 53 / 73 (72.60%) 87.250.250.22:443
2020-06-26 16:00:28a2495891cd198c95d448127926f95924Virustotal results 45 / 73 (61.64%) 87.250.250.22:443
2020-06-26 16:00:28a2495891cd198c95d448127926f95924Virustotal results 45 / 73 (61.64%) 87.250.250.22:443
2020-06-26 14:44:029f72b4f85ec7f2ae6f4b30ed08830e6aVirustotal results 38 / 74 (51.35%) 87.250.250.22:443
2020-06-26 14:44:029f72b4f85ec7f2ae6f4b30ed08830e6aVirustotal results 38 / 74 (51.35%) 87.250.250.22:443
2020-06-26 14:16:549d119e6aa5c3f7adb2abdd231bd6992bVirustotal results 49 / 74 (66.22%) 87.250.250.22:443
2020-06-26 14:16:549d119e6aa5c3f7adb2abdd231bd6992bVirustotal results 49 / 74 (66.22%) 87.250.250.22:443
2020-06-26 14:10:099ccb0f26bef0707bdf02e72d6d31ac5cVirustotal results 44 / 74 (59.46%) 87.250.250.22:443
2020-06-26 14:10:099ccb0f26bef0707bdf02e72d6d31ac5cVirustotal results 44 / 74 (59.46%) 87.250.250.22:443
2020-06-26 13:43:429aa7da2842bda3f1a17cf1a2a97d0e9cVirustotal results 47 / 72 (65.28%) 87.250.250.22:443
2020-06-26 13:43:429aa7da2842bda3f1a17cf1a2a97d0e9cVirustotal results 47 / 72 (65.28%) 87.250.250.22:443
2020-06-26 11:50:269141f6e8ca1b9b774eab72134d950ae5Virustotal results 31 / 72 (43.06%) 87.250.250.22:443
2020-06-26 11:50:269141f6e8ca1b9b774eab72134d950ae5Virustotal results 31 / 72 (43.06%) 87.250.250.22:443
2020-06-26 11:42:4590cc729ffbfa93996e708437954e427fVirustotal results 40 / 73 (54.79%) 87.250.250.22:443
2020-06-26 11:42:4590cc729ffbfa93996e708437954e427fVirustotal results 40 / 73 (54.79%) 87.250.250.22:443
2020-06-26 11:30:308fcd0c491909c23995838a12c2093672Virustotal results 45 / 73 (61.64%) 87.250.250.22:443
2020-06-26 11:30:308fcd0c491909c23995838a12c2093672Virustotal results 45 / 73 (61.64%) 87.250.250.22:443
2020-06-26 10:58:098d2bf866e1cb2920d507f7fdf907919dVirustotal results 52 / 73 (71.23%) 87.250.250.22:443
2020-06-26 10:58:098d2bf866e1cb2920d507f7fdf907919dVirustotal results 52 / 73 (71.23%) 87.250.250.22:443
2020-06-26 10:08:1188f767ca0ee519a416a43025ea4ae00eVirustotal results 47 / 74 (63.51%) 87.250.250.22:443
2020-06-26 10:08:1188f767ca0ee519a416a43025ea4ae00eVirustotal results 47 / 74 (63.51%) 87.250.250.22:443
2020-06-26 09:43:48878cd909faa553c52d10eec5eea0ed7dVirustotal results 44 / 73 (60.27%) 87.250.250.22:443
2020-06-26 09:43:48878cd909faa553c52d10eec5eea0ed7dVirustotal results 44 / 73 (60.27%) 87.250.250.22:443
2020-06-26 09:33:5686e4f8f1bb1992f0d9533f57af8a6196Virustotal results 45 / 74 (60.81%) 87.250.250.22:443
2020-06-26 09:33:5686e4f8f1bb1992f0d9533f57af8a6196Virustotal results 45 / 74 (60.81%) 87.250.250.22:443
2020-06-26 07:42:523db29510963233ca740957bca7204a47Virustotal results 49 / 74 (66.22%) 87.250.250.22:443
2020-06-26 07:42:523db29510963233ca740957bca7204a47Virustotal results 49 / 74 (66.22%) 87.250.250.22:443
2020-06-26 07:37:1126c79e6a10217fd183be6a9c81c893f0Virustotal results 44 / 68 (64.71%) 87.250.250.22:443
2020-06-26 07:37:1126c79e6a10217fd183be6a9c81c893f0Virustotal results 44 / 68 (64.71%) 87.250.250.22:443
2020-06-26 07:18:373b9af528bf2193ef27d2a8f627b7a7efVirustotal results 46 / 73 (63.01%) 87.250.250.22:443
2020-06-26 07:18:373b9af528bf2193ef27d2a8f627b7a7efVirustotal results 46 / 73 (63.01%) 87.250.250.22:443
2020-06-26 07:17:552067cd66f1ea6df62868d4c2dbd35b3dVirustotal results 41 / 73 (56.16%) 87.250.250.22:443
2020-06-26 07:17:552067cd66f1ea6df62868d4c2dbd35b3dVirustotal results 41 / 73 (56.16%) 87.250.250.22:443
2020-06-26 07:10:09288cdba34601be0edc5c06d271ace832Virustotal results 49 / 74 (66.22%) 87.250.250.22:443
2020-06-26 07:10:09288cdba34601be0edc5c06d271ace832Virustotal results 49 / 74 (66.22%) 87.250.250.22:443
2020-06-25 22:09:57173ea84d6f2b6fac96efa9b69a31056dVirustotal results 44 / 73 (60.27%) 87.250.250.22:443
2020-06-25 22:09:57173ea84d6f2b6fac96efa9b69a31056dVirustotal results 44 / 73 (60.27%) 87.250.250.22:443
2020-06-25 19:47:00070b5f96822729d572a1a690ba4cdc23Virustotal results 48 / 74 (64.86%) 87.250.250.22:443
2020-06-25 19:47:00070b5f96822729d572a1a690ba4cdc23Virustotal results 48 / 74 (64.86%) 87.250.250.22:443
2020-06-25 13:14:477e91f6c58840d22df9278cb00a96c60cVirustotal results 41 / 67 (61.19%) 87.250.250.22:443
2020-06-25 13:14:477e91f6c58840d22df9278cb00a96c60cVirustotal results 41 / 67 (61.19%) 87.250.250.22:443
2020-06-25 11:00:047128d615c570558e48a016438512612dVirustotal results 46 / 74 (62.16%) 87.250.250.22:443
2020-06-25 11:00:047128d615c570558e48a016438512612dVirustotal results 46 / 74 (62.16%) 87.250.250.22:443
2020-06-25 10:59:3371c9a9dbcf6531635511bbd909bbdad2Virustotal results 47 / 74 (63.51%) 87.250.250.22:443
2020-06-25 10:59:3371c9a9dbcf6531635511bbd909bbdad2Virustotal results 47 / 74 (63.51%) 87.250.250.22:443
2020-06-25 10:51:577186cd4a6e8e08ede9e07b672d9f2bbcVirustotal results 49 / 73 (67.12%) 87.250.250.22:443
2020-06-25 10:51:577186cd4a6e8e08ede9e07b672d9f2bbcVirustotal results 49 / 73 (67.12%) 87.250.250.22:443
2020-06-25 10:24:026f0ed58bb85df2c82f959b8727094aebVirustotal results 50 / 73 (68.49%) 87.250.250.22:443
2020-06-25 10:24:026f0ed58bb85df2c82f959b8727094aebVirustotal results 50 / 73 (68.49%) 87.250.250.22:443
2020-06-25 08:41:5665f1bd3547814ee716d08fcc829dbd1cVirustotal results 45 / 74 (60.81%) 87.250.250.22:443
2020-06-25 08:41:5665f1bd3547814ee716d08fcc829dbd1cVirustotal results 45 / 74 (60.81%) 87.250.250.22:443
2020-06-25 08:37:0265372bc6ebd15ba611463d03831e2c9eVirustotal results 49 / 74 (66.22%) 87.250.250.22:443
2020-06-25 08:37:0265372bc6ebd15ba611463d03831e2c9eVirustotal results 49 / 74 (66.22%) 87.250.250.22:443
2020-06-25 08:28:046433de7ce840d126f5e1e6fc4a11d932Virustotal results 51 / 73 (69.86%) 87.250.250.22:443
2020-06-25 08:28:046433de7ce840d126f5e1e6fc4a11d932Virustotal results 51 / 73 (69.86%) 87.250.250.22:443
2020-06-25 08:14:206387aa03f2d7e44d0d2c76d49ac3213aVirustotal results 46 / 74 (62.16%) 87.250.250.22:443
2020-06-25 08:14:206387aa03f2d7e44d0d2c76d49ac3213aVirustotal results 46 / 74 (62.16%) 87.250.250.22:443
2020-06-25 08:00:46625964abb316f2d1bd5c9a3c88baf443Virustotal results 48 / 73 (65.75%) 87.250.250.22:443
2020-06-25 08:00:46625964abb316f2d1bd5c9a3c88baf443Virustotal results 48 / 73 (65.75%) 87.250.250.22:443
2020-06-25 07:49:336165c03ba4a7d9a6abb6ddd5b8eb69bdVirustotal results 45 / 73 (61.64%) 87.250.250.22:443
2020-06-25 07:49:336165c03ba4a7d9a6abb6ddd5b8eb69bdVirustotal results 45 / 73 (61.64%) 87.250.250.22:443
2020-06-25 07:43:3060b13febc9aafab4dafe749daca50aedVirustotal results 49 / 73 (67.12%) 87.250.250.22:443
2020-06-25 07:43:3060b13febc9aafab4dafe749daca50aedVirustotal results 49 / 73 (67.12%) 87.250.250.22:443
2020-06-25 07:38:38602fea1e45422f55dbb5a61066bb3410Virustotal results 45 / 74 (60.81%) 87.250.250.22:443
2020-06-25 07:38:38602fea1e45422f55dbb5a61066bb3410Virustotal results 45 / 74 (60.81%) 87.250.250.22:443
2020-06-25 07:11:195dc9c7fa960255f99977e6ef484d017cVirustotal results 47 / 74 (63.51%) 87.250.250.22:443
2020-06-25 07:11:195dc9c7fa960255f99977e6ef484d017cVirustotal results 47 / 74 (63.51%) 87.250.250.22:443
2020-06-25 05:48:095487d6ed4a373309397eecb2b205731dVirustotal results 46 / 74 (62.16%) 87.250.250.22:443
2020-06-25 05:48:095487d6ed4a373309397eecb2b205731dVirustotal results 46 / 74 (62.16%) 87.250.250.22:443

# of entries: 100 (max: 100)