JA3 Fingerprints

You can find further information about the JA3 fingerprint 0cc1e84568e471aa1d62ad4158ade6b5, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:0cc1e84568e471aa1d62ad4158ade6b5
First seen:2018-06-24 10:50:47 UTC
Last seen:2021-06-21 02:35:57 UTC
Status:Blacklisted
Malware samples:323
Destination IPs:220
Malware:Tofsee -
Listing date:2018-11-14 12:52:01

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2025-03-23 02:16:384bfd5c65e01f71f644d140afeef24855n/a193.246.105.91:443
2025-03-23 02:16:384bfd5c65e01f71f644d140afeef24855n/a3.210.24.210:443
2025-03-12 02:26:213a6b7247458d4c876299049369595433n/a163.181.131.244:443
2025-03-12 02:26:213a6b7247458d4c876299049369595433n/a47.246.50.176:443
2025-03-09 18:42:57b2e65fee0b881e9f26e7a2e7c24f3802n/a193.246.105.58:443
2025-03-09 18:37:49bcfb64c1f601358c9a2079cc62130e88n/a193.246.105.58:443
2025-03-09 18:37:49bcfb64c1f601358c9a2079cc62130e88n/a193.246.105.97:443
2025-03-09 00:32:451b85004b58f121dd7aace9315794cae5n/a172.217.168.14:443
2025-03-09 00:32:451b85004b58f121dd7aace9315794cae5n/a172.67.73.191:443
2025-03-09 00:32:441b85004b58f121dd7aace9315794cae5n/a104.26.7.120:443
2025-03-07 21:47:565242c4d88264791195bb700c08a2a3c1n/a52.202.180.121:443
2025-03-07 21:47:565242c4d88264791195bb700c08a2a3c1n/a193.247.41.9:443
2025-03-07 00:18:221431d73394044be65b0ed88de7554386n/a193.247.41.9:443
2025-03-04 09:07:39f0ece516a2308c9d4830c20d6bd82ce1n/a193.246.105.91:443
2025-02-20 18:29:2231d75b99e3564667b1773902b5b66368n/a193.246.105.91:443
2025-02-20 18:29:2131d75b99e3564667b1773902b5b66368n/a44.216.89.176:443
2025-02-17 08:39:53ef4f7ee1ace8b37791f24fe4c4e12f3bn/a193.247.41.9:443
2025-02-13 01:51:46bca7e49ad1032e26d338b70a9cc911e8n/a193.247.41.48:443
2025-02-10 20:00:1039b76c2c3642869902179c027d9350a8n/a173.223.162.43:443
2025-02-10 20:00:1039b76c2c3642869902179c027d9350a8n/a52.44.230.176:443
2025-02-10 12:08:3568dfd7e3a40d9f0c0fd679b76557d1can/a193.247.41.48:443
2025-01-22 01:11:33351d31ef2005743f7b00a386eb353866n/a3.232.135.78:443
2025-01-12 21:59:466912b3a2cd4c941a293c20d730b5fc79n/a35.174.38.64:443
2025-01-12 21:59:466912b3a2cd4c941a293c20d730b5fc79n/a193.246.105.58:443
2025-01-12 05:54:376bdb3bc97f08b5f62956922327fea070n/a15.197.228.107:443
2025-01-12 05:54:376bdb3bc97f08b5f62956922327fea070n/a199.232.210.172:443
2024-09-29 08:07:19f8f85b5eb2dcdb16626a7dd8a7e23d81n/a104.26.7.120:443
2024-09-29 08:07:19f8f85b5eb2dcdb16626a7dd8a7e23d81n/a216.239.32.178:443
2024-09-29 08:07:19f8f85b5eb2dcdb16626a7dd8a7e23d81n/a104.26.6.120:443
2024-09-28 13:41:486938b98af3483f80c5e20e879139bec8n/a152.199.20.140:443
2024-09-13 16:21:3124f305407bf45db365a4fd495cfa6c4bn/a68.232.34.200:443
2024-09-13 16:21:3124f305407bf45db365a4fd495cfa6c4bn/a159.203.69.7:443
2024-09-13 16:21:3124f305407bf45db365a4fd495cfa6c4bn/a15.197.228.107:443
2024-08-10 09:10:2432f0313a61252f92fb14b5daa02bdaben/a68.232.34.200:443
2024-08-10 09:10:2432f0313a61252f92fb14b5daa02bdaben/a15.197.228.107:443
2024-08-07 16:50:182dab911a73074da684aa5bdc13d4631en/a15.197.228.107:443
2024-08-07 16:50:182dab911a73074da684aa5bdc13d4631en/a68.232.34.200:443
2024-05-22 09:11:29a34cd9ba457beb5aeb485ee161d28797n/a152.199.23.214:443
2024-05-19 05:21:214ff84a6c04d0f29b232df6f85d513b07n/a116.203.13.71:443
2024-05-16 20:59:49069cf9acaca6e64f32ecce2485ded153n/a3.33.231.75:443
2024-05-12 19:29:29a23f9cff0847967b2fd09df5973fc6e5n/a152.199.23.214:443
2024-04-14 10:30:37fee22d83afd92b6fff8544cc976c347an/a193.246.8.224:443
2024-04-14 10:30:37fee22d83afd92b6fff8544cc976c347an/a15.197.228.107:443
2024-04-14 10:30:37fee22d83afd92b6fff8544cc976c347an/a68.232.34.200:443
2024-04-14 00:32:57e6534cfaa4d4b0bd34398060855c0ac7n/a104.166.182.99:443
2024-04-14 00:32:57e6534cfaa4d4b0bd34398060855c0ac7n/a163.181.49.250:443
2024-04-13 16:28:38d1f8c0c7eaf024f84b11d7f19c9920c9n/a13.107.42.22:443
2024-04-03 12:17:32055ec270285537f6f89d9b5c94333404Virustotal results 2 / 70 (2.86%) 152.199.23.214:443
2024-04-01 16:21:5407d0100bdf118829e41188a22ebded65Virustotal results 14 / 70 (20.00%) 3.33.231.75:443
2024-04-01 16:21:5407d0100bdf118829e41188a22ebded65Virustotal results 14 / 70 (20.00%) 184.30.158.37:443
2024-04-01 16:21:5407d0100bdf118829e41188a22ebded65Virustotal results 14 / 70 (20.00%) 68.232.34.200:443
2024-04-01 12:15:111f5a70ee02b8187e1778b75eb5065ff2Virustotal results 15 / 70 (21.43%) 68.232.34.200:443
2024-04-01 12:15:111f5a70ee02b8187e1778b75eb5065ff2Virustotal results 15 / 70 (21.43%) 15.197.228.107:443
2024-04-01 12:15:111f5a70ee02b8187e1778b75eb5065ff2Virustotal results 15 / 70 (21.43%) 193.246.8.224:443
2024-03-21 12:51:1621193bb6223e3f0b4159d075435f8364n/a15.197.228.107:443
2024-03-21 12:51:1621193bb6223e3f0b4159d075435f8364n/a104.99.233.107:443
2024-03-21 12:51:1521193bb6223e3f0b4159d075435f8364n/a68.232.34.200:443
2024-03-10 07:46:580e330056919e29e52db1725df201144eVirustotal results 14 / 69 (20.29%) 104.99.233.107:443
2024-03-10 07:46:570e330056919e29e52db1725df201144eVirustotal results 14 / 69 (20.29%) 3.33.231.75:443
2024-03-10 07:46:570e330056919e29e52db1725df201144eVirustotal results 14 / 69 (20.29%) 68.232.34.200:443
2024-02-29 04:54:1832d50550012464e12e6dd28b5c8fe81eVirustotal results 1 / 70 (1.43%) 152.199.23.214:443
2024-02-25 20:22:38083fb90ab388b557702eca8b9e023241Virustotal results 12 / 66 (18.18%) 104.99.233.107:443
2024-02-25 20:22:37083fb90ab388b557702eca8b9e023241Virustotal results 12 / 66 (18.18%) 15.197.228.107:443
2024-02-24 08:31:2121ce67a1b9496664a685c1915c9dcc45n/a104.99.233.107:443
2024-02-24 08:31:2121ce67a1b9496664a685c1915c9dcc45n/a15.197.228.107:443
2024-02-23 21:32:46135b56ce49be027a6ef7dfb242b69a91Virustotal results 14 / 69 (20.29%) 193.246.8.224:443
2024-02-23 21:32:46135b56ce49be027a6ef7dfb242b69a91Virustotal results 14 / 69 (20.29%) 3.33.231.75:443
2024-02-22 05:48:18047c2f1c3e1d407f75742055ac3e7574Virustotal results 17 / 71 (23.94%) 3.33.231.75:443
2024-02-22 05:48:18047c2f1c3e1d407f75742055ac3e7574Virustotal results 17 / 71 (23.94%) 3.33.231.75:443
2024-02-22 05:48:18047c2f1c3e1d407f75742055ac3e7574Virustotal results 17 / 71 (23.94%) 3.33.231.75:443
2024-02-22 05:48:17047c2f1c3e1d407f75742055ac3e7574Virustotal results 17 / 71 (23.94%) 193.246.8.224:443
2024-02-22 05:48:17047c2f1c3e1d407f75742055ac3e7574Virustotal results 17 / 71 (23.94%) 193.246.8.224:443
2024-02-22 05:48:17047c2f1c3e1d407f75742055ac3e7574Virustotal results 17 / 71 (23.94%) 193.246.8.224:443
2024-02-21 10:53:29a9a10b607d56608f9ef7d1d17cafa955n/a104.99.233.107:443
2024-02-21 10:53:29a9a10b607d56608f9ef7d1d17cafa955n/a3.33.231.75:443
2024-02-19 06:11:5616d8f5db29fa8ff6f8e8766aa4661879n/a15.197.228.107:443
2024-02-19 06:11:5516d8f5db29fa8ff6f8e8766aa4661879n/a23.212.89.111:443
2024-02-19 03:56:2904df9ddf56c84311948e2baea7177d70n/a184.86.80.163:443
2024-02-19 03:56:2904df9ddf56c84311948e2baea7177d70n/a15.197.228.107:443
2024-02-19 03:56:2904df9ddf56c84311948e2baea7177d70n/a15.197.228.107:443
2024-02-19 03:56:2904df9ddf56c84311948e2baea7177d70n/a184.86.80.163:443
2024-02-18 22:22:5731db2fdfee094d551ca8a6777df028dbn/a104.99.233.107:443
2024-02-18 22:22:5631db2fdfee094d551ca8a6777df028dbn/a3.33.231.75:443
2024-02-09 00:10:51016d6734db47f4de144cb565a9682576n/a15.197.228.107:443
2024-02-09 00:10:50016d6734db47f4de144cb565a9682576n/a104.99.233.107:443
2024-02-08 21:54:18a7e39d219fa4abf0af5d83933ab5a42en/a193.246.8.224:443
2024-02-08 21:54:18a7e39d219fa4abf0af5d83933ab5a42en/a3.33.231.75:443
2024-01-31 04:32:15096b9187dbff1be5dc8c018beea07f02Virustotal results 16 / 69 (23.19%) 23.35.228.223:443
2024-01-31 04:32:14096b9187dbff1be5dc8c018beea07f02Virustotal results 16 / 69 (23.19%) 15.197.228.107:443
2024-01-31 02:41:54044041b9b93370affca14c5f35ff3f67n/a15.197.228.107:443
2024-01-31 02:41:53044041b9b93370affca14c5f35ff3f67n/a2.17.220.195:443
2024-01-23 11:08:14a15a6d945affb1cb4bcd1a031e592c36n/a76.223.44.67:443
2024-01-23 05:10:060ea57cf3d7a29a80fd42a8f557d91766Virustotal results 13 / 67 (19.40%) 15.197.228.107:443
2024-01-23 05:10:050ea57cf3d7a29a80fd42a8f557d91766Virustotal results 13 / 67 (19.40%) 193.246.8.224:443
2024-01-17 12:53:592bbd60274dca8509bbcaf724c585ab92n/a23.212.89.111:443
2024-01-17 12:53:592bbd60274dca8509bbcaf724c585ab92n/a15.197.228.107:443
2024-01-16 07:25:351c285addecadc2d602f23c7d07cfe40en/a193.246.8.224:443
2024-01-16 07:25:351c285addecadc2d602f23c7d07cfe40en/a3.33.231.75:443
2024-01-14 09:20:13d4bb820e83fdbf7e8a58147abd5953f2n/a3.33.231.75:443
2024-01-14 09:20:13d4bb820e83fdbf7e8a58147abd5953f2n/a193.246.8.224:443

# of entries: 100 (max: 100)