JA3 Fingerprints

You can find further information about the JA3 fingerprint 0cc1e84568e471aa1d62ad4158ade6b5, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:0cc1e84568e471aa1d62ad4158ade6b5
First seen:2018-06-24 10:50:47 UTC
Last seen:2018-10-16 08:59:44 UTC
Status:Blacklisted
Malware samples:25
Destination IPs:50
Malware:Tofsee -
Listing date:2018-11-14 12:52:01

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2018-10-16 08:59:4449e432e58bd163f1ed814f54b7bed9f3Virustotal results 37/67 (55.22%) 40.126.1.166:443
2018-10-16 08:59:4349e432e58bd163f1ed814f54b7bed9f3Virustotal results 37/67 (55.22%) 23.45.96.252:443
2018-10-16 08:59:4349e432e58bd163f1ed814f54b7bed9f3Virustotal results 37/67 (55.22%) 40.124.13.195:443
2018-10-16 08:59:4049e432e58bd163f1ed814f54b7bed9f3Virustotal results 37/67 (55.22%) 13.107.42.11:443
2018-10-16 08:59:3949e432e58bd163f1ed814f54b7bed9f3Virustotal results 37/67 (55.22%) 65.55.163.78:443
2018-10-15 06:28:025f783acdf0e680cb05df27c9101090ean/a13.107.42.11:443
2018-10-15 06:28:015f783acdf0e680cb05df27c9101090ean/a23.45.96.252:443
2018-10-15 06:28:005f783acdf0e680cb05df27c9101090ean/a104.42.232.32:443
2018-10-15 06:27:585f783acdf0e680cb05df27c9101090ean/a104.41.216.16:443
2018-10-15 06:27:565f783acdf0e680cb05df27c9101090ean/a65.55.163.76:443
2018-10-11 18:27:42283752382eaba6313bdf4c3d21f8ea68Virustotal results 16/67 (23.88%) 184.28.113.37:443
2018-10-11 18:27:42283752382eaba6313bdf4c3d21f8ea68Virustotal results 16/67 (23.88%) 40.112.64.18:443
2018-10-11 18:27:42283752382eaba6313bdf4c3d21f8ea68Virustotal results 16/67 (23.88%) 40.101.90.178:443
2018-10-11 18:27:42283752382eaba6313bdf4c3d21f8ea68Virustotal results 16/67 (23.88%) 104.42.232.32:443
2018-10-11 18:27:41283752382eaba6313bdf4c3d21f8ea68Virustotal results 16/67 (23.88%) 65.55.163.80:443
2018-10-09 06:52:457980757350818e013930c3e8339ee835Virustotal results 40/69 (57.97%) 40.71.94.214:443
2018-10-09 06:52:457980757350818e013930c3e8339ee835Virustotal results 40/69 (57.97%) 23.45.96.252:443
2018-10-09 06:52:447980757350818e013930c3e8339ee835Virustotal results 40/69 (57.97%) 65.55.163.78:443
2018-10-09 06:52:437980757350818e013930c3e8339ee835Virustotal results 40/69 (57.97%) 104.42.232.32:443
2018-10-09 06:52:437980757350818e013930c3e8339ee835Virustotal results 40/69 (57.97%) 40.112.64.25:443
2018-10-09 06:52:427980757350818e013930c3e8339ee835Virustotal results 40/69 (57.97%) 13.107.42.11:443
2018-10-08 04:26:430afa975d799b02214776fece33adc91bVirustotal results 13/69 (18.84%) 23.45.96.252:443
2018-10-08 04:26:390afa975d799b02214776fece33adc91bVirustotal results 13/69 (18.84%) 131.253.61.64:443
2018-10-08 04:26:370afa975d799b02214776fece33adc91bVirustotal results 13/69 (18.84%) 13.107.42.11:443
2018-10-08 04:26:350afa975d799b02214776fece33adc91bVirustotal results 13/69 (18.84%) 40.112.64.18:443
2018-10-08 04:26:340afa975d799b02214776fece33adc91bVirustotal results 13/69 (18.84%) 40.124.13.195:443
2018-10-07 04:15:27c5a4ab3875d8acd2fe09d4775be60ba4Virustotal results 43/69 (62.32%) 104.42.232.32:443
2018-10-07 04:15:26c5a4ab3875d8acd2fe09d4775be60ba4Virustotal results 43/69 (62.32%) 23.45.96.252:443
2018-10-07 04:15:26c5a4ab3875d8acd2fe09d4775be60ba4Virustotal results 43/69 (62.32%) 40.71.94.214:443
2018-10-07 04:15:26c5a4ab3875d8acd2fe09d4775be60ba4Virustotal results 43/69 (62.32%) 104.41.216.16:443
2018-10-07 04:15:25c5a4ab3875d8acd2fe09d4775be60ba4Virustotal results 43/69 (62.32%) 13.107.42.11:443
2018-10-07 04:15:25c5a4ab3875d8acd2fe09d4775be60ba4Virustotal results 43/69 (62.32%) 104.41.216.18:443
2018-10-07 04:15:25c5a4ab3875d8acd2fe09d4775be60ba4Virustotal results 43/69 (62.32%) 131.253.61.98:443
2018-10-06 15:12:29fa4da11707ffb21046b362c7210eed90Virustotal results 15/68 (22.06%) 40.124.13.195:443
2018-10-06 15:12:28fa4da11707ffb21046b362c7210eed90Virustotal results 15/68 (22.06%) 23.45.96.252:443
2018-10-06 15:12:27fa4da11707ffb21046b362c7210eed90Virustotal results 15/68 (22.06%) 104.41.216.18:443
2018-10-06 15:12:27fa4da11707ffb21046b362c7210eed90Virustotal results 15/68 (22.06%) 131.253.61.68:443
2018-10-06 15:12:26fa4da11707ffb21046b362c7210eed90Virustotal results 15/68 (22.06%) 13.107.42.11:443
2018-09-26 18:57:08bc29e80b4ca74e30bbf243d3a53b1c53Virustotal results 36/68 (52.94%) 131.253.61.84:443
2018-09-26 18:57:08bc29e80b4ca74e30bbf243d3a53b1c53Virustotal results 36/68 (52.94%) 184.28.113.37:443
2018-09-26 18:57:08bc29e80b4ca74e30bbf243d3a53b1c53Virustotal results 36/68 (52.94%) 40.71.94.214:443
2018-09-26 18:57:07bc29e80b4ca74e30bbf243d3a53b1c53Virustotal results 36/68 (52.94%) 13.107.42.11:443
2018-09-26 18:57:07bc29e80b4ca74e30bbf243d3a53b1c53Virustotal results 36/68 (52.94%) 104.41.216.27:443
2018-09-24 10:52:41a46ee7ea43c9cedbe6a80d3bd35849f3Virustotal results 40/68 (58.82%) 40.112.64.28:443
2018-09-24 10:52:41a46ee7ea43c9cedbe6a80d3bd35849f3Virustotal results 40/68 (58.82%) 131.253.61.68:443
2018-09-24 10:52:40a46ee7ea43c9cedbe6a80d3bd35849f3Virustotal results 40/68 (58.82%) 13.107.42.11:443
2018-09-24 10:19:26fb3e7181d295afc983aeb3b0d6ab8a71Virustotal results 35/67 (52.24%) 13.107.42.11:443
2018-09-24 10:19:26fb3e7181d295afc983aeb3b0d6ab8a71Virustotal results 35/67 (52.24%) 40.112.64.30:443
2018-09-24 10:19:26fb3e7181d295afc983aeb3b0d6ab8a71Virustotal results 35/67 (52.24%) 131.253.61.102:443
2018-09-24 10:19:26fb3e7181d295afc983aeb3b0d6ab8a71Virustotal results 35/67 (52.24%) 23.45.96.252:443
2018-09-24 10:19:26fb3e7181d295afc983aeb3b0d6ab8a71Virustotal results 35/67 (52.24%) 104.42.232.32:443
2018-09-21 15:40:2283ea9ddb698c6ee6c0838fcf731b78d0Virustotal results 36/69 (52.17%) 184.28.113.37:443
2018-09-21 15:40:2283ea9ddb698c6ee6c0838fcf731b78d0Virustotal results 36/69 (52.17%) 104.42.232.32:443
2018-09-21 15:40:2183ea9ddb698c6ee6c0838fcf731b78d0Virustotal results 36/69 (52.17%) 131.253.61.66:443
2018-09-21 15:40:2083ea9ddb698c6ee6c0838fcf731b78d0Virustotal results 36/69 (52.17%) 40.112.64.28:443
2018-09-21 15:40:1983ea9ddb698c6ee6c0838fcf731b78d0Virustotal results 36/69 (52.17%) 13.107.42.11:443
2018-09-21 13:53:5899378fa4905357891283d2280d61c9b3Virustotal results 21/68 (30.88%) 23.37.50.157:443
2018-09-21 13:53:5899378fa4905357891283d2280d61c9b3Virustotal results 21/68 (30.88%) 104.42.232.32:443
2018-09-21 13:53:5699378fa4905357891283d2280d61c9b3Virustotal results 21/68 (30.88%) 40.112.64.28:443
2018-09-21 13:53:5699378fa4905357891283d2280d61c9b3Virustotal results 21/68 (30.88%) 131.253.61.70:443
2018-09-21 13:53:5599378fa4905357891283d2280d61c9b3Virustotal results 21/68 (30.88%) 13.107.42.11:443
2018-07-29 18:56:24d040f181a80d68fa1c4f743f8982a0deVirustotal results 28/68 (41.18%) 13.107.42.11:443
2018-07-29 18:56:24d040f181a80d68fa1c4f743f8982a0deVirustotal results 28/68 (41.18%) 104.210.208.16:443
2018-07-29 18:56:24d040f181a80d68fa1c4f743f8982a0deVirustotal results 28/68 (41.18%) 131.253.61.100:443
2018-07-29 18:56:24d040f181a80d68fa1c4f743f8982a0deVirustotal results 28/68 (41.18%) 23.0.224.102:443
2018-07-29 18:56:24d040f181a80d68fa1c4f743f8982a0deVirustotal results 28/68 (41.18%) 40.124.13.195:443
2018-07-29 18:56:24d040f181a80d68fa1c4f743f8982a0deVirustotal results 28/68 (41.18%) 104.210.208.17:443
2018-07-28 01:26:023c5fbdb5a263876d9482d1c4adc5d204Virustotal results 12/68 (17.65%) 13.107.42.11:443
2018-07-28 01:26:023c5fbdb5a263876d9482d1c4adc5d204Virustotal results 12/68 (17.65%) 23.101.181.128:443
2018-07-28 01:26:023c5fbdb5a263876d9482d1c4adc5d204Virustotal results 12/68 (17.65%) 131.253.61.98:443
2018-07-28 01:26:023c5fbdb5a263876d9482d1c4adc5d204Virustotal results 12/68 (17.65%) 23.43.94.124:443
2018-07-28 01:26:023c5fbdb5a263876d9482d1c4adc5d204Virustotal results 12/68 (17.65%) 40.71.94.214:443
2018-07-28 01:26:023c5fbdb5a263876d9482d1c4adc5d204Virustotal results 12/68 (17.65%) 104.210.208.16:443
2018-07-21 07:04:594a7d4b69f07c151ea3dcbf6f77ff6665Virustotal results 40/68 (58.82%) 13.107.42.11:443
2018-07-21 07:04:594a7d4b69f07c151ea3dcbf6f77ff6665Virustotal results 40/68 (58.82%) 104.210.208.18:443
2018-07-21 07:04:594a7d4b69f07c151ea3dcbf6f77ff6665Virustotal results 40/68 (58.82%) 131.253.61.84:443
2018-07-21 07:04:594a7d4b69f07c151ea3dcbf6f77ff6665Virustotal results 40/68 (58.82%) 23.54.216.142:443
2018-07-21 02:22:2015c3c95d4c6765750646e458a9e30df7Virustotal results 29/68 (42.65%) 13.107.42.11:443
2018-07-21 02:22:2015c3c95d4c6765750646e458a9e30df7Virustotal results 29/68 (42.65%) 104.210.208.18:443
2018-07-21 02:22:2015c3c95d4c6765750646e458a9e30df7Virustotal results 29/68 (42.65%) 131.253.61.70:443
2018-07-21 02:22:2015c3c95d4c6765750646e458a9e30df7Virustotal results 29/68 (42.65%) 104.210.208.17:443
2018-07-21 02:22:2015c3c95d4c6765750646e458a9e30df7Virustotal results 29/68 (42.65%) 23.79.217.132:443
2018-07-21 02:22:2015c3c95d4c6765750646e458a9e30df7Virustotal results 29/68 (42.65%) 65.52.217.237:443
2018-07-12 16:21:453ce0b66ba9d968c39bc4ce4487bf57a8Virustotal results 18/68 (26.47%) 13.107.43.11:443
2018-07-12 16:21:453ce0b66ba9d968c39bc4ce4487bf57a8Virustotal results 18/68 (26.47%) 23.100.120.70:443
2018-07-12 16:21:453ce0b66ba9d968c39bc4ce4487bf57a8Virustotal results 18/68 (26.47%) 131.253.61.96:443
2018-07-12 16:21:453ce0b66ba9d968c39bc4ce4487bf57a8Virustotal results 18/68 (26.47%) 104.66.55.77:443
2018-07-12 16:21:453ce0b66ba9d968c39bc4ce4487bf57a8Virustotal results 18/68 (26.47%) 104.42.232.32:443
2018-07-12 16:21:453ce0b66ba9d968c39bc4ce4487bf57a8Virustotal results 18/68 (26.47%) 40.124.13.195:443
2018-07-12 16:21:453ce0b66ba9d968c39bc4ce4487bf57a8Virustotal results 18/68 (26.47%) 65.52.217.237:443
2018-07-12 16:21:453ce0b66ba9d968c39bc4ce4487bf57a8Virustotal results 18/68 (26.47%) 131.253.61.80:443
2018-07-12 09:36:2916df902cc782430b698e0bed279e491eVirustotal results 37/68 (54.41%) 13.107.42.11:443
2018-07-12 09:36:2916df902cc782430b698e0bed279e491eVirustotal results 37/68 (54.41%) 104.210.208.20:443
2018-07-12 09:36:2916df902cc782430b698e0bed279e491eVirustotal results 37/68 (54.41%) 131.253.61.98:443
2018-07-12 09:36:2916df902cc782430b698e0bed279e491eVirustotal results 37/68 (54.41%) 172.226.245.215:443
2018-07-12 09:36:2916df902cc782430b698e0bed279e491eVirustotal results 37/68 (54.41%) 65.52.217.237:443
2018-07-11 09:35:061f58e92e4a3086ea4e7a108a5399c6c4Virustotal results 47/64 (73.44%) 13.107.42.11:443
2018-07-11 09:35:061f58e92e4a3086ea4e7a108a5399c6c4Virustotal results 47/64 (73.44%) 23.100.120.65:443
2018-07-11 09:35:061f58e92e4a3086ea4e7a108a5399c6c4Virustotal results 47/64 (73.44%) 131.253.61.70:443
2018-07-11 09:35:061f58e92e4a3086ea4e7a108a5399c6c4Virustotal results 47/64 (73.44%) 23.79.217.132:443

# of entries: 100 (max: 100)