JA3 Fingerprints

You can find further information about the JA3 fingerprint 0cc1e84568e471aa1d62ad4158ade6b5, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:0cc1e84568e471aa1d62ad4158ade6b5
First seen:2018-06-24 10:50:47 UTC
Last seen:2020-03-27 13:54:18 UTC
Status:Blacklisted
Malware samples:30
Destination IPs:62
Malware:Tofsee -
Listing date:2018-11-14 12:52:01

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2020-03-27 13:54:188815daa15c9acd80b0c2940ce1d276acVirustotal results 24 / 72 (33.33%) 40.90.23.247:443
2020-03-27 13:54:178815daa15c9acd80b0c2940ce1d276acVirustotal results 24 / 72 (33.33%) 13.107.42.22:443
2020-03-27 13:54:178815daa15c9acd80b0c2940ce1d276acVirustotal results 24 / 72 (33.33%) 13.107.42.11:443
2020-03-26 21:13:42803c7e7340e9f2e3c492662eadc5afa6Virustotal results 22 / 73 (30.14%) 40.90.23.154:443
2020-03-26 21:13:41803c7e7340e9f2e3c492662eadc5afa6Virustotal results 22 / 73 (30.14%) 40.90.137.126:443
2020-03-26 21:13:41803c7e7340e9f2e3c492662eadc5afa6Virustotal results 22 / 73 (30.14%) 13.107.42.11:443
2020-03-26 21:13:40803c7e7340e9f2e3c492662eadc5afa6Virustotal results 22 / 73 (30.14%) 13.107.42.22:443
2020-03-26 13:57:59d86b5aad90c5c2928fdff9718cb8ef24Virustotal results 21 / 71 (29.58%) 40.90.137.127:443
2020-03-26 13:57:59d86b5aad90c5c2928fdff9718cb8ef24Virustotal results 21 / 71 (29.58%) 20.190.128.4:443
2020-03-26 13:57:59d86b5aad90c5c2928fdff9718cb8ef24Virustotal results 21 / 71 (29.58%) 13.107.42.22:443
2020-03-26 13:57:58d86b5aad90c5c2928fdff9718cb8ef24Virustotal results 21 / 71 (29.58%) 20.190.128.6:443
2020-03-26 13:57:57d86b5aad90c5c2928fdff9718cb8ef24Virustotal results 21 / 71 (29.58%) 13.107.42.11:443
2020-03-25 16:19:5139b961c13850e7910d07c9d1993b47a7Virustotal results 20 / 72 (27.78%) 13.107.42.11:443
2020-03-25 16:19:4939b961c13850e7910d07c9d1993b47a7Virustotal results 20 / 72 (27.78%) 13.107.42.22:443
2020-03-25 16:19:4739b961c13850e7910d07c9d1993b47a7Virustotal results 20 / 72 (27.78%) 40.90.137.125:443
2020-03-25 16:19:4239b961c13850e7910d07c9d1993b47a7Virustotal results 20 / 72 (27.78%) 40.90.23.206:443
2020-03-13 15:51:1687ddb4a46f4099cf156c9107e4bd3feaVirustotal results 19 / 72 (26.39%) 13.107.42.11:443
2020-03-13 15:51:1487ddb4a46f4099cf156c9107e4bd3feaVirustotal results 19 / 72 (26.39%) 20.190.128.4:443
2020-03-13 15:51:1387ddb4a46f4099cf156c9107e4bd3feaVirustotal results 19 / 72 (26.39%) 20.190.128.3:443
2020-03-13 15:51:1287ddb4a46f4099cf156c9107e4bd3feaVirustotal results 19 / 72 (26.39%) 40.90.22.188:443
2020-03-13 15:51:1287ddb4a46f4099cf156c9107e4bd3feaVirustotal results 19 / 72 (26.39%) 40.90.22.191:443
2020-03-13 15:51:1087ddb4a46f4099cf156c9107e4bd3feaVirustotal results 19 / 72 (26.39%) 13.107.42.22:443
2018-10-16 08:59:4449e432e58bd163f1ed814f54b7bed9f3Virustotal results 37/67 (55.22%) 40.126.1.166:443
2018-10-16 08:59:4349e432e58bd163f1ed814f54b7bed9f3Virustotal results 37/67 (55.22%) 23.45.96.252:443
2018-10-16 08:59:4349e432e58bd163f1ed814f54b7bed9f3Virustotal results 37/67 (55.22%) 40.124.13.195:443
2018-10-16 08:59:4049e432e58bd163f1ed814f54b7bed9f3Virustotal results 37/67 (55.22%) 13.107.42.11:443
2018-10-16 08:59:3949e432e58bd163f1ed814f54b7bed9f3Virustotal results 37/67 (55.22%) 65.55.163.78:443
2018-10-15 06:28:025f783acdf0e680cb05df27c9101090ean/a13.107.42.11:443
2018-10-15 06:28:015f783acdf0e680cb05df27c9101090ean/a23.45.96.252:443
2018-10-15 06:28:005f783acdf0e680cb05df27c9101090ean/a104.42.232.32:443
2018-10-15 06:27:585f783acdf0e680cb05df27c9101090ean/a104.41.216.16:443
2018-10-15 06:27:565f783acdf0e680cb05df27c9101090ean/a65.55.163.76:443
2018-10-11 18:27:42283752382eaba6313bdf4c3d21f8ea68Virustotal results 16/67 (23.88%) 184.28.113.37:443
2018-10-11 18:27:42283752382eaba6313bdf4c3d21f8ea68Virustotal results 16/67 (23.88%) 40.112.64.18:443
2018-10-11 18:27:42283752382eaba6313bdf4c3d21f8ea68Virustotal results 16/67 (23.88%) 40.101.90.178:443
2018-10-11 18:27:42283752382eaba6313bdf4c3d21f8ea68Virustotal results 16/67 (23.88%) 104.42.232.32:443
2018-10-11 18:27:41283752382eaba6313bdf4c3d21f8ea68Virustotal results 16/67 (23.88%) 65.55.163.80:443
2018-10-09 06:52:457980757350818e013930c3e8339ee835Virustotal results 40/69 (57.97%) 40.71.94.214:443
2018-10-09 06:52:457980757350818e013930c3e8339ee835Virustotal results 40/69 (57.97%) 23.45.96.252:443
2018-10-09 06:52:447980757350818e013930c3e8339ee835Virustotal results 40/69 (57.97%) 65.55.163.78:443
2018-10-09 06:52:437980757350818e013930c3e8339ee835Virustotal results 40/69 (57.97%) 104.42.232.32:443
2018-10-09 06:52:437980757350818e013930c3e8339ee835Virustotal results 40/69 (57.97%) 40.112.64.25:443
2018-10-09 06:52:427980757350818e013930c3e8339ee835Virustotal results 40/69 (57.97%) 13.107.42.11:443
2018-10-08 04:26:430afa975d799b02214776fece33adc91bVirustotal results 13/69 (18.84%) 23.45.96.252:443
2018-10-08 04:26:390afa975d799b02214776fece33adc91bVirustotal results 13/69 (18.84%) 131.253.61.64:443
2018-10-08 04:26:370afa975d799b02214776fece33adc91bVirustotal results 13/69 (18.84%) 13.107.42.11:443
2018-10-08 04:26:350afa975d799b02214776fece33adc91bVirustotal results 13/69 (18.84%) 40.112.64.18:443
2018-10-08 04:26:340afa975d799b02214776fece33adc91bVirustotal results 13/69 (18.84%) 40.124.13.195:443
2018-10-07 04:15:27c5a4ab3875d8acd2fe09d4775be60ba4Virustotal results 43/69 (62.32%) 104.42.232.32:443
2018-10-07 04:15:26c5a4ab3875d8acd2fe09d4775be60ba4Virustotal results 43/69 (62.32%) 23.45.96.252:443
2018-10-07 04:15:26c5a4ab3875d8acd2fe09d4775be60ba4Virustotal results 43/69 (62.32%) 40.71.94.214:443
2018-10-07 04:15:26c5a4ab3875d8acd2fe09d4775be60ba4Virustotal results 43/69 (62.32%) 104.41.216.16:443
2018-10-07 04:15:25c5a4ab3875d8acd2fe09d4775be60ba4Virustotal results 43/69 (62.32%) 13.107.42.11:443
2018-10-07 04:15:25c5a4ab3875d8acd2fe09d4775be60ba4Virustotal results 43/69 (62.32%) 104.41.216.18:443
2018-10-07 04:15:25c5a4ab3875d8acd2fe09d4775be60ba4Virustotal results 43/69 (62.32%) 131.253.61.98:443
2018-10-06 15:12:29fa4da11707ffb21046b362c7210eed90Virustotal results 15/68 (22.06%) 40.124.13.195:443
2018-10-06 15:12:28fa4da11707ffb21046b362c7210eed90Virustotal results 15/68 (22.06%) 23.45.96.252:443
2018-10-06 15:12:27fa4da11707ffb21046b362c7210eed90Virustotal results 15/68 (22.06%) 104.41.216.18:443
2018-10-06 15:12:27fa4da11707ffb21046b362c7210eed90Virustotal results 15/68 (22.06%) 131.253.61.68:443
2018-10-06 15:12:26fa4da11707ffb21046b362c7210eed90Virustotal results 15/68 (22.06%) 13.107.42.11:443
2018-09-26 18:57:08bc29e80b4ca74e30bbf243d3a53b1c53Virustotal results 36/68 (52.94%) 131.253.61.84:443
2018-09-26 18:57:08bc29e80b4ca74e30bbf243d3a53b1c53Virustotal results 36/68 (52.94%) 184.28.113.37:443
2018-09-26 18:57:08bc29e80b4ca74e30bbf243d3a53b1c53Virustotal results 36/68 (52.94%) 40.71.94.214:443
2018-09-26 18:57:07bc29e80b4ca74e30bbf243d3a53b1c53Virustotal results 36/68 (52.94%) 13.107.42.11:443
2018-09-26 18:57:07bc29e80b4ca74e30bbf243d3a53b1c53Virustotal results 36/68 (52.94%) 104.41.216.27:443
2018-09-24 10:52:41a46ee7ea43c9cedbe6a80d3bd35849f3Virustotal results 40/68 (58.82%) 40.112.64.28:443
2018-09-24 10:52:41a46ee7ea43c9cedbe6a80d3bd35849f3Virustotal results 40/68 (58.82%) 131.253.61.68:443
2018-09-24 10:52:40a46ee7ea43c9cedbe6a80d3bd35849f3Virustotal results 40/68 (58.82%) 13.107.42.11:443
2018-09-24 10:19:26fb3e7181d295afc983aeb3b0d6ab8a71Virustotal results 35/67 (52.24%) 13.107.42.11:443
2018-09-24 10:19:26fb3e7181d295afc983aeb3b0d6ab8a71Virustotal results 35/67 (52.24%) 40.112.64.30:443
2018-09-24 10:19:26fb3e7181d295afc983aeb3b0d6ab8a71Virustotal results 35/67 (52.24%) 131.253.61.102:443
2018-09-24 10:19:26fb3e7181d295afc983aeb3b0d6ab8a71Virustotal results 35/67 (52.24%) 23.45.96.252:443
2018-09-24 10:19:26fb3e7181d295afc983aeb3b0d6ab8a71Virustotal results 35/67 (52.24%) 104.42.232.32:443
2018-09-21 15:40:2283ea9ddb698c6ee6c0838fcf731b78d0Virustotal results 36/69 (52.17%) 184.28.113.37:443
2018-09-21 15:40:2283ea9ddb698c6ee6c0838fcf731b78d0Virustotal results 36/69 (52.17%) 104.42.232.32:443
2018-09-21 15:40:2183ea9ddb698c6ee6c0838fcf731b78d0Virustotal results 36/69 (52.17%) 131.253.61.66:443
2018-09-21 15:40:2083ea9ddb698c6ee6c0838fcf731b78d0Virustotal results 36/69 (52.17%) 40.112.64.28:443
2018-09-21 15:40:1983ea9ddb698c6ee6c0838fcf731b78d0Virustotal results 36/69 (52.17%) 13.107.42.11:443
2018-09-21 13:53:5899378fa4905357891283d2280d61c9b3Virustotal results 21/68 (30.88%) 23.37.50.157:443
2018-09-21 13:53:5899378fa4905357891283d2280d61c9b3Virustotal results 21/68 (30.88%) 104.42.232.32:443
2018-09-21 13:53:5699378fa4905357891283d2280d61c9b3Virustotal results 21/68 (30.88%) 40.112.64.28:443
2018-09-21 13:53:5699378fa4905357891283d2280d61c9b3Virustotal results 21/68 (30.88%) 131.253.61.70:443
2018-09-21 13:53:5599378fa4905357891283d2280d61c9b3Virustotal results 21/68 (30.88%) 13.107.42.11:443
2018-07-29 18:56:24d040f181a80d68fa1c4f743f8982a0deVirustotal results 28/68 (41.18%) 13.107.42.11:443
2018-07-29 18:56:24d040f181a80d68fa1c4f743f8982a0deVirustotal results 28/68 (41.18%) 104.210.208.16:443
2018-07-29 18:56:24d040f181a80d68fa1c4f743f8982a0deVirustotal results 28/68 (41.18%) 131.253.61.100:443
2018-07-29 18:56:24d040f181a80d68fa1c4f743f8982a0deVirustotal results 28/68 (41.18%) 23.0.224.102:443
2018-07-29 18:56:24d040f181a80d68fa1c4f743f8982a0deVirustotal results 28/68 (41.18%) 40.124.13.195:443
2018-07-29 18:56:24d040f181a80d68fa1c4f743f8982a0deVirustotal results 28/68 (41.18%) 104.210.208.17:443
2018-07-28 01:26:023c5fbdb5a263876d9482d1c4adc5d204Virustotal results 12/68 (17.65%) 13.107.42.11:443
2018-07-28 01:26:023c5fbdb5a263876d9482d1c4adc5d204Virustotal results 12/68 (17.65%) 23.101.181.128:443
2018-07-28 01:26:023c5fbdb5a263876d9482d1c4adc5d204Virustotal results 12/68 (17.65%) 131.253.61.98:443
2018-07-28 01:26:023c5fbdb5a263876d9482d1c4adc5d204Virustotal results 12/68 (17.65%) 23.43.94.124:443
2018-07-28 01:26:023c5fbdb5a263876d9482d1c4adc5d204Virustotal results 12/68 (17.65%) 40.71.94.214:443
2018-07-28 01:26:023c5fbdb5a263876d9482d1c4adc5d204Virustotal results 12/68 (17.65%) 104.210.208.16:443
2018-07-21 07:04:594a7d4b69f07c151ea3dcbf6f77ff6665Virustotal results 40/68 (58.82%) 13.107.42.11:443
2018-07-21 07:04:594a7d4b69f07c151ea3dcbf6f77ff6665Virustotal results 40/68 (58.82%) 104.210.208.18:443
2018-07-21 07:04:594a7d4b69f07c151ea3dcbf6f77ff6665Virustotal results 40/68 (58.82%) 131.253.61.84:443
2018-07-21 07:04:594a7d4b69f07c151ea3dcbf6f77ff6665Virustotal results 40/68 (58.82%) 23.54.216.142:443
2018-07-21 02:22:2015c3c95d4c6765750646e458a9e30df7Virustotal results 29/68 (42.65%) 13.107.42.11:443

# of entries: 100 (max: 100)