JA3 Fingerprints

You can find further information about the JA3 fingerprint 35c0a31c481927f022a3b530255ac080, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:35c0a31c481927f022a3b530255ac080
First seen:2017-07-15 19:43:19 UTC
Last seen:2021-04-10 12:54:04 UTC
Status:Blacklisted
Malware samples:1'274
Destination IPs:195
Malware:Tofsee -
Listing date:2018-11-14 12:41:34

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2024-01-29 15:44:40e93c433311d58577391f4ac85f36d752n/a10.0.14.235:49774
2024-01-29 15:44:39e93c433311d58577391f4ac85f36d752n/a31.13.84.52:443
2024-01-28 13:27:41a2aa23054c16ec5a732c3985809f583en/a157.240.253.63:443
2024-01-28 13:27:40a2aa23054c16ec5a732c3985809f583en/a10.0.14.236:50183
2024-01-28 13:27:32a2aa23054c16ec5a732c3985809f583en/a10.0.14.236:49859
2024-01-28 13:27:30a2aa23054c16ec5a732c3985809f583en/a10.0.14.236:49936
2024-01-28 13:27:30a2aa23054c16ec5a732c3985809f583en/a10.0.14.236:50264
2024-01-28 13:27:25a2aa23054c16ec5a732c3985809f583en/a10.0.14.236:49895
2024-01-08 06:16:41e77a1aef1a3f6107cd8ac432d3d50325n/a157.240.201.63:443
2024-01-08 05:05:33dd3a8f81c8fbd3c4ffd249b05c6f6fe5n/a157.240.17.63:443
2023-12-29 22:50:03a69f01de8fdeefb56b46e33390bf54b6Virustotal results 54 / 72 (75.00%) 157.240.251.63:443
2023-10-25 13:40:24c44607d75b82fd71dba507c41eec8493n/a217.69.139.61:443
2023-09-16 01:01:362fad45b92b035259d4b40f8dd83be28fn/a13.107.42.14:443
2023-09-16 01:01:332fad45b92b035259d4b40f8dd83be28fn/a10.0.7.85:50099
2023-09-16 01:01:332fad45b92b035259d4b40f8dd83be28fn/a10.0.7.85:50074
2023-04-13 03:42:08ab16ed8bf0e2b918f944bed8805bf35an/a13.107.42.14:443
2023-02-21 10:41:1339ee2114d05e7771740bada0b8871493n/a157.240.17.35:443
2022-11-09 04:23:18c364c9854d3262b7975e991bc066849cn/a157.240.17.63:443
2022-11-05 00:59:43869450e88727effc1038eaa80ee77fc0n/a157.240.201.63:443
2022-11-04 16:18:027091783e21821683751fdb2e06be76b1n/a157.240.17.63:443
2022-11-04 15:09:156dbe0a3bd17a1f983218dbcab8c26ab0n/a157.240.17.63:443
2022-11-04 14:11:186b7131cf14ebce7c6c0a9820d3584b6en/a157.240.17.63:443
2022-11-02 19:51:443950d84bcd3c4ed6b96a41d46737fd4en/a157.240.17.63:443
2022-11-02 16:52:59258b842ea2ebb01ee51444c2a14e8fcbn/a157.240.17.63:443
2022-11-02 16:41:0322f5aa618a7107e2d7d6741c821171edn/a185.60.216.52:443
2022-11-02 16:41:0322f5aa618a7107e2d7d6741c821171edn/a157.240.20.63:443
2022-11-02 07:38:221278fd376102db3e9f44c39c05299ac6n/a157.240.17.63:443
2022-11-02 01:18:31e63f4fe868021a05e5e4ded410b26718n/a157.240.20.63:443
2022-11-01 23:40:426c11d2a5b2ffb8ce57374526d3d5877an/a157.240.201.63:443
2022-11-01 23:32:166ae221dfbbddf38c7f0f50ce41f0bdc8n/a157.240.247.63:443
2022-11-01 02:28:0265d06cdf91153777d2c88fad225270d6n/a157.240.22.63:443
2022-10-31 20:12:10472d9ee61e16176bf8bae4126a44133en/a157.240.17.63:443
2022-10-31 18:41:1147ed0cda600d713807c0637eb6baf987n/a157.240.17.63:443
2022-10-31 18:30:43412f38d3059de15a10d9d2aa18758b22n/a157.240.17.63:443
2022-10-31 18:03:1742e18db52becf8a5b31e0c67efb46135n/a185.60.216.52:443
2022-10-31 16:08:34341ec7e0f99bb1541016b8f4fa5c0e3fn/a157.240.11.52:443
2022-10-31 13:31:043057477419aa647f98876ed7d625483dn/a157.240.22.63:443
2022-10-31 13:31:033057477419aa647f98876ed7d625483dn/a157.240.11.52:443
2022-10-30 13:49:1655006170e8a35db5fcab546144942aa1n/a157.240.11.52:443
2022-10-29 15:33:58e8638ad88395db2c211ce98599056e5dVirustotal results 28 / 72 (38.89%) 157.240.247.63:443
2022-10-29 15:32:50d258643332bccc2a1b0a85bb7b92adefn/a157.240.20.63:443
2022-10-28 05:52:49b893dcf14e9e9ac6c5cfefb50c388840n/a157.240.17.63:443
2022-10-28 05:48:41a8c53473c3ff974d9470dbb0dc38fcbbn/a157.240.17.63:443
2022-10-28 05:39:06621b519c3d70b7e14fa6723d72c544fen/a31.13.70.52:443
2022-10-28 05:32:32643dffd2cf34e325c81bd77922064247Virustotal results 35 / 71 (49.30%) 157.240.22.63:443
2022-10-28 05:20:2727ed630e4fb8fce3eb26855519071800Virustotal results 36 / 72 (50.00%) 157.240.17.63:443
2022-10-27 21:43:56194e8ec3676467ca82cf937fc662d628n/a157.240.247.63:443
2022-10-27 21:43:56194e8ec3676467ca82cf937fc662d628n/a157.240.20.63:443
2022-10-27 21:06:2222884dd9551ece8bef4f716f5774ea61Virustotal results 26 / 72 (36.11%) 157.240.247.63:443
2022-10-27 21:06:2222884dd9551ece8bef4f716f5774ea61Virustotal results 26 / 72 (36.11%) 157.240.201.63:443
2022-10-27 19:18:5701132f4c8f991180a5b9c523853fe9f8Virustotal results 36 / 72 (50.00%) 157.240.247.63:443
2022-10-27 18:39:1168c81ae0153755e92d610c253327af01n/a157.240.17.63:443
2022-10-27 18:06:5600d24c82e0e2da5b9f857869a5d4af26Virustotal results 47 / 71 (66.20%) 157.240.17.63:443
2022-10-27 17:33:4829564fd91385206bba22cf14d015ad89Virustotal results 50 / 70 (71.43%) 157.240.17.63:443
2022-10-27 16:35:108a645352953ba700247b33de96f421a0n/a157.240.17.63:443
2022-10-27 16:05:3378b0abb8368cf555a457bd552bdfc0d7Virustotal results 60 / 71 (84.51%) 157.240.11.52:443
2022-10-27 15:32:22b4f58d868e1774e2095da43a9f651171n/a157.240.201.63:443
2022-10-27 13:06:3182f7cfd7af1db6b322b770767ecf0443n/a157.240.22.63:443
2022-09-10 15:02:13fed63e04cc8427f85ab5e0344ab7f244n/a157.240.17.63:443
2022-09-10 10:38:05990a8809a246831c3f23f303cefb0e2cn/a157.240.247.63:443
2022-09-10 06:07:424e246ba3f6867950513382219e4aa921n/a157.240.17.63:443
2022-08-28 13:04:33fef3db4ad1181c8971b746647fc3c8ban/a157.240.17.63:443
2022-08-26 23:25:5598f756dc776d1aaaa5cff490376f17c4Virustotal results 27 / 69 (39.13%) 185.60.216.52:443
2022-08-26 23:01:108defc530caecfd189931580dd2ae1998n/a157.240.196.63:443
2022-08-26 23:01:108defc530caecfd189931580dd2ae1998n/a157.240.201.63:443
2022-08-26 22:59:53880c519fdce0f2a1aa97dbf554a27580n/a157.240.17.63:443
2022-08-26 22:27:475b49d4a2b69c4282b042f5f866a84a33Virustotal results 54 / 71 (76.06%) 157.240.17.63:443
2022-08-26 22:17:465340f59ba8da484f2381aebf593c5833Virustotal results 52 / 71 (73.24%) 157.240.247.63:443
2022-08-26 22:16:4031a6199d5d2e2b82a77e08ec26313f1bVirustotal results 48 / 71 (67.61%) 157.240.247.63:443
2022-08-26 13:08:50d5d27ac5c65e3b9990e38558ea75fec6n/a157.240.17.63:443
2022-08-26 10:14:13bb066cddd5b62002ddb105d88d6945c4n/a157.240.247.63:443
2022-08-26 09:07:31b636b2afabdeabda0713c31b582ff0bbn/a157.240.20.63:443
2022-08-26 09:07:30b636b2afabdeabda0713c31b582ff0bbn/a185.60.216.52:443
2022-08-26 01:15:023632417b24325ebe511cf0abdaa0c3cfn/a157.240.17.63:443
2022-08-26 01:09:5730d3dca470c12b0856834d1800ba89c9n/a157.240.247.63:443
2022-08-26 01:01:4826b24e238c8f9eaf528100101a5119f0n/a157.240.247.63:443
2022-08-26 01:01:4726b24e238c8f9eaf528100101a5119f0n/a157.240.201.63:443
2022-08-13 15:10:58a1dd595c9b0ecc88a80051fec0439814n/a157.240.17.63:443
2022-07-25 21:28:5951f81d8a1db9f8a9c51daaec3a4bf4edn/a157.240.17.63:443
2022-06-06 19:58:48ba4e843255dd4005041543477dd85ed3n/a157.240.201.63:443
2022-05-19 01:14:480085db88c7814373f9160d29423eb27en/a157.240.17.63:443
2022-04-30 13:29:19b600e2503a3e84a33fe82c05d2c4acf4n/a157.240.17.63:443
2022-04-28 14:24:080da4de1f7a12624e5d4b010ed72b2003Virustotal results 41 / 71 (57.75%) 157.240.17.63:443
2022-04-28 11:20:47f163008a2a146317dd57d5673712e3e3n/a157.240.9.52:443
2022-04-28 09:48:13796333cee5e30770f35bd072ed6f6d3bn/a157.240.17.63:443
2022-04-28 08:08:16aa8dddf165038b76396c6887861c7737n/a157.240.11.52:443
2022-04-28 07:42:39aa2a7873a2df6bbfd9f8f3dd21fb382cn/a157.240.17.63:443
2022-04-28 05:39:03b019a9a5d4bc1d85462ea25e5227d20an/a157.240.22.63:443
2022-04-28 04:32:017c5fc370ff8ded0b7cb4e9acab7d0b16n/a157.240.17.63:443
2022-04-28 01:43:415286bd9b336025cb129d7b297109d70dn/a157.240.17.63:443
2022-04-27 23:17:226d24c650f874c108549872fdb0dbfe7en/a157.240.17.63:443
2022-04-27 21:58:01b9752bbe1b09eeed11d7a298d3b0c664n/a157.240.17.63:443
2022-04-25 17:10:3212d5ffd92740d47a5b90d7b8d2f4842cVirustotal results 48 / 69 (69.57%) 31.13.64.52:443
2022-04-24 08:38:51aac70a1d03659db37f4e9a6ca4cda521n/a157.240.17.63:443
2022-04-21 07:23:392c6b8c118b30b6faf424f5246fb3e055n/a157.240.17.63:443
2022-04-21 06:49:01a0d009d84f8e2bfaf9446d475d576d25n/a185.60.216.52:443
2022-04-21 06:49:01a0d009d84f8e2bfaf9446d475d576d25n/a157.240.20.63:443
2022-04-20 22:23:36564a832fbfbe0fb80dbd71c6fb01f55dn/a157.240.17.63:443
2022-04-20 09:12:11921aca9fb58246dcf100754d93390d67n/a157.240.20.63:443
2022-04-20 09:12:11921aca9fb58246dcf100754d93390d67n/a185.60.216.52:443

# of entries: 100 (max: 100)