JA3 Fingerprints

You can find further information about the JA3 fingerprint 35c0a31c481927f022a3b530255ac080, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:35c0a31c481927f022a3b530255ac080
First seen:2017-07-15 19:43:19 UTC
Last seen:2021-04-10 12:54:04 UTC
Status:Blacklisted
Malware samples:1'295
Destination IPs:203
Malware:Tofsee -
Listing date:2018-11-14 12:41:34

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2024-08-28 08:50:5987892c307f8712d913f1dc58c1392b81n/a157.240.17.63:443
2024-08-28 05:32:010d6bf26747ab7deeae8018d05b2a80b5n/a157.240.17.63:443
2024-08-27 03:11:00015d9bf35ccebccb9ef304821c5da406n/a157.240.17.63:443
2024-08-27 01:57:1501c9fa60761fb4b56a97b55c2bd8fba9n/a157.240.195.63:443
2024-08-27 01:57:1501c9fa60761fb4b56a97b55c2bd8fba9n/a157.240.195.63:443
2024-08-26 16:02:272b06a1519cf9599ed66f6f4aba70681en/a157.240.247.63:443
2024-08-26 16:02:262b06a1519cf9599ed66f6f4aba70681en/a157.240.201.63:443
2024-08-19 20:57:073e473f7a637ff2dc45471d51613145ecn/a157.240.17.63:443
2024-08-19 14:14:34083335113a0653558cdc4aca1d102c19n/a157.240.247.63:443
2024-08-19 13:03:121bd8cf561c3485efafe753a2967b8f0an/a57.144.120.192:443
2024-08-19 05:48:3844968637a5ad7eeefce05f43ac1efd11n/a157.240.17.63:443
2024-08-18 07:55:07144720f56cdc012920ec1bb2201ced0dn/a157.240.247.63:443
2024-08-18 01:25:030ef92126f66ce2443a81a7329b3e8351n/a157.240.223.63:443
2024-08-17 04:22:1523077579cea44ee2a468722a80c58685n/a157.240.203.63:443
2024-08-17 04:22:1423077579cea44ee2a468722a80c58685n/a157.240.201.63:443
2024-08-17 04:22:1323077579cea44ee2a468722a80c58685n/a157.240.247.63:443
2024-08-05 18:56:33c9e5c8ce493cae6be4e44b215f1528e1n/a157.240.201.63:443
2024-08-05 14:30:32b00e82bacbd2266b5e14f94010a0fae4n/a157.240.196.63:443
2024-08-05 03:33:426333f39a0cfea300c8c01ef65884c2f7n/a157.240.247.63:443
2024-08-05 03:33:416333f39a0cfea300c8c01ef65884c2f7n/a157.240.203.63:443
2024-06-21 17:23:516b57897a92c7b3d98ee9b60c3ce1a137n/a157.240.196.63:443
2024-06-12 10:42:5937963fac936267f5017c34c4196bd560n/a10.0.14.107:50000
2024-06-12 10:42:5837963fac936267f5017c34c4196bd560n/a157.240.201.63:443
2024-06-12 10:42:5737963fac936267f5017c34c4196bd560n/a10.0.14.107:50223
2024-06-12 10:42:5037963fac936267f5017c34c4196bd560n/a157.240.247.63:443
2024-05-29 08:26:098ff54d9a7fa992b297fb1e15588c3aeen/a31.13.86.52:443
2024-05-29 08:26:078ff54d9a7fa992b297fb1e15588c3aeen/a10.0.7.81:49999
2024-05-14 09:03:44e2875825a1b5c8f086d72b8f75150056n/a157.240.0.63:443
2024-05-14 09:03:41e2875825a1b5c8f086d72b8f75150056n/a10.0.20.138:50071
2024-05-14 09:03:36e2875825a1b5c8f086d72b8f75150056n/a10.0.20.138:50050
2024-04-13 18:47:11d790f163a9d67027383ce9d979e87029n/a157.240.17.63:443
2024-04-13 09:36:503379cf70f370742e7a6c117776771c8dn/a157.240.17.63:443
2024-01-29 15:44:40e93c433311d58577391f4ac85f36d752n/a10.0.14.235:49774
2024-01-29 15:44:39e93c433311d58577391f4ac85f36d752n/a31.13.84.52:443
2024-01-28 13:27:41a2aa23054c16ec5a732c3985809f583en/a157.240.253.63:443
2024-01-28 13:27:40a2aa23054c16ec5a732c3985809f583en/a10.0.14.236:50183
2024-01-28 13:27:32a2aa23054c16ec5a732c3985809f583en/a10.0.14.236:49859
2024-01-28 13:27:30a2aa23054c16ec5a732c3985809f583en/a10.0.14.236:49936
2024-01-28 13:27:30a2aa23054c16ec5a732c3985809f583en/a10.0.14.236:50264
2024-01-28 13:27:25a2aa23054c16ec5a732c3985809f583en/a10.0.14.236:49895
2024-01-08 06:16:41e77a1aef1a3f6107cd8ac432d3d50325n/a157.240.201.63:443
2024-01-08 05:05:33dd3a8f81c8fbd3c4ffd249b05c6f6fe5n/a157.240.17.63:443
2023-12-29 22:50:03a69f01de8fdeefb56b46e33390bf54b6Virustotal results 54 / 72 (75.00%) 157.240.251.63:443
2023-10-25 13:40:24c44607d75b82fd71dba507c41eec8493n/a217.69.139.61:443
2023-09-16 01:01:362fad45b92b035259d4b40f8dd83be28fn/a13.107.42.14:443
2023-09-16 01:01:332fad45b92b035259d4b40f8dd83be28fn/a10.0.7.85:50074
2023-09-16 01:01:332fad45b92b035259d4b40f8dd83be28fn/a10.0.7.85:50099
2023-04-13 03:42:08ab16ed8bf0e2b918f944bed8805bf35an/a13.107.42.14:443
2023-02-21 10:41:1339ee2114d05e7771740bada0b8871493n/a157.240.17.35:443
2022-11-09 04:23:18c364c9854d3262b7975e991bc066849cn/a157.240.17.63:443
2022-11-05 00:59:43869450e88727effc1038eaa80ee77fc0n/a157.240.201.63:443
2022-11-04 16:18:027091783e21821683751fdb2e06be76b1n/a157.240.17.63:443
2022-11-04 15:09:156dbe0a3bd17a1f983218dbcab8c26ab0n/a157.240.17.63:443
2022-11-04 14:11:186b7131cf14ebce7c6c0a9820d3584b6en/a157.240.17.63:443
2022-11-02 19:51:443950d84bcd3c4ed6b96a41d46737fd4en/a157.240.17.63:443
2022-11-02 16:52:59258b842ea2ebb01ee51444c2a14e8fcbn/a157.240.17.63:443
2022-11-02 16:41:0322f5aa618a7107e2d7d6741c821171edn/a157.240.20.63:443
2022-11-02 16:41:0322f5aa618a7107e2d7d6741c821171edn/a185.60.216.52:443
2022-11-02 07:38:221278fd376102db3e9f44c39c05299ac6n/a157.240.17.63:443
2022-11-02 01:18:31e63f4fe868021a05e5e4ded410b26718n/a157.240.20.63:443
2022-11-01 23:40:426c11d2a5b2ffb8ce57374526d3d5877an/a157.240.201.63:443
2022-11-01 23:32:166ae221dfbbddf38c7f0f50ce41f0bdc8n/a157.240.247.63:443
2022-11-01 02:28:0265d06cdf91153777d2c88fad225270d6n/a157.240.22.63:443
2022-10-31 20:12:10472d9ee61e16176bf8bae4126a44133en/a157.240.17.63:443
2022-10-31 18:41:1147ed0cda600d713807c0637eb6baf987n/a157.240.17.63:443
2022-10-31 18:30:43412f38d3059de15a10d9d2aa18758b22n/a157.240.17.63:443
2022-10-31 18:03:1742e18db52becf8a5b31e0c67efb46135n/a185.60.216.52:443
2022-10-31 16:08:34341ec7e0f99bb1541016b8f4fa5c0e3fn/a157.240.11.52:443
2022-10-31 13:31:043057477419aa647f98876ed7d625483dn/a157.240.22.63:443
2022-10-31 13:31:033057477419aa647f98876ed7d625483dn/a157.240.11.52:443
2022-10-30 13:49:1655006170e8a35db5fcab546144942aa1n/a157.240.11.52:443
2022-10-29 15:33:58e8638ad88395db2c211ce98599056e5dVirustotal results 28 / 72 (38.89%) 157.240.247.63:443
2022-10-29 15:32:50d258643332bccc2a1b0a85bb7b92adefn/a157.240.20.63:443
2022-10-28 05:52:49b893dcf14e9e9ac6c5cfefb50c388840n/a157.240.17.63:443
2022-10-28 05:48:41a8c53473c3ff974d9470dbb0dc38fcbbn/a157.240.17.63:443
2022-10-28 05:39:06621b519c3d70b7e14fa6723d72c544fen/a31.13.70.52:443
2022-10-28 05:32:32643dffd2cf34e325c81bd77922064247Virustotal results 35 / 71 (49.30%) 157.240.22.63:443
2022-10-28 05:20:2727ed630e4fb8fce3eb26855519071800Virustotal results 36 / 72 (50.00%) 157.240.17.63:443
2022-10-27 21:43:56194e8ec3676467ca82cf937fc662d628n/a157.240.20.63:443
2022-10-27 21:43:56194e8ec3676467ca82cf937fc662d628n/a157.240.247.63:443
2022-10-27 21:06:2222884dd9551ece8bef4f716f5774ea61Virustotal results 26 / 72 (36.11%) 157.240.247.63:443
2022-10-27 21:06:2222884dd9551ece8bef4f716f5774ea61Virustotal results 26 / 72 (36.11%) 157.240.201.63:443
2022-10-27 19:18:5701132f4c8f991180a5b9c523853fe9f8Virustotal results 36 / 72 (50.00%) 157.240.247.63:443
2022-10-27 18:39:1168c81ae0153755e92d610c253327af01n/a157.240.17.63:443
2022-10-27 18:06:5600d24c82e0e2da5b9f857869a5d4af26Virustotal results 47 / 71 (66.20%) 157.240.17.63:443
2022-10-27 17:33:4829564fd91385206bba22cf14d015ad89Virustotal results 50 / 70 (71.43%) 157.240.17.63:443
2022-10-27 16:35:108a645352953ba700247b33de96f421a0n/a157.240.17.63:443
2022-10-27 16:05:3378b0abb8368cf555a457bd552bdfc0d7Virustotal results 60 / 71 (84.51%) 157.240.11.52:443
2022-10-27 15:32:22b4f58d868e1774e2095da43a9f651171n/a157.240.201.63:443
2022-10-27 13:06:3182f7cfd7af1db6b322b770767ecf0443n/a157.240.22.63:443
2022-09-10 15:02:13fed63e04cc8427f85ab5e0344ab7f244n/a157.240.17.63:443
2022-09-10 10:38:05990a8809a246831c3f23f303cefb0e2cn/a157.240.247.63:443
2022-09-10 06:07:424e246ba3f6867950513382219e4aa921n/a157.240.17.63:443
2022-08-28 13:04:33fef3db4ad1181c8971b746647fc3c8ban/a157.240.17.63:443
2022-08-26 23:25:5598f756dc776d1aaaa5cff490376f17c4Virustotal results 27 / 69 (39.13%) 185.60.216.52:443
2022-08-26 23:01:108defc530caecfd189931580dd2ae1998n/a157.240.201.63:443
2022-08-26 23:01:108defc530caecfd189931580dd2ae1998n/a157.240.196.63:443
2022-08-26 22:59:53880c519fdce0f2a1aa97dbf554a27580n/a157.240.17.63:443
2022-08-26 22:27:475b49d4a2b69c4282b042f5f866a84a33Virustotal results 54 / 71 (76.06%) 157.240.17.63:443
2022-08-26 22:17:465340f59ba8da484f2381aebf593c5833Virustotal results 52 / 71 (73.24%) 157.240.247.63:443

# of entries: 100 (max: 100)