JA3 Fingerprints

You can find further information about the JA3 fingerprint 7dcce5b76c8b17472d024758970a406b, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:7dcce5b76c8b17472d024758970a406b
First seen:2017-11-22 12:42:46 UTC
Last seen:2019-01-03 19:12:59 UTC
Status:Blacklisted
Malware samples:39
Destination IPs:22
Malware:Tofsee -
Listing date:2018-11-14 12:39:56

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2019-01-03 19:12:59ec40ccaad63f8855d8de31a42b7c67acVirustotal results 28/69 (40.58%) 54.171.27.14:443
2018-10-12 02:22:0602340aab7ac9b9305a88ddaec71ce18cVirustotal results 36/69 (52.17%) 52.223.241.20:443
2018-10-12 02:22:0502340aab7ac9b9305a88ddaec71ce18cVirustotal results 36/69 (52.17%) 52.223.241.21:443
2018-10-11 09:17:492886a390e674776c4a94674c0ed382ffVirustotal results 18/69 (26.09%) 52.223.241.21:443
2018-10-09 04:51:51e16582bbc7a4adcc0d7791b6b3ae6ca7Virustotal results 37/69 (53.62%) 52.223.241.21:443
2018-10-06 03:10:35a84c251bd0191808f5b819e2b13f2a3dVirustotal results 36/68 (52.94%) 159.153.191.240:443
2018-10-06 03:10:34a84c251bd0191808f5b819e2b13f2a3dVirustotal results 36/68 (52.94%) 159.153.191.239:443
2018-10-05 22:21:29614ffc059fc2ecbbd09cac491a27f25dVirustotal results 35/69 (50.72%) 159.153.191.240:443
2018-10-05 22:21:29614ffc059fc2ecbbd09cac491a27f25dVirustotal results 35/69 (50.72%) 159.153.191.239:443
2018-10-05 21:11:01a2c265dcda4b8c63343326368a7edd9aVirustotal results 36/67 (53.73%) 159.153.191.240:443
2018-10-05 21:11:00a2c265dcda4b8c63343326368a7edd9aVirustotal results 36/67 (53.73%) 159.153.191.239:443
2018-10-05 21:10:59a2c265dcda4b8c63343326368a7edd9aVirustotal results 36/67 (53.73%) 52.223.241.21:443
2018-10-05 21:10:58a2c265dcda4b8c63343326368a7edd9aVirustotal results 36/67 (53.73%) 52.223.241.20:443
2018-10-03 23:13:45a679fc33cd540373f39838d4d6dfdca8Virustotal results 35/69 (50.72%) 188.166.143.163:443
2018-09-30 10:20:331032c4d8e0f2c07fb67ef23c91cfeec6Virustotal results 25/68 (36.76%) 52.223.241.21:443
2018-09-29 20:02:24f0ef0845b106f5aff1965ee3b38bd69en/a52.223.241.21:443
2018-09-29 20:02:24f0ef0845b106f5aff1965ee3b38bd69en/a52.223.241.20:443
2018-09-29 14:56:4311767ddc618756b6b640160e541473edVirustotal results 37/69 (53.62%) 52.223.241.21:443
2018-09-29 14:56:4311767ddc618756b6b640160e541473edVirustotal results 37/69 (53.62%) 52.223.241.20:443
2018-09-25 22:08:59bedc6c35189f81de5267b375ad149324Virustotal results 33/68 (48.53%) 52.223.241.21:443
2018-09-25 22:08:57bedc6c35189f81de5267b375ad149324Virustotal results 33/68 (48.53%) 52.223.241.20:443
2018-09-25 21:24:2917b28eae4c3ef0e41549951f2fa73ce9Virustotal results 32/69 (46.38%) 52.223.241.20:443
2018-09-25 21:24:2417b28eae4c3ef0e41549951f2fa73ce9Virustotal results 32/69 (46.38%) 52.223.241.21:443
2018-09-25 17:43:21048891d91129fd6077b5ca2e9cb89e61Virustotal results 29/69 (42.03%) 52.223.241.20:443
2018-09-25 17:43:20048891d91129fd6077b5ca2e9cb89e61Virustotal results 29/69 (42.03%) 52.223.241.21:443
2018-09-22 21:39:23bd61ef212d566d7619caf25b9d33399bVirustotal results 41/68 (60.29%) 192.108.239.108:443
2018-09-22 21:39:22bd61ef212d566d7619caf25b9d33399bVirustotal results 41/68 (60.29%) 52.223.241.20:443
2018-09-06 15:17:36804fcadfb4edc3fefece4f6fe8fca94bVirustotal results 22/68 (32.35%) 52.223.241.21:443
2018-08-27 23:22:42bc346d0e973fedec461f0c4db651df12Virustotal results 36/67 (53.73%) 52.223.228.241:443
2018-08-27 23:22:41bc346d0e973fedec461f0c4db651df12Virustotal results 36/67 (53.73%) 52.223.227.101:443
2018-08-27 23:22:32bc346d0e973fedec461f0c4db651df12Virustotal results 36/67 (53.73%) 52.223.241.20:443
2018-08-27 23:22:32bc346d0e973fedec461f0c4db651df12Virustotal results 36/67 (53.73%) 52.223.241.21:443
2018-08-26 20:06:02d21f1bff8d6ade12305e25511a2f1f1eVirustotal results 34/66 (51.52%) 185.42.206.91:443
2018-08-24 15:14:268820060303e2fdcfe558f54cc298a039Virustotal results 38/68 (55.88%) 52.223.241.20:443
2018-05-28 17:31:376d8371cd42322e64cd99141cc8f3e1d9Virustotal results 31/66 (46.97%) 2.17.226.54:443
2018-04-13 05:58:24e64d5d4dbc43d97734685452cf1ca6f8Virustotal results 37/67 (55.22%) 104.73.128.139:443
2018-04-13 05:58:24e64d5d4dbc43d97734685452cf1ca6f8Virustotal results 37/67 (55.22%) 151.101.1.204:443
2018-04-03 01:04:503298a674db74aeb183b757b0254c02a7Virustotal results 33/67 (49.25%) 91.235.140.148:443
2018-03-18 00:29:443cde9b22f945f7d3a2933663337a1572Virustotal results 37/66 (56.06%) 151.101.1.204:443
2018-03-18 00:29:443cde9b22f945f7d3a2933663337a1572Virustotal results 37/66 (56.06%) 2.20.76.70:443
2018-03-17 12:20:30100a752c5bfceff1995d97cf27cf8e1bVirustotal results 23/66 (34.85%) 159.153.191.239:443
2018-03-17 12:20:30100a752c5bfceff1995d97cf27cf8e1bVirustotal results 23/66 (34.85%) 159.153.191.240:443
2018-03-17 11:53:14009097035eab9fd1ee2ce4e97e8de4abVirustotal results 38/65 (58.46%) 104.73.128.139:443
2018-03-17 11:53:14009097035eab9fd1ee2ce4e97e8de4abVirustotal results 38/65 (58.46%) 151.101.1.204:443
2018-03-16 23:00:55cc0e0e8d8b40f72fc136bfaa0a763870Virustotal results 38/67 (56.72%) 159.153.191.240:443
2018-03-16 23:00:55cc0e0e8d8b40f72fc136bfaa0a763870Virustotal results 38/67 (56.72%) 159.153.191.239:443
2018-03-10 19:43:1417344aa1656a4660357d5d96cf7e02d9Virustotal results 42/65 (64.62%) 151.101.1.204:443
2018-03-10 17:49:33011ec42a1518ed896b091f188ac416f7Virustotal results 35/67 (52.24%) 151.101.1.204:443
2018-03-10 08:31:36c794c39c4c646435befff731e2350893Virustotal results 39/58 (67.24%) 2.20.76.70:443
2018-03-10 08:31:36c794c39c4c646435befff731e2350893Virustotal results 39/58 (67.24%) 151.101.1.204:443
2018-03-10 07:51:404db7c68d371c42c219a2225ca71ab350Virustotal results 40/68 (58.82%) 151.101.1.204:443
2018-03-08 06:57:24454f9ae39bd061019bdcadcb881446caVirustotal results 34/67 (50.75%) 151.101.1.204:443
2018-02-25 14:54:177420b52ae4f605dfdb2a8d423f4b20c3Virustotal results 33/68 (48.53%) 2.19.77.81:443
2018-02-24 11:19:589ae21b2ef3c56d249e07351e31a7d937Virustotal results 27/67 (40.30%) 2.19.77.81:443
2018-02-12 10:20:18ea06d1ecb55a8cf3fc646a279208422aVirustotal results 50/68 (73.53%) 66.211.179.150:443
2018-02-12 10:20:18ea06d1ecb55a8cf3fc646a279208422aVirustotal results 50/68 (73.53%) 66.211.179.180:443
2018-01-27 19:33:55710e56576651c49c0c1335bb92f34335Virustotal results 16/66 (24.24%) 104.96.17.149:443
2018-01-26 03:15:254f1d457a7a982d1efa1b78cc8ec89ef2Virustotal results 23/64 (35.94%) 66.135.223.243:443
2018-01-26 03:06:1432eea98d8cfe40075ee912361445452aVirustotal results 22/65 (33.85%) 66.135.223.243:443
2018-01-10 11:36:35094ae14264f2817db78894e3e83169c2Virustotal results 13/68 (19.12%) 104.73.136.164:443
2017-11-22 12:42:4694c54be0be25b4dee0aa3db016c4b524Virustotal results 26/68 (38.24%) 54.239.29.142:443

# of entries: 61 (max: 100)