JA3 Fingerprints

You can find further information about the JA3 fingerprint 7dcce5b76c8b17472d024758970a406b, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:7dcce5b76c8b17472d024758970a406b
First seen:2017-11-22 12:42:46 UTC
Last seen:2019-04-20 05:05:19 UTC
Status:Blacklisted
Malware samples:51
Destination IPs:41
Malware:Tofsee -
Listing date:2018-11-14 12:39:56

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2019-04-20 05:05:19385622c40b99b7dfbcad474a75ffc200n/a23.211.6.196:443
2019-04-16 19:38:246f94250fd038748283a8cea015a920e5n/a88.221.165.146:443
2019-04-10 06:04:443625e4917f620c3f9627f5bf0be3c895n/a35.160.7.30:443
2019-04-08 04:09:18cbe8dffe151f8ed0412d684ca8430128Virustotal results 35/66 (53.03%) 35.160.69.163:443
2019-04-08 04:09:18cbe8dffe151f8ed0412d684ca8430128Virustotal results 35/66 (53.03%) 52.33.42.218:443
2019-04-07 13:35:5996f8471a20fc9d665fc3e444dca25b69Virustotal results 36/67 (53.73%) 52.43.223.181:443
2019-04-07 10:58:42dfd2884b93775c662c3a057487f3da27Virustotal results 35/68 (51.47%) 50.112.213.184:443
2019-03-23 04:28:347d2472198cb536b033d5904ae609bd45n/a52.30.134.73:443
2019-03-23 04:28:347d2472198cb536b033d5904ae609bd45n/a54.171.27.14:443
2019-03-21 05:20:2064d87d62e00076fabe1cbc9184c1f29en/a54.77.135.19:443
2019-03-17 23:53:398d1026fe8bbf09734ae70a3d4c5360ben/a52.36.31.140:443
2019-03-17 23:53:398d1026fe8bbf09734ae70a3d4c5360ben/a52.40.19.98:443
2019-03-17 23:53:388d1026fe8bbf09734ae70a3d4c5360ben/a52.10.96.2:443
2019-03-17 23:53:388d1026fe8bbf09734ae70a3d4c5360ben/a52.40.54.78:443
2019-03-17 23:53:388d1026fe8bbf09734ae70a3d4c5360ben/a50.112.221.133:443
2019-03-14 01:49:44331d5ac244795e202b869668c5836b2bVirustotal results 37/65 (56.92%) 52.209.214.74:443
2019-03-14 01:49:44331d5ac244795e202b869668c5836b2bVirustotal results 37/65 (56.92%) 54.76.99.188:443
2019-03-14 01:49:44331d5ac244795e202b869668c5836b2bVirustotal results 37/65 (56.92%) 52.30.45.198:443
2019-03-12 13:08:23e0f76b90905ec73d159f3b0054a681a5n/a52.30.128.237:443
2019-02-15 21:24:36ac08737d4b88cd5df916448da941fae8Virustotal results 41/69 (59.42%) 2.22.201.103:443
2019-01-03 19:12:59ec40ccaad63f8855d8de31a42b7c67acVirustotal results 28/69 (40.58%) 54.171.27.14:443
2018-10-12 02:22:0602340aab7ac9b9305a88ddaec71ce18cVirustotal results 36/69 (52.17%) 52.223.241.20:443
2018-10-12 02:22:0502340aab7ac9b9305a88ddaec71ce18cVirustotal results 36/69 (52.17%) 52.223.241.21:443
2018-10-11 09:17:492886a390e674776c4a94674c0ed382ffVirustotal results 18/69 (26.09%) 52.223.241.21:443
2018-10-09 04:51:51e16582bbc7a4adcc0d7791b6b3ae6ca7Virustotal results 37/69 (53.62%) 52.223.241.21:443
2018-10-06 03:10:35a84c251bd0191808f5b819e2b13f2a3dVirustotal results 36/68 (52.94%) 159.153.191.240:443
2018-10-06 03:10:34a84c251bd0191808f5b819e2b13f2a3dVirustotal results 36/68 (52.94%) 159.153.191.239:443
2018-10-05 22:21:29614ffc059fc2ecbbd09cac491a27f25dVirustotal results 35/69 (50.72%) 159.153.191.240:443
2018-10-05 22:21:29614ffc059fc2ecbbd09cac491a27f25dVirustotal results 35/69 (50.72%) 159.153.191.239:443
2018-10-05 21:11:01a2c265dcda4b8c63343326368a7edd9aVirustotal results 36/67 (53.73%) 159.153.191.240:443
2018-10-05 21:11:00a2c265dcda4b8c63343326368a7edd9aVirustotal results 36/67 (53.73%) 159.153.191.239:443
2018-10-05 21:10:59a2c265dcda4b8c63343326368a7edd9aVirustotal results 36/67 (53.73%) 52.223.241.21:443
2018-10-05 21:10:58a2c265dcda4b8c63343326368a7edd9aVirustotal results 36/67 (53.73%) 52.223.241.20:443
2018-10-03 23:13:45a679fc33cd540373f39838d4d6dfdca8Virustotal results 35/69 (50.72%) 188.166.143.163:443
2018-09-30 10:20:331032c4d8e0f2c07fb67ef23c91cfeec6Virustotal results 25/68 (36.76%) 52.223.241.21:443
2018-09-29 20:02:24f0ef0845b106f5aff1965ee3b38bd69en/a52.223.241.21:443
2018-09-29 20:02:24f0ef0845b106f5aff1965ee3b38bd69en/a52.223.241.20:443
2018-09-29 14:56:4311767ddc618756b6b640160e541473edVirustotal results 37/69 (53.62%) 52.223.241.21:443
2018-09-29 14:56:4311767ddc618756b6b640160e541473edVirustotal results 37/69 (53.62%) 52.223.241.20:443
2018-09-25 22:08:59bedc6c35189f81de5267b375ad149324Virustotal results 33/68 (48.53%) 52.223.241.21:443
2018-09-25 22:08:57bedc6c35189f81de5267b375ad149324Virustotal results 33/68 (48.53%) 52.223.241.20:443
2018-09-25 21:24:2917b28eae4c3ef0e41549951f2fa73ce9Virustotal results 32/69 (46.38%) 52.223.241.20:443
2018-09-25 21:24:2417b28eae4c3ef0e41549951f2fa73ce9Virustotal results 32/69 (46.38%) 52.223.241.21:443
2018-09-25 17:43:21048891d91129fd6077b5ca2e9cb89e61Virustotal results 29/69 (42.03%) 52.223.241.20:443
2018-09-25 17:43:20048891d91129fd6077b5ca2e9cb89e61Virustotal results 29/69 (42.03%) 52.223.241.21:443
2018-09-22 21:39:23bd61ef212d566d7619caf25b9d33399bVirustotal results 41/68 (60.29%) 192.108.239.108:443
2018-09-22 21:39:22bd61ef212d566d7619caf25b9d33399bVirustotal results 41/68 (60.29%) 52.223.241.20:443
2018-09-06 15:17:36804fcadfb4edc3fefece4f6fe8fca94bVirustotal results 22/68 (32.35%) 52.223.241.21:443
2018-08-27 23:22:42bc346d0e973fedec461f0c4db651df12Virustotal results 36/67 (53.73%) 52.223.228.241:443
2018-08-27 23:22:41bc346d0e973fedec461f0c4db651df12Virustotal results 36/67 (53.73%) 52.223.227.101:443
2018-08-27 23:22:32bc346d0e973fedec461f0c4db651df12Virustotal results 36/67 (53.73%) 52.223.241.20:443
2018-08-27 23:22:32bc346d0e973fedec461f0c4db651df12Virustotal results 36/67 (53.73%) 52.223.241.21:443
2018-08-26 20:06:02d21f1bff8d6ade12305e25511a2f1f1eVirustotal results 34/66 (51.52%) 185.42.206.91:443
2018-08-24 15:14:268820060303e2fdcfe558f54cc298a039Virustotal results 38/68 (55.88%) 52.223.241.20:443
2018-05-28 17:31:376d8371cd42322e64cd99141cc8f3e1d9Virustotal results 31/66 (46.97%) 2.17.226.54:443
2018-04-13 05:58:24e64d5d4dbc43d97734685452cf1ca6f8Virustotal results 37/67 (55.22%) 104.73.128.139:443
2018-04-13 05:58:24e64d5d4dbc43d97734685452cf1ca6f8Virustotal results 37/67 (55.22%) 151.101.1.204:443
2018-04-03 01:04:503298a674db74aeb183b757b0254c02a7Virustotal results 33/67 (49.25%) 91.235.140.148:443
2018-03-18 00:29:443cde9b22f945f7d3a2933663337a1572Virustotal results 37/66 (56.06%) 151.101.1.204:443
2018-03-18 00:29:443cde9b22f945f7d3a2933663337a1572Virustotal results 37/66 (56.06%) 2.20.76.70:443
2018-03-17 12:20:30100a752c5bfceff1995d97cf27cf8e1bVirustotal results 23/66 (34.85%) 159.153.191.239:443
2018-03-17 12:20:30100a752c5bfceff1995d97cf27cf8e1bVirustotal results 23/66 (34.85%) 159.153.191.240:443
2018-03-17 11:53:14009097035eab9fd1ee2ce4e97e8de4abVirustotal results 38/65 (58.46%) 104.73.128.139:443
2018-03-17 11:53:14009097035eab9fd1ee2ce4e97e8de4abVirustotal results 38/65 (58.46%) 151.101.1.204:443
2018-03-16 23:00:55cc0e0e8d8b40f72fc136bfaa0a763870Virustotal results 38/67 (56.72%) 159.153.191.239:443
2018-03-16 23:00:55cc0e0e8d8b40f72fc136bfaa0a763870Virustotal results 38/67 (56.72%) 159.153.191.240:443
2018-03-10 19:43:1417344aa1656a4660357d5d96cf7e02d9Virustotal results 42/65 (64.62%) 151.101.1.204:443
2018-03-10 17:49:33011ec42a1518ed896b091f188ac416f7Virustotal results 35/67 (52.24%) 151.101.1.204:443
2018-03-10 08:31:36c794c39c4c646435befff731e2350893Virustotal results 39/58 (67.24%) 2.20.76.70:443
2018-03-10 08:31:36c794c39c4c646435befff731e2350893Virustotal results 39/58 (67.24%) 151.101.1.204:443
2018-03-10 07:51:404db7c68d371c42c219a2225ca71ab350Virustotal results 40/68 (58.82%) 151.101.1.204:443
2018-03-08 06:57:24454f9ae39bd061019bdcadcb881446caVirustotal results 34/67 (50.75%) 151.101.1.204:443
2018-02-25 14:54:177420b52ae4f605dfdb2a8d423f4b20c3Virustotal results 33/68 (48.53%) 2.19.77.81:443
2018-02-24 11:19:589ae21b2ef3c56d249e07351e31a7d937Virustotal results 27/67 (40.30%) 2.19.77.81:443
2018-02-12 10:20:18ea06d1ecb55a8cf3fc646a279208422aVirustotal results 50/68 (73.53%) 66.211.179.150:443
2018-02-12 10:20:18ea06d1ecb55a8cf3fc646a279208422aVirustotal results 50/68 (73.53%) 66.211.179.180:443
2018-01-27 19:33:55710e56576651c49c0c1335bb92f34335Virustotal results 16/66 (24.24%) 104.96.17.149:443
2018-01-26 03:15:254f1d457a7a982d1efa1b78cc8ec89ef2Virustotal results 23/64 (35.94%) 66.135.223.243:443
2018-01-26 03:06:1432eea98d8cfe40075ee912361445452aVirustotal results 22/65 (33.85%) 66.135.223.243:443
2018-01-10 11:36:35094ae14264f2817db78894e3e83169c2Virustotal results 13/68 (19.12%) 104.73.136.164:443
2017-11-22 12:42:4694c54be0be25b4dee0aa3db016c4b524Virustotal results 26/68 (38.24%) 54.239.29.142:443

# of entries: 81 (max: 100)