JA3 Fingerprints

You can find further information about the JA3 fingerprint 807fca46d9d0cf63adf4e5e80e414bbe, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:807fca46d9d0cf63adf4e5e80e414bbe
First seen:2018-06-07 16:51:03 UTC
Last seen:2021-08-07 03:15:42 UTC
Status:Blacklisted
Malware samples:977
Destination IPs:281
Malware:Tofsee -
Listing date:2020-01-09 14:22:48

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2023-02-07 14:18:492a35046b2579468e641585d6c00cd809Virustotal results 8 / 62 (12.90%) 162.159.138.232:443
2023-02-07 13:28:59080586757d7a4b7bdef947d58e2b9b98Virustotal results 34 / 69 (49.28%) 162.159.136.232:443
2023-02-03 22:36:261ff30ab5161ad8205700e0c9a81cab13n/a185.40.154.13:443
2023-02-03 22:36:261ff30ab5161ad8205700e0c9a81cab13n/a99.84.192.101:443
2023-02-03 22:36:261ff30ab5161ad8205700e0c9a81cab13n/a185.40.154.13:443
2023-02-03 22:36:261ff30ab5161ad8205700e0c9a81cab13n/a99.84.192.101:443
2023-02-03 19:44:0828e75f2acbd054f6dd4311897458f405n/a104.237.62.211:443
2023-02-03 19:44:0828e75f2acbd054f6dd4311897458f405n/a162.159.136.232:443
2023-02-03 19:44:0828e75f2acbd054f6dd4311897458f405n/a104.20.68.143:443
2023-02-01 17:03:3769991ad06c9136a771c312a33ad463bcn/a162.159.138.232:443
2023-02-01 17:03:3769991ad06c9136a771c312a33ad463bcn/a104.20.68.143:443
2023-02-01 17:03:3769991ad06c9136a771c312a33ad463bcn/a104.237.62.211:443
2023-02-01 11:10:5813bb645507e789fc1c1b2accbaeb96eaVirustotal results 33 / 68 (48.53%) 104.237.62.211:443
2023-02-01 11:10:5813bb645507e789fc1c1b2accbaeb96eaVirustotal results 33 / 68 (48.53%) 162.159.137.232:443
2023-02-01 11:10:5813bb645507e789fc1c1b2accbaeb96eaVirustotal results 33 / 68 (48.53%) 104.20.67.143:443
2023-01-31 02:28:33c18bcf84d1b96afa8a4425d3f47f309fn/a162.159.136.232:443
2023-01-22 21:52:546ce55dec5efa07ab71104205076d6c68n/a162.159.136.232:443
2023-01-20 22:29:50fdf3f205d8026fd353415aae94af28e9n/a104.237.62.211:443
2023-01-20 22:29:50fdf3f205d8026fd353415aae94af28e9n/a162.159.128.233:443
2023-01-18 12:39:59e98f2211ce6f858d25fe7162707359ben/a104.20.68.143:443
2023-01-18 12:39:59e98f2211ce6f858d25fe7162707359ben/a104.237.62.211:443
2023-01-18 12:39:59e98f2211ce6f858d25fe7162707359ben/a162.159.136.232:443
2023-01-18 03:26:01cfd851af4c98887f17f17701476f61ebn/a162.159.138.232:443
2023-01-17 22:03:50c3a16d7fc6561f82735b58603cbd504dn/a162.159.137.232:443
2023-01-17 22:03:50c3a16d7fc6561f82735b58603cbd504dn/a104.20.68.143:443
2023-01-17 22:03:50c3a16d7fc6561f82735b58603cbd504dn/a64.185.227.155:443
2023-01-16 23:11:2564860909b6e147172cdb42ad35c826e3n/a172.67.34.170:443
2023-01-16 23:11:2564860909b6e147172cdb42ad35c826e3n/a162.159.135.233:443
2023-01-16 23:11:2464860909b6e147172cdb42ad35c826e3n/a104.237.62.211:443
2023-01-09 01:38:367cbf7e9ab78bf576cac250e73b814851n/a34.160.111.145:443
2023-01-09 01:38:367cbf7e9ab78bf576cac250e73b814851n/a162.159.136.232:443
2023-01-04 18:16:092e937adf2a89d1a046cb3ea0542028d9Virustotal results 32 / 66 (48.48%) 104.237.62.212:443
2023-01-04 18:16:092e937adf2a89d1a046cb3ea0542028d9Virustotal results 32 / 66 (48.48%) 162.159.136.232:443
2023-01-04 18:16:082e937adf2a89d1a046cb3ea0542028d9Virustotal results 32 / 66 (48.48%) 172.67.34.170:443
2023-01-03 11:34:57f0783e36f29f21ef1e0c9284d95fd168n/a162.159.128.233:443
2023-01-01 03:04:4275cf3f55cf451084cced699934590084n/a162.159.138.232:443
2022-12-30 13:51:532a3390e77a9a4127204513056f2953dcn/a162.159.135.232:443
2022-12-30 13:51:532a3390e77a9a4127204513056f2953dcn/a34.160.111.145:443
2022-12-15 09:09:574d90f7ea3ec9cf206beaf776a36eb3fcn/a162.159.138.232:443
2022-12-15 04:42:12db30734ad5801e4f68666d4f337f74f6n/a104.237.62.212:443
2022-12-15 04:42:12db30734ad5801e4f68666d4f337f74f6n/a162.159.138.232:443
2022-12-11 20:05:2268753aa9586c56cee84ca471a4a0e308n/a162.159.136.232:443
2022-12-11 09:16:585a57b5c8b3074e6df3a2e83fa7610182Virustotal results 25 / 69 (36.23%) 173.231.16.76:443
2022-12-11 09:16:585a57b5c8b3074e6df3a2e83fa7610182Virustotal results 25 / 69 (36.23%) 162.159.128.233:443
2022-12-11 06:12:41bbe8d5b2b0bd2b69aab35136a658fdebn/a162.159.135.232:443
2022-12-11 02:26:43b1cd5913b3723fae7eac716ac9411b0en/a162.159.138.232:443
2022-12-11 02:26:43b1cd5913b3723fae7eac716ac9411b0en/a104.237.62.212:443
2022-12-11 02:26:43b1cd5913b3723fae7eac716ac9411b0en/a104.20.68.143:443
2022-12-10 23:48:13ab44834132690f2bd41a60136aca2e83n/a104.237.62.212:443
2022-12-10 12:22:4809e35ec958b718b81c8d89fe083ec5deVirustotal results 41 / 71 (57.75%) 162.159.128.233:443
2022-12-10 12:22:4809e35ec958b718b81c8d89fe083ec5deVirustotal results 41 / 71 (57.75%) 104.237.62.212:443
2022-11-20 16:53:4756648db8b4a237c6981e12d7048ef9c8n/a144.76.136.153:443
2022-11-14 09:23:02b47ae09f86fefb8efc7572a83b6ded62n/a162.159.128.233:443
2022-11-10 10:20:18e3fa476e00a9961a0aa3145e1478d284n/a162.159.136.232:443
2022-11-10 10:20:18e3fa476e00a9961a0aa3145e1478d284n/a3.220.57.224:443
2022-10-15 18:27:4521add128d45831529185751a39466310Virustotal results 6 / 72 (8.33%) 65.108.156.223:443
2022-10-09 06:54:32bfbf6572787412ccb11f20b6a42127b5Virustotal results 19 / 71 (26.76%) 104.20.67.143:443
2022-10-09 06:54:32bfbf6572787412ccb11f20b6a42127b5Virustotal results 19 / 71 (26.76%) 185.199.108.133:443
2022-10-04 17:56:43e0d4a76eb5489edecd7c247840a93861n/a188.114.97.7:443
2022-10-04 17:56:43e0d4a76eb5489edecd7c247840a93861n/a162.159.136.232:443
2022-10-04 17:32:16d9d25695631379039a304ee3ea74d1c8n/a162.159.138.232:443
2022-10-04 04:21:008ba8e377019585d80fed2e5adae88b61n/a3.232.242.170:443
2022-10-04 04:21:008ba8e377019585d80fed2e5adae88b61n/a104.20.68.143:443
2022-10-04 04:21:008ba8e377019585d80fed2e5adae88b61n/a162.159.137.232:443
2022-10-01 12:45:09eef1936396ab53a6617fe7bd3af75bbfn/a162.159.135.232:443
2022-10-01 12:45:09eef1936396ab53a6617fe7bd3af75bbfn/a3.232.242.170:443
2022-10-01 12:45:09eef1936396ab53a6617fe7bd3af75bbfn/a172.67.34.170:443
2022-09-22 15:18:51b649eb643a22a9824831820cd862cfbdn/a162.159.137.232:443
2022-09-22 15:18:51b649eb643a22a9824831820cd862cfbdn/a172.67.34.170:443
2022-09-22 15:18:51b649eb643a22a9824831820cd862cfbdn/a3.220.57.224:443
2022-09-21 12:04:220ee367040f932d7dfa20ca25d139104cVirustotal results 36 / 70 (51.43%) 162.159.137.232:443
2022-09-14 22:52:32e6633e964e603c722fc950b3f3a96ce6n/a162.159.137.232:443
2022-09-14 22:52:32e6633e964e603c722fc950b3f3a96ce6n/a104.20.68.143:443
2022-09-14 22:52:32e6633e964e603c722fc950b3f3a96ce6n/a52.20.78.240:443
2022-09-14 18:36:29ca38ecc27e50dacfb8462a31146fd0ddn/a162.159.136.232:443
2022-09-14 18:36:29ca38ecc27e50dacfb8462a31146fd0ddn/a104.20.68.143:443
2022-09-14 05:52:3279ba0900754b03eb3165c15edb98ab63n/a104.20.68.143:443
2022-09-14 05:52:3279ba0900754b03eb3165c15edb98ab63n/a162.159.135.233:443
2022-09-14 05:52:3279ba0900754b03eb3165c15edb98ab63n/a162.159.137.232:443
2022-09-13 23:29:4250ed56c48c0ca8658531a1298a56f9fbn/a3.220.57.224:443
2022-09-13 23:29:4250ed56c48c0ca8658531a1298a56f9fbn/a172.217.168.3:443
2022-09-13 23:29:4250ed56c48c0ca8658531a1298a56f9fbn/a162.159.138.232:443
2022-09-13 23:29:4250ed56c48c0ca8658531a1298a56f9fbn/a104.20.67.143:443
2022-09-13 16:35:4127da12482f40ff1074d9cd04dc943768Virustotal results 21 / 69 (30.43%) 34.160.111.145:443
2022-09-13 16:35:4127da12482f40ff1074d9cd04dc943768Virustotal results 21 / 69 (30.43%) 162.159.137.232:443
2022-09-10 13:51:19f80cf5a8cb1ade52b6b85bd654e47c51n/a104.20.67.143:443
2022-09-10 13:51:19f80cf5a8cb1ade52b6b85bd654e47c51n/a52.20.78.240:443
2022-09-10 13:51:19f80cf5a8cb1ade52b6b85bd654e47c51n/a162.159.138.232:443
2022-09-04 05:19:0570e8f6ef93eb50cd5f06a8beabf7fa0an/a185.199.111.133:443
2022-09-04 05:19:0570e8f6ef93eb50cd5f06a8beabf7fa0an/a172.67.34.170:443
2022-09-03 17:46:5903c59ee6d746e78cff61c4f9090be60cn/a104.20.68.143:443
2022-09-03 17:46:5903c59ee6d746e78cff61c4f9090be60cn/a3.220.57.224:443
2022-09-03 17:46:5903c59ee6d746e78cff61c4f9090be60cn/a162.159.138.232:443
2022-08-27 19:22:57ee3022fffb80cb985d0fe38d4fb34e02n/a162.159.136.232:443
2022-08-27 19:22:57ee3022fffb80cb985d0fe38d4fb34e02n/a34.160.111.145:443
2022-08-25 22:09:38d04360c76e34b86b1672e4f42a1cc064n/a3.220.57.224:443
2022-08-25 22:09:38d04360c76e34b86b1672e4f42a1cc064n/a162.159.135.232:443
2022-08-25 22:09:38d04360c76e34b86b1672e4f42a1cc064n/a104.20.68.143:443
2022-08-25 16:28:2655deda26ea3d71cb214d2dca4b69727en/a162.159.138.232:443
2022-08-25 16:28:2655deda26ea3d71cb214d2dca4b69727en/a104.20.67.143:443

# of entries: 100 (max: 100)