JA3 Fingerprints

You can find further information about the JA3 fingerprint 807fca46d9d0cf63adf4e5e80e414bbe, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:807fca46d9d0cf63adf4e5e80e414bbe
First seen:2018-06-07 16:51:03 UTC
Last seen:2021-08-07 03:15:42 UTC
Status:Blacklisted
Malware samples:907
Destination IPs:262
Malware:Tofsee -
Listing date:2020-01-09 14:22:48

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2022-06-29 11:46:10ccaaac10c297381889a3dccf0308c074n/a162.159.137.232:443
2022-06-29 11:46:10ccaaac10c297381889a3dccf0308c074n/a52.20.78.240:443
2022-06-28 06:37:01bbfe83d667ca760f6a53511fd5ded4f1n/a172.67.34.170:443
2022-06-28 06:37:01bbfe83d667ca760f6a53511fd5ded4f1n/a162.159.135.232:443
2022-06-28 06:37:01bbfe83d667ca760f6a53511fd5ded4f1n/a54.91.59.199:443
2022-06-26 17:53:21591026b224f53e9667b211bd3a6f9616n/a3.220.57.224:443
2022-06-26 17:53:21591026b224f53e9667b211bd3a6f9616n/a162.159.138.232:443
2022-06-26 17:53:21591026b224f53e9667b211bd3a6f9616n/a172.67.34.170:443
2022-06-26 17:31:0024e8a6b833df8f6c8b6547bef088203fVirustotal results 41 / 70 (58.57%) 104.20.67.143:443
2022-06-26 17:31:0024e8a6b833df8f6c8b6547bef088203fVirustotal results 41 / 70 (58.57%) 162.159.136.232:443
2022-06-26 17:31:0024e8a6b833df8f6c8b6547bef088203fVirustotal results 41 / 70 (58.57%) 3.232.242.170:443
2022-06-26 17:10:3526efc04ff2e7faf5e9f73a8bafef5658Virustotal results 45 / 67 (67.16%) 162.159.137.232:443
2022-06-17 15:05:367071e57757dd806034e048dda6195aean/a192.229.133.221:443
2022-06-17 15:05:367071e57757dd806034e048dda6195aean/a54.73.53.134:443
2022-06-05 03:10:534cd0a96403a171bc425f5aa7c94b46f6n/a162.159.137.232:443
2022-05-29 18:39:308eb6d53da2188eaa5eea154fc8651960n/a104.20.67.143:443
2022-05-29 18:39:308eb6d53da2188eaa5eea154fc8651960n/a162.159.137.232:443
2022-05-29 18:39:308eb6d53da2188eaa5eea154fc8651960n/a52.20.78.240:443
2022-05-25 16:05:47af6f1ca38867341547610f7435ab3119n/a162.159.138.232:443
2022-04-15 21:00:2853955a53cfb1172376496c4cc53f5ac4n/a162.159.128.233:443
2022-03-31 06:30:19c4d3221f08567332323eb18acab0f4f6n/a142.250.141.109:465
2022-03-14 12:30:317cbf234172cc5527a48e3f1fb75e3194Virustotal results 28 / 68 (41.18%) 66.220.9.57:443
2022-03-14 12:30:317cbf234172cc5527a48e3f1fb75e3194Virustotal results 28 / 68 (41.18%) 66.220.9.50:21
2022-03-04 07:51:376416e70062eed7e7db454f34ce17ff7fn/a104.23.99.190:443
2022-03-04 07:51:376416e70062eed7e7db454f34ce17ff7fn/a3.220.57.224:443
2022-03-04 07:51:376416e70062eed7e7db454f34ce17ff7fn/a162.159.133.233:443
2022-02-28 01:41:590dd510047f661bf3a6993eea73ecca6an/a142.251.5.109:587
2022-02-21 11:56:33ad0c824b494fde674ebb0c38ca890b4bn/a104.23.99.190:443
2022-02-21 11:56:33ad0c824b494fde674ebb0c38ca890b4bn/a162.159.135.232:443
2022-02-21 11:56:33ad0c824b494fde674ebb0c38ca890b4bn/a52.20.78.240:443
2022-02-10 02:43:34b59f6cb9b9356cfea9673f67676935a8Virustotal results 10 / 65 (15.38%) 52.20.78.240:443
2022-02-10 02:43:34b59f6cb9b9356cfea9673f67676935a8Virustotal results 10 / 65 (15.38%) 162.159.135.232:443
2022-02-08 22:09:37815cff9ac07bf19bb60e6e2f5c4856e4Virustotal results 33 / 66 (50.00%) 162.159.135.232:443
2022-01-24 22:37:22b32d0ee5f196ef534fdf83943d11c443Virustotal results 5 / 65 (7.69%) 142.251.36.33:443
2022-01-22 21:24:354f0a0b508c43a76adb97f89e8c9611b9Virustotal results 33 / 67 (49.25%) 162.159.138.232:443
2022-01-15 20:31:180fad509ff4c37dd184a1953f4f32b00fVirustotal results 13 / 67 (19.40%) 104.120.119.162:443
2022-01-15 20:31:180fad509ff4c37dd184a1953f4f32b00fVirustotal results 13 / 67 (19.40%) 104.89.4.197:443
2022-01-15 20:31:180fad509ff4c37dd184a1953f4f32b00fVirustotal results 13 / 67 (19.40%) 104.215.148.63:443
2022-01-15 20:31:180fad509ff4c37dd184a1953f4f32b00fVirustotal results 13 / 67 (19.40%) 104.120.119.162:443
2022-01-15 20:31:180fad509ff4c37dd184a1953f4f32b00fVirustotal results 13 / 67 (19.40%) 104.89.4.197:443
2022-01-15 20:31:180fad509ff4c37dd184a1953f4f32b00fVirustotal results 13 / 67 (19.40%) 104.215.148.63:443
2022-01-09 18:04:183b2d4feeb29777cab1b7d0c726e54fe7Virustotal results 27 / 67 (40.30%) 74.125.133.109:587
2022-01-09 17:12:483c79f963e00427f2db5e43d4ea46aad0Virustotal results 35 / 68 (51.47%) 52.97.232.246:587
2022-01-04 18:01:01ac37cf32ea3d1cf814a23fadd0cd736fn/a162.159.135.232:443
2022-01-04 12:26:50a5a87ab1899219ece55d5f24d7075991n/a162.159.135.232:443
2022-01-02 07:14:47b472bdf7a91f9f20bcdb35d77d66f21bn/a94.100.180.160:587
2021-12-31 03:36:43a1f96096607ca4a950693bbaebb2287dn/a162.159.135.232:443
2021-12-31 03:36:43a1f96096607ca4a950693bbaebb2287dn/a162.159.130.234:443
2021-12-31 03:36:43a1f96096607ca4a950693bbaebb2287dn/a159.89.102.253:443
2021-12-27 13:30:22c91cae68e267eb27770f4122bb17f741n/a159.89.102.253:443
2021-12-27 13:30:22c91cae68e267eb27770f4122bb17f741n/a162.159.135.232:443
2021-12-27 13:30:22c91cae68e267eb27770f4122bb17f741n/a162.159.136.234:443
2021-12-25 04:11:54aa7c1462fa7c1e4020c754216e8757b6n/a162.159.137.232:443
2021-12-25 04:11:54aa7c1462fa7c1e4020c754216e8757b6n/a104.23.99.190:443
2021-12-25 04:11:54aa7c1462fa7c1e4020c754216e8757b6n/a54.91.59.199:443
2021-12-22 07:54:15add2aa0b5944dd5777f1f4a5c1487676n/a34.117.59.81:443
2021-12-12 19:42:3247a9bc007b85f675f4fc2903710ef4ffn/a54.91.59.199:443
2021-12-12 19:42:3247a9bc007b85f675f4fc2903710ef4ffn/a162.159.135.232:443
2021-12-12 19:42:3247a9bc007b85f675f4fc2903710ef4ffn/a104.23.99.190:443
2021-12-12 11:31:38c872533fdb1ca80c3e1ca60251276621n/a52.20.78.240:443
2021-12-12 11:31:38c872533fdb1ca80c3e1ca60251276621n/a162.159.138.232:443
2021-11-06 14:49:5468d2899ad55eefed5b4cc047337d4727n/a173.194.76.109:587
2021-10-24 08:40:10a716cc391eae9aedf7b869eed57318ffn/a50.17.226.156:443
2021-10-24 08:40:10a716cc391eae9aedf7b869eed57318ffn/a162.159.128.233:443
2021-10-20 18:26:42aa7848adc94aca47e20ed46f855f17c6n/a52.97.232.210:993
2021-10-08 04:28:293abf510475def80e3204008402567eb5n/a162.159.137.232:443
2021-10-08 04:28:293abf510475def80e3204008402567eb5n/a23.23.147.66:443
2021-09-23 03:52:25bf59bcf689c92cae2770befffa49a9a0n/a54.152.238.77:443
2021-09-11 10:56:42c36d4ff50c734ad03c2cc5a109fe1204n/a64.233.167.109:587
2021-09-06 01:42:5411e4a49c488debe802645c8c096abdd4Virustotal results 36 / 67 (53.73%) 162.159.136.232:443
2021-08-29 00:31:568470cc0ab7a4ce9b542e6a4f2df993c1n/a142.250.102.109:587
2021-08-26 02:12:34b84a1e2776853089f774f3679b53e8d8n/a162.159.138.232:443
2021-08-25 02:46:26cbda0c4132e53803fc304d60128f3649n/a104.23.99.190:443
2021-08-25 02:46:26cbda0c4132e53803fc304d60128f3649n/a162.159.134.233:443
2021-08-25 02:46:26cbda0c4132e53803fc304d60128f3649n/a162.159.135.232:443
2021-08-23 20:30:203a29907ed1f09200b0779105aa0b5d3eVirustotal results 11 / 67 (16.42%) 162.159.136.234:443
2021-08-23 20:30:203a29907ed1f09200b0779105aa0b5d3eVirustotal results 11 / 67 (16.42%) 162.159.135.232:443
2021-08-19 22:10:523889dbd3297a3311f9f23535a9e31f64Virustotal results 35 / 68 (51.47%) 94.100.180.160:25
2021-08-19 20:58:261a9d7d7e62ba3497ad3a19d30ab5c8fdVirustotal results 30 / 69 (43.48%) 162.159.138.232:443
2021-08-19 20:58:261a9d7d7e62ba3497ad3a19d30ab5c8fdVirustotal results 30 / 69 (43.48%) 104.21.29.16:443
2021-08-19 07:06:27326ff86ca00a194f244b5c9950b31301Virustotal results 27 / 68 (39.71%) 142.250.153.109:587
2021-08-14 18:18:110f0bdac4d78aa4642d5e8d9f77d17d23Virustotal results 15 / 68 (22.06%) 142.250.102.109:465
2021-08-13 21:40:18686b967546ab8169c64842d340b7d89cn/a204.68.111.105:443
2021-08-13 21:40:18686b967546ab8169c64842d340b7d89cn/a45.67.159.245:443
2021-08-13 21:40:18686b967546ab8169c64842d340b7d89cn/a5.154.224.27:443
2021-08-13 21:40:18686b967546ab8169c64842d340b7d89cn/a89.111.52.100:443
2021-08-13 21:40:18686b967546ab8169c64842d340b7d89cn/a78.35.24.46:443
2021-08-13 02:06:22f908d42b67bc1416a6435493720ec987n/a50.16.239.65:443
2021-08-13 02:06:22f908d42b67bc1416a6435493720ec987n/a162.159.128.233:443
2021-08-13 02:06:22f908d42b67bc1416a6435493720ec987n/a104.23.99.190:443
2021-08-07 03:15:42a34d8322abcfbde1bfa9c227daf9a56eVirustotal results 34 / 65 (52.31%) 104.23.98.190:443
2021-08-07 03:15:42a34d8322abcfbde1bfa9c227daf9a56eVirustotal results 34 / 65 (52.31%) 54.235.88.121:443
2021-08-07 03:15:42a34d8322abcfbde1bfa9c227daf9a56eVirustotal results 34 / 65 (52.31%) 162.159.128.233:443
2021-08-07 03:15:42a34d8322abcfbde1bfa9c227daf9a56eVirustotal results 34 / 65 (52.31%) 104.23.98.190:443
2021-08-07 03:15:42a34d8322abcfbde1bfa9c227daf9a56eVirustotal results 34 / 65 (52.31%) 54.235.88.121:443
2021-08-07 03:15:42a34d8322abcfbde1bfa9c227daf9a56eVirustotal results 34 / 65 (52.31%) 162.159.128.233:443
2021-08-04 21:41:430acca931ddf7879d5047b492716848b8Virustotal results 23 / 69 (33.33%) 162.159.138.232:443
2021-08-04 21:41:430acca931ddf7879d5047b492716848b8Virustotal results 23 / 69 (33.33%) 162.159.138.232:443
2021-08-01 12:58:21da9571c77e427736f06a174f1c4073b7Virustotal results 36 / 67 (53.73%) 162.159.128.233:443
2021-08-01 12:58:21da9571c77e427736f06a174f1c4073b7Virustotal results 36 / 67 (53.73%) 162.159.128.233:443

# of entries: 100 (max: 100)