JA3 Fingerprints

You can find further information about the JA3 fingerprint 96eba628dcb2b47607192ba74a3b55ba, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:96eba628dcb2b47607192ba74a3b55ba
First seen:2017-07-19 18:53:48 UTC
Last seen:2021-07-31 01:48:32 UTC
Status:Blacklisted
Malware samples:1'536
Destination IPs:395
Malware:Tofsee -
Listing date:2018-11-14 11:49:02

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2021-10-18 21:18:19d5ba8ec389724fb5bcfdee83394b9f37n/a88.99.1.130:587
2021-10-11 05:33:41a9bf0bbb7cb7e1171fc6d3efd5d588c4n/a173.199.132.62:587
2021-10-10 07:02:561f095180682f14091ad5055be758247cn/a195.121.65.26:587
2021-10-09 23:22:285bec1166ffd2277f2dff94e4bcac5003n/a176.100.7.136:465
2021-10-09 22:59:15ae477d3aee6d377c8d2eccfd5d69de13n/a95.142.156.6:587
2021-10-09 22:59:15ae477d3aee6d377c8d2eccfd5d69de13n/a87.106.24.23:587
2021-10-09 22:59:15ae477d3aee6d377c8d2eccfd5d69de13n/a95.142.156.8:587
2021-10-09 22:59:15ae477d3aee6d377c8d2eccfd5d69de13n/a87.106.24.23:465
2021-10-09 22:59:14ae477d3aee6d377c8d2eccfd5d69de13n/a95.142.156.28:587
2021-10-09 22:59:14ae477d3aee6d377c8d2eccfd5d69de13n/a95.142.156.28:465
2021-10-09 22:59:14ae477d3aee6d377c8d2eccfd5d69de13n/a95.142.156.8:465
2021-10-09 17:17:16aefe060582c7af2f6e783d1ba89ba024n/a212.227.17.168:465
2021-10-09 15:55:45acde17af83040cafaaf7183820a3fd89n/a80.191.56.151:465
2021-10-09 15:55:45acde17af83040cafaaf7183820a3fd89n/a195.130.217.210:587
2021-10-09 14:17:586c5e5bcf03fbe994d3b9941f3dbd1b85n/a95.142.156.28:465
2021-10-09 14:17:586c5e5bcf03fbe994d3b9941f3dbd1b85n/a95.142.156.28:587
2021-10-09 14:17:576c5e5bcf03fbe994d3b9941f3dbd1b85n/a95.142.156.18:465
2021-10-09 14:17:576c5e5bcf03fbe994d3b9941f3dbd1b85n/a95.142.156.6:587
2021-10-09 14:17:576c5e5bcf03fbe994d3b9941f3dbd1b85n/a95.142.156.18:587
2021-10-09 14:17:576c5e5bcf03fbe994d3b9941f3dbd1b85n/a195.130.217.210:587
2021-10-09 07:09:284ade9bccd0b2b9447ff9dbb9c3880830n/a74.50.62.117:465
2021-10-09 04:58:19ebf3755ddefaa5cb79df628c85ff267bn/a208.89.133.9:587
2021-10-08 22:37:328bbe061254c2f7df8628d014594bae07n/a104.244.120.82:587
2021-10-08 22:37:318bbe061254c2f7df8628d014594bae07n/a104.244.120.82:465
2021-10-08 21:44:186eb144d61460b8e5e9da3226070a68ebn/a160.153.78.131:587
2021-10-08 21:44:186eb144d61460b8e5e9da3226070a68ebn/a160.153.78.131:465
2021-10-08 19:20:1319d688ee7f1238a41b27d6fa143ecb86Virustotal results 48 / 69 (69.57%) 66.226.70.66:587
2021-10-08 19:20:1319d688ee7f1238a41b27d6fa143ecb86Virustotal results 48 / 69 (69.57%) 66.226.70.66:465
2021-10-08 04:14:01049458cf84d53142577e028c37d4dfe3n/a169.61.73.165:443
2021-10-06 22:14:59ce11aae9a09a841f08dde930704813b7n/a209.102.225.2:587
2021-10-06 21:52:03399ac0dad612e0d35a02e7efa1b31850n/a168.0.132.203:587
2021-10-05 05:44:2097ffba9364e8d91ae0e77bd9d21ef55dn/a62.149.128.203:587
2021-10-05 05:14:31609b6bb39d45ce755da8e34620206ae9n/a85.13.157.215:465
2021-10-04 20:00:10d15a4c058d6d3d8f4cb3b3d23b8c4e35Virustotal results 24 / 69 (34.78%) 223.29.248.111:465
2021-10-04 07:09:273b48192c10cd25c7a7d5b78ec0f5d9d4n/a133.167.73.73:587
2021-10-04 07:09:273b48192c10cd25c7a7d5b78ec0f5d9d4n/a133.167.73.73:465
2021-10-04 06:44:221f8f27ac53543bb015ef6c44b4da5f53n/a205.147.111.56:465
2021-10-04 06:44:211f8f27ac53543bb015ef6c44b4da5f53n/a103.20.213.48:465
2021-10-04 02:59:17a23229a7d4a5cc14d40ede304fe4f584n/a173.236.29.82:465
2021-10-04 02:59:17a23229a7d4a5cc14d40ede304fe4f584n/a173.236.29.82:587
2021-10-04 00:23:40a16cbc6f6af29082d4dd015e4e77aab6n/a66.96.160.141:465
2021-10-04 00:23:40a16cbc6f6af29082d4dd015e4e77aab6n/a66.96.160.141:587
2021-10-03 17:41:460ee63705af64383c75ea7cb510e179b0n/a124.156.190.79:465
2021-10-03 17:41:460ee63705af64383c75ea7cb510e179b0n/a124.156.190.79:587
2021-10-03 03:35:41922e58fed94bf67d74276fa38aede439n/a52.97.186.114:587
2021-10-03 03:35:41922e58fed94bf67d74276fa38aede439n/a52.98.168.178:587
2021-10-02 23:34:21a08ab368170e0317c9f76e6dd6922d17n/a107.180.2.152:587
2021-10-02 23:34:20a08ab368170e0317c9f76e6dd6922d17n/a15.222.16.210:587
2021-10-02 23:34:20a08ab368170e0317c9f76e6dd6922d17n/a69.49.101.233:465
2021-10-02 23:34:20a08ab368170e0317c9f76e6dd6922d17n/a69.49.101.233:587
2021-10-02 23:02:509adfa789ad24d2d1395f14a3ba96e968n/a205.178.146.249:587
2021-10-01 18:09:0353b2bbd4507c850e2ca5e93856dad69cn/a193.70.18.144:587
2021-10-01 18:09:0253b2bbd4507c850e2ca5e93856dad69cn/a193.70.18.144:465
2021-10-01 06:54:12a4274160d57e2287223da19eeec5a7e8n/a172.96.191.65:587
2021-09-23 22:48:211ef746966e85bae95974990de264080dn/a153.92.8.199:587
2021-09-20 13:15:31bab4fea354ce6944ad3db50c7b0de304n/a64.98.36.221:587
2021-09-17 13:27:54a8de8e9c71c361cd0a38fac8c5305496n/a81.0.212.10:465
2021-09-02 17:03:50ef253b20c2beea13fcf6bf9c590f78bfn/a116.211.15.215:443
2021-08-29 07:25:12a06ba495c2485e21af395263e3b9841cVirustotal results 0 / 63 (0.00%) 169.61.73.165:443
2021-08-25 20:08:44491c9f75f988d018b16c6c32d907ea8dn/a64.34.156.154:587
2021-08-25 20:08:44491c9f75f988d018b16c6c32d907ea8dn/a64.34.156.154:465
2021-08-12 04:55:391e90cc98e8afb798455ebb2dda8f98fdVirustotal results 1 / 68 (1.47%) 163.171.138.158:443
2021-07-31 01:48:32f4940e9d843336a142b0deae0ec2174dVirustotal results 43 / 69 (62.32%) 45.32.120.24:777
2021-07-31 01:48:32f4940e9d843336a142b0deae0ec2174dVirustotal results 43 / 69 (62.32%) 45.32.120.24:777
2021-07-20 20:25:076e6ed85abc5bee4d20bd675ae564a07aVirustotal results 1 / 67 (1.49%) 116.211.15.215:443
2021-07-20 20:25:076e6ed85abc5bee4d20bd675ae564a07aVirustotal results 1 / 67 (1.49%) 116.211.15.215:443
2021-07-01 20:28:0167eb2cf5c9e34b6dcafae2c8c3582b6en/a216.240.135.98:587
2021-07-01 20:28:0167eb2cf5c9e34b6dcafae2c8c3582b6en/a216.240.135.98:465
2021-07-01 20:28:0167eb2cf5c9e34b6dcafae2c8c3582b6en/a216.240.135.98:587
2021-07-01 20:28:0167eb2cf5c9e34b6dcafae2c8c3582b6en/a216.240.135.98:465
2021-06-10 18:38:53377e602861784a23e81cd4581e3ceaa5Virustotal results 33 / 69 (47.83%) 45.32.120.24:777
2021-06-10 18:38:53377e602861784a23e81cd4581e3ceaa5Virustotal results 33 / 69 (47.83%) 45.32.120.24:777
2021-05-25 19:22:268d43acc0746fe7ea6ab84b5c4b646d2aVirustotal results 2 / 71 (2.82%) 116.211.15.215:443
2021-05-25 19:22:268d43acc0746fe7ea6ab84b5c4b646d2aVirustotal results 2 / 71 (2.82%) 116.211.15.215:443
2021-05-25 18:54:47f922fbe29201b4cc31951fb0b01b33daVirustotal results 0 / 48 (0.00%) 116.211.15.215:443
2021-05-25 18:54:47f922fbe29201b4cc31951fb0b01b33daVirustotal results 0 / 48 (0.00%) 116.211.15.215:443
2021-05-03 10:55:4357e54353a0aae647fd6a7d879d81e516Virustotal results 33 / 47 (70.21%) 193.246.9.44:443
2021-05-03 10:55:4357e54353a0aae647fd6a7d879d81e516Virustotal results 33 / 47 (70.21%) 193.246.9.44:443
2021-04-16 04:42:38b30d03f7d800765095f64f2940f1484bVirustotal results 13 / 70 (18.57%) 166.78.85.190:443
2021-04-16 04:42:38b30d03f7d800765095f64f2940f1484bVirustotal results 13 / 70 (18.57%) 52.0.99.229:443
2021-04-16 04:42:38b30d03f7d800765095f64f2940f1484bVirustotal results 13 / 70 (18.57%) 166.78.85.190:443
2021-04-16 04:42:38b30d03f7d800765095f64f2940f1484bVirustotal results 13 / 70 (18.57%) 52.0.99.229:443
2021-04-08 07:02:2628c6062200c174e2a8048cae0ec899edn/a62.149.128.201:587
2021-04-08 07:02:2628c6062200c174e2a8048cae0ec899edn/a62.149.128.201:587
2021-04-08 07:02:2528c6062200c174e2a8048cae0ec899edn/a62.149.128.202:587
2021-04-08 07:02:2528c6062200c174e2a8048cae0ec899edn/a62.149.128.202:587
2021-04-08 07:02:0382821e54f009d27ead25571b77f5476aVirustotal results 39 / 69 (56.52%) 173.201.193.101:587
2021-04-08 07:02:0382821e54f009d27ead25571b77f5476aVirustotal results 39 / 69 (56.52%) 198.38.88.80:587
2021-04-08 07:02:0382821e54f009d27ead25571b77f5476aVirustotal results 39 / 69 (56.52%) 173.201.193.101:587
2021-04-08 07:02:0382821e54f009d27ead25571b77f5476aVirustotal results 39 / 69 (56.52%) 198.38.88.80:587
2021-04-08 06:35:23c7012f3e4e95ff94d66b60aaf556c98an/a81.88.178.55:587
2021-04-08 06:35:23c7012f3e4e95ff94d66b60aaf556c98an/a81.88.178.55:587
2021-04-08 03:12:23d45f09fbae6b86977830fb7fcfaddc25Virustotal results 44 / 69 (63.77%) 52.97.179.194:587
2021-04-08 03:12:23d45f09fbae6b86977830fb7fcfaddc25Virustotal results 44 / 69 (63.77%) 52.97.179.194:587
2021-04-08 01:21:36d019b3344a1d000f31de5033839c3dd4n/a213.190.6.246:587
2021-04-08 01:21:36d019b3344a1d000f31de5033839c3dd4n/a213.190.6.246:587
2021-04-08 00:52:32d0ea04f585a6649a0db7a4ee9fb832f3Virustotal results 36 / 65 (55.38%) 150.162.2.72:465
2021-04-08 00:52:32d0ea04f585a6649a0db7a4ee9fb832f3Virustotal results 36 / 65 (55.38%) 150.162.2.72:465
2021-04-07 23:53:32b5b9d140b5eadd9c311a8d16b348bbdeVirustotal results 44 / 67 (65.67%) 186.215.90.50:587
2021-04-07 23:53:32b5b9d140b5eadd9c311a8d16b348bbdeVirustotal results 44 / 67 (65.67%) 186.215.90.50:587

# of entries: 100 (max: 100)