JA3 Fingerprints

You can find further information about the JA3 fingerprint 96eba628dcb2b47607192ba74a3b55ba, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:96eba628dcb2b47607192ba74a3b55ba
First seen:2017-07-19 18:53:48 UTC
Last seen:2021-07-31 01:48:32 UTC
Status:Blacklisted
Malware samples:1'553
Destination IPs:411
Malware:Tofsee -
Listing date:2018-11-14 11:49:02

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2022-05-28 12:41:1579a211a58e9228afd4a46f7e02335ff6n/a169.61.73.165:443
2022-05-08 20:04:44929d8284d08fc4479935107485e146a5n/a70.35.198.84:443
2021-11-25 19:47:5219d5fb573bfc7428ab4c1a6f7d80ddf6Virustotal results 4 / 67 (5.97%) 157.185.160.88:443
2021-11-23 18:11:56f680fe0d45177edced48df69dfe6091cn/a78.46.98.23:465
2021-11-23 18:11:56f680fe0d45177edced48df69dfe6091cn/a78.46.98.23:587
2021-11-22 22:25:32672e852bcf79e3eb3c44ebff092d34f8n/a191.252.112.194:587
2021-11-22 22:25:32672e852bcf79e3eb3c44ebff092d34f8n/a191.252.112.194:465
2021-11-22 21:58:095bf8cbde945501a7057445d26c1c06b0n/a66.96.146.89:465
2021-11-22 21:58:095bf8cbde945501a7057445d26c1c06b0n/a66.96.146.89:587
2021-11-22 19:52:392bb01bf19d31cf95bd1308ecec167d5dVirustotal results 50 / 68 (73.53%) 94.199.183.24:465
2021-11-22 15:42:56e1971ba5ca1082d58de64958e0bf30d5n/a88.198.36.249:465
2021-11-19 00:28:00771797bc958b2b41549b1cb9a1fa2109n/a92.43.200.131:465
2021-11-18 23:57:0069f78fa1405fe5ef48cc238efe961072n/a64.98.36.162:587
2021-11-18 22:23:080d9f1b23f7206c3063456bf653148f8aVirustotal results 49 / 67 (73.13%) 62.201.172.21:587
2021-11-18 22:23:070d9f1b23f7206c3063456bf653148f8aVirustotal results 49 / 67 (73.13%) 62.149.128.201:587
2021-11-18 22:23:070d9f1b23f7206c3063456bf653148f8aVirustotal results 49 / 67 (73.13%) 103.229.73.118:465
2021-11-18 22:23:070d9f1b23f7206c3063456bf653148f8aVirustotal results 49 / 67 (73.13%) 203.190.36.4:587
2021-11-18 22:23:070d9f1b23f7206c3063456bf653148f8aVirustotal results 49 / 67 (73.13%) 103.229.73.118:587
2021-11-18 20:57:5208616e2f5b23af1bbb37cd5d9dbb627bVirustotal results 54 / 68 (79.41%) 62.149.128.202:587
2021-11-05 13:59:36abac49de11a2913556ff9909dc01cb49n/a85.128.242.31:465
2021-11-05 13:59:36abac49de11a2913556ff9909dc01cb49n/a64.251.188.88:465
2021-11-05 13:59:36abac49de11a2913556ff9909dc01cb49n/a193.70.18.144:587
2021-11-04 23:51:206baf8dbacb08865e8bf3b645c9122041n/a74.81.68.235:465
2021-11-04 23:51:206baf8dbacb08865e8bf3b645c9122041n/a74.81.68.235:587
2021-10-27 21:30:15abe2cba3c54694fece4304dce27c934an/a85.93.19.85:465
2021-10-27 21:30:15abe2cba3c54694fece4304dce27c934an/a85.93.19.85:587
2021-10-23 06:37:24083b1df804061b0368d21b6987903de3n/a208.84.244.140:587
2021-10-19 15:57:490cdadcc95738dd2694cbcac01ce3f3c8Virustotal results 0 / 68 (0.00%) 166.78.85.190:443
2021-10-19 15:57:490cdadcc95738dd2694cbcac01ce3f3c8Virustotal results 0 / 68 (0.00%) 54.205.238.163:443
2021-10-18 21:18:19d5ba8ec389724fb5bcfdee83394b9f37n/a88.99.1.130:587
2021-10-11 05:33:41a9bf0bbb7cb7e1171fc6d3efd5d588c4n/a173.199.132.62:587
2021-10-10 07:02:561f095180682f14091ad5055be758247cn/a195.121.65.26:587
2021-10-09 23:22:285bec1166ffd2277f2dff94e4bcac5003n/a176.100.7.136:465
2021-10-09 22:59:15ae477d3aee6d377c8d2eccfd5d69de13n/a95.142.156.6:587
2021-10-09 22:59:15ae477d3aee6d377c8d2eccfd5d69de13n/a87.106.24.23:587
2021-10-09 22:59:15ae477d3aee6d377c8d2eccfd5d69de13n/a95.142.156.8:587
2021-10-09 22:59:15ae477d3aee6d377c8d2eccfd5d69de13n/a87.106.24.23:465
2021-10-09 22:59:14ae477d3aee6d377c8d2eccfd5d69de13n/a95.142.156.28:587
2021-10-09 22:59:14ae477d3aee6d377c8d2eccfd5d69de13n/a95.142.156.28:465
2021-10-09 22:59:14ae477d3aee6d377c8d2eccfd5d69de13n/a95.142.156.8:465
2021-10-09 17:17:16aefe060582c7af2f6e783d1ba89ba024n/a212.227.17.168:465
2021-10-09 15:55:45acde17af83040cafaaf7183820a3fd89n/a80.191.56.151:465
2021-10-09 15:55:45acde17af83040cafaaf7183820a3fd89n/a195.130.217.210:587
2021-10-09 14:17:586c5e5bcf03fbe994d3b9941f3dbd1b85n/a95.142.156.28:465
2021-10-09 14:17:586c5e5bcf03fbe994d3b9941f3dbd1b85n/a95.142.156.28:587
2021-10-09 14:17:576c5e5bcf03fbe994d3b9941f3dbd1b85n/a95.142.156.18:465
2021-10-09 14:17:576c5e5bcf03fbe994d3b9941f3dbd1b85n/a95.142.156.6:587
2021-10-09 14:17:576c5e5bcf03fbe994d3b9941f3dbd1b85n/a95.142.156.18:587
2021-10-09 14:17:576c5e5bcf03fbe994d3b9941f3dbd1b85n/a195.130.217.210:587
2021-10-09 07:09:284ade9bccd0b2b9447ff9dbb9c3880830n/a74.50.62.117:465
2021-10-09 04:58:19ebf3755ddefaa5cb79df628c85ff267bn/a208.89.133.9:587
2021-10-08 22:37:328bbe061254c2f7df8628d014594bae07n/a104.244.120.82:587
2021-10-08 22:37:318bbe061254c2f7df8628d014594bae07n/a104.244.120.82:465
2021-10-08 21:44:186eb144d61460b8e5e9da3226070a68ebn/a160.153.78.131:587
2021-10-08 21:44:186eb144d61460b8e5e9da3226070a68ebn/a160.153.78.131:465
2021-10-08 19:20:1319d688ee7f1238a41b27d6fa143ecb86Virustotal results 48 / 69 (69.57%) 66.226.70.66:587
2021-10-08 19:20:1319d688ee7f1238a41b27d6fa143ecb86Virustotal results 48 / 69 (69.57%) 66.226.70.66:465
2021-10-08 04:14:01049458cf84d53142577e028c37d4dfe3n/a169.61.73.165:443
2021-10-06 22:14:59ce11aae9a09a841f08dde930704813b7n/a209.102.225.2:587
2021-10-06 21:52:03399ac0dad612e0d35a02e7efa1b31850n/a168.0.132.203:587
2021-10-05 05:44:2097ffba9364e8d91ae0e77bd9d21ef55dn/a62.149.128.203:587
2021-10-05 05:14:31609b6bb39d45ce755da8e34620206ae9n/a85.13.157.215:465
2021-10-04 20:00:10d15a4c058d6d3d8f4cb3b3d23b8c4e35Virustotal results 24 / 69 (34.78%) 223.29.248.111:465
2021-10-04 07:09:273b48192c10cd25c7a7d5b78ec0f5d9d4n/a133.167.73.73:587
2021-10-04 07:09:273b48192c10cd25c7a7d5b78ec0f5d9d4n/a133.167.73.73:465
2021-10-04 06:44:221f8f27ac53543bb015ef6c44b4da5f53n/a205.147.111.56:465
2021-10-04 06:44:211f8f27ac53543bb015ef6c44b4da5f53n/a103.20.213.48:465
2021-10-04 02:59:17a23229a7d4a5cc14d40ede304fe4f584n/a173.236.29.82:465
2021-10-04 02:59:17a23229a7d4a5cc14d40ede304fe4f584n/a173.236.29.82:587
2021-10-04 00:23:40a16cbc6f6af29082d4dd015e4e77aab6n/a66.96.160.141:465
2021-10-04 00:23:40a16cbc6f6af29082d4dd015e4e77aab6n/a66.96.160.141:587
2021-10-03 17:41:460ee63705af64383c75ea7cb510e179b0n/a124.156.190.79:465
2021-10-03 17:41:460ee63705af64383c75ea7cb510e179b0n/a124.156.190.79:587
2021-10-03 03:35:41922e58fed94bf67d74276fa38aede439n/a52.97.186.114:587
2021-10-03 03:35:41922e58fed94bf67d74276fa38aede439n/a52.98.168.178:587
2021-10-02 23:34:21a08ab368170e0317c9f76e6dd6922d17n/a107.180.2.152:587
2021-10-02 23:34:20a08ab368170e0317c9f76e6dd6922d17n/a15.222.16.210:587
2021-10-02 23:34:20a08ab368170e0317c9f76e6dd6922d17n/a69.49.101.233:465
2021-10-02 23:34:20a08ab368170e0317c9f76e6dd6922d17n/a69.49.101.233:587
2021-10-02 23:02:509adfa789ad24d2d1395f14a3ba96e968n/a205.178.146.249:587
2021-10-01 18:09:0353b2bbd4507c850e2ca5e93856dad69cn/a193.70.18.144:587
2021-10-01 18:09:0253b2bbd4507c850e2ca5e93856dad69cn/a193.70.18.144:465
2021-10-01 06:54:12a4274160d57e2287223da19eeec5a7e8n/a172.96.191.65:587
2021-09-23 22:48:211ef746966e85bae95974990de264080dn/a153.92.8.199:587
2021-09-20 13:15:31bab4fea354ce6944ad3db50c7b0de304n/a64.98.36.221:587
2021-09-17 13:27:54a8de8e9c71c361cd0a38fac8c5305496n/a81.0.212.10:465
2021-09-02 17:03:50ef253b20c2beea13fcf6bf9c590f78bfn/a116.211.15.215:443
2021-08-29 07:25:12a06ba495c2485e21af395263e3b9841cVirustotal results 0 / 63 (0.00%) 169.61.73.165:443
2021-08-25 20:08:44491c9f75f988d018b16c6c32d907ea8dn/a64.34.156.154:587
2021-08-25 20:08:44491c9f75f988d018b16c6c32d907ea8dn/a64.34.156.154:465
2021-08-12 04:55:391e90cc98e8afb798455ebb2dda8f98fdVirustotal results 1 / 68 (1.47%) 163.171.138.158:443
2021-07-31 01:48:32f4940e9d843336a142b0deae0ec2174dVirustotal results 43 / 69 (62.32%) 45.32.120.24:777
2021-07-31 01:48:32f4940e9d843336a142b0deae0ec2174dVirustotal results 43 / 69 (62.32%) 45.32.120.24:777
2021-07-20 20:25:076e6ed85abc5bee4d20bd675ae564a07aVirustotal results 1 / 67 (1.49%) 116.211.15.215:443
2021-07-20 20:25:076e6ed85abc5bee4d20bd675ae564a07aVirustotal results 1 / 67 (1.49%) 116.211.15.215:443
2021-07-01 20:28:0167eb2cf5c9e34b6dcafae2c8c3582b6en/a216.240.135.98:587
2021-07-01 20:28:0167eb2cf5c9e34b6dcafae2c8c3582b6en/a216.240.135.98:465
2021-07-01 20:28:0167eb2cf5c9e34b6dcafae2c8c3582b6en/a216.240.135.98:587
2021-07-01 20:28:0167eb2cf5c9e34b6dcafae2c8c3582b6en/a216.240.135.98:465
2021-06-10 18:38:53377e602861784a23e81cd4581e3ceaa5Virustotal results 33 / 69 (47.83%) 45.32.120.24:777

# of entries: 100 (max: 100)