JA3 Fingerprints

You can find further information about the JA3 fingerprint 96eba628dcb2b47607192ba74a3b55ba, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:96eba628dcb2b47607192ba74a3b55ba
First seen:2017-07-19 18:53:48 UTC
Last seen:2021-01-04 12:45:08 UTC
Status:Blacklisted
Malware samples:1'389
Destination IPs:210
Malware:Tofsee -
Listing date:2018-11-14 11:49:02

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2021-01-04 12:45:08a95d1d954bdb8b1c32a9a9e3bb9c0f60Virustotal results 36 / 69 (52.17%) 23.211.5.207:443
2021-01-03 10:46:277e556d6350621eb5e2934c1491c2faecVirustotal results 52 / 69 (75.36%) 2.18.234.68:443
2021-01-03 10:42:397b5de857179fbe87066d30452fda6508Virustotal results 53 / 71 (74.65%) 23.211.5.207:443
2020-12-23 09:23:24520fe00778f7f46cab063e09b709672fVirustotal results 53 / 71 (74.65%) 23.211.5.207:443
2020-12-21 12:08:12619372fba55866f7306cf6c2fe432628Virustotal results 47 / 69 (68.12%) 2.21.40.32:443
2020-12-21 11:58:475d125ab4c630f626107e22e43bafbe89n/a2.21.40.32:443
2020-12-21 10:02:4432f6d288d619cc80b469a5bb8502e577Virustotal results 56 / 71 (78.87%) 23.211.5.207:443
2020-12-19 12:02:57f3c4f552b1d34306614bcca5fad5cffen/a23.211.5.207:443
2020-12-19 11:27:47ef25c7d0b378551006a9d50138b36c3eVirustotal results 46 / 71 (64.79%) 2.21.37.119:443
2020-12-19 11:23:25f086e19e01e6df2c28f21fa63d993933Virustotal results 47 / 69 (68.12%) 2.21.40.32:443
2020-12-19 11:12:26ef951d4bd2a0912cee1be686e2c290d4Virustotal results 46 / 68 (67.65%) 2.21.40.32:443
2020-12-18 11:39:43af85b20a941db9aa48f56fb8b87b61bfVirustotal results 56 / 70 (80.00%) 2.21.40.32:443
2020-12-18 11:37:54afc85ea9cd6f6dde28af2c77b9109222Virustotal results 54 / 71 (76.06%) 23.211.5.207:443
2020-12-17 16:42:17b27ade3b2029909203d7de238c54c3b0n/a2.21.40.32:443
2020-11-13 17:37:0561b4f8c99c90c8c2173299aac4b9f306n/a107.161.178.2:465
2020-11-13 17:37:0461b4f8c99c90c8c2173299aac4b9f306n/a107.161.178.2:587
2020-11-13 14:06:45b4c4e0f4ee5f26134644ed48da9f2f82n/a193.70.18.144:465
2020-11-13 14:06:45b4c4e0f4ee5f26134644ed48da9f2f82n/a193.70.18.144:587
2020-11-11 12:33:55a758d67f99944a1ab5e5237d842e7611n/a213.209.1.145:587
2020-11-10 19:05:49a6cbe29d4d7745d7d83895d460ef8396Virustotal results 42 / 71 (59.15%) 212.227.17.190:465
2020-10-22 11:59:14cfcd4edd2a5c3212a649c90e8c28108fVirustotal results 38 / 69 (55.07%) 195.130.217.210:587
2020-10-22 11:59:14cfcd4edd2a5c3212a649c90e8c28108fVirustotal results 38 / 69 (55.07%) 212.77.101.1:587
2020-10-22 11:59:13cfcd4edd2a5c3212a649c90e8c28108fVirustotal results 38 / 69 (55.07%) 62.241.4.2:465
2020-10-22 11:59:13cfcd4edd2a5c3212a649c90e8c28108fVirustotal results 38 / 69 (55.07%) 203.36.137.241:465
2020-10-22 11:58:09cd9dc6f9dc091d4923eacc1756b4894dVirustotal results 52 / 67 (77.61%) 82.215.18.88:465
2020-10-22 11:58:09cd9dc6f9dc091d4923eacc1756b4894dVirustotal results 52 / 67 (77.61%) 207.69.189.208:587
2020-10-22 11:58:09cd9dc6f9dc091d4923eacc1756b4894dVirustotal results 52 / 67 (77.61%) 107.6.16.19:587
2020-10-22 11:58:09cd9dc6f9dc091d4923eacc1756b4894dVirustotal results 52 / 67 (77.61%) 87.229.120.69:465
2020-10-22 11:58:09cd9dc6f9dc091d4923eacc1756b4894dVirustotal results 52 / 67 (77.61%) 208.84.244.140:587
2020-10-22 11:58:08cd9dc6f9dc091d4923eacc1756b4894dVirustotal results 52 / 67 (77.61%) 62.254.26.221:465
2020-10-22 11:58:08cd9dc6f9dc091d4923eacc1756b4894dVirustotal results 52 / 67 (77.61%) 194.105.232.72:587
2020-10-22 11:58:08cd9dc6f9dc091d4923eacc1756b4894dVirustotal results 52 / 67 (77.61%) 107.6.16.19:465
2020-10-22 11:58:08cd9dc6f9dc091d4923eacc1756b4894dVirustotal results 52 / 67 (77.61%) 207.251.194.25:465
2020-10-22 11:58:08cd9dc6f9dc091d4923eacc1756b4894dVirustotal results 52 / 67 (77.61%) 200.147.35.206:587
2020-10-22 11:58:08cd9dc6f9dc091d4923eacc1756b4894dVirustotal results 52 / 67 (77.61%) 34.102.136.180:465
2020-10-22 11:58:08cd9dc6f9dc091d4923eacc1756b4894dVirustotal results 52 / 67 (77.61%) 212.54.42.9:587
2020-10-22 11:58:08cd9dc6f9dc091d4923eacc1756b4894dVirustotal results 52 / 67 (77.61%) 217.74.64.235:465
2020-10-22 11:58:07cd9dc6f9dc091d4923eacc1756b4894dVirustotal results 52 / 67 (77.61%) 59.157.128.15:587
2020-10-22 11:58:07cd9dc6f9dc091d4923eacc1756b4894dVirustotal results 52 / 67 (77.61%) 64.136.52.45:465
2020-10-22 11:58:07cd9dc6f9dc091d4923eacc1756b4894dVirustotal results 52 / 67 (77.61%) 195.3.96.71:587
2020-10-22 11:58:07cd9dc6f9dc091d4923eacc1756b4894dVirustotal results 52 / 67 (77.61%) 91.189.182.70:587
2020-10-22 11:58:07cd9dc6f9dc091d4923eacc1756b4894dVirustotal results 52 / 67 (77.61%) 64.136.52.44:465
2020-10-22 11:44:24c8aeb722eba7793a59dfacfcd088c615Virustotal results 44 / 70 (62.86%) 64.136.52.44:465
2020-10-22 11:44:24c8aeb722eba7793a59dfacfcd088c615Virustotal results 44 / 70 (62.86%) 202.137.235.17:587
2020-10-22 11:44:24c8aeb722eba7793a59dfacfcd088c615Virustotal results 44 / 70 (62.86%) 62.24.139.43:587
2020-10-22 11:44:23c8aeb722eba7793a59dfacfcd088c615Virustotal results 44 / 70 (62.86%) 208.84.244.49:587
2020-10-22 11:44:22c8aeb722eba7793a59dfacfcd088c615Virustotal results 44 / 70 (62.86%) 195.3.96.71:587
2020-10-22 11:44:22c8aeb722eba7793a59dfacfcd088c615Virustotal results 44 / 70 (62.86%) 195.4.92.215:587
2020-10-19 15:23:40bffff24f8fc9e659be164759f9155e84n/a202.137.237.24:587
2020-10-19 15:23:40bffff24f8fc9e659be164759f9155e84n/a202.137.237.24:465
2020-10-15 19:50:306c8dfa80a8c8d03a3effcf406278f454n/a64.98.36.213:465
2020-10-15 19:50:296c8dfa80a8c8d03a3effcf406278f454n/a64.98.36.213:587
2020-10-15 19:36:28646afd46ece4fc841fef363a33d7e604n/a69.90.160.140:587
2020-10-15 19:10:5343d77e17c03611be32fa01324ce88e01n/a104.18.100.40:443
2020-10-15 18:43:311e82620a3663a7d00dea0a7155d5fe9an/a35.209.169.142:587
2020-10-15 18:43:311e82620a3663a7d00dea0a7155d5fe9an/a104.18.100.40:443
2020-10-15 18:43:311e82620a3663a7d00dea0a7155d5fe9an/a35.209.169.142:465
2020-10-14 21:38:066e690503e4350197c180081b22e9705bVirustotal results 49 / 70 (70.00%) 143.95.252.192:587
2020-10-14 20:15:053af33f8eab0b4678b5270c2a151d7af5Virustotal results 54 / 71 (76.06%) 65.254.248.128:587
2020-10-08 10:09:18b66534551723e606ec1b5ea2bb951a45Virustotal results 42 / 70 (60.00%) 64.29.145.104:587
2020-10-07 14:12:11a9df76048a5789c5489bf5059fbd0649Virustotal results 56 / 70 (80.00%) 208.84.244.140:587
2020-10-07 14:12:11a9df76048a5789c5489bf5059fbd0649Virustotal results 56 / 70 (80.00%) 195.3.96.71:587
2020-10-03 02:48:49b2f392046684883429b752f6f975d978Virustotal results 40 / 71 (56.34%) 191.252.112.194:465
2020-10-03 02:48:49b2f392046684883429b752f6f975d978Virustotal results 40 / 71 (56.34%) 191.252.112.194:587
2020-09-28 05:46:349f426143bfc4922c4ec66aa7d39dd821n/a104.18.101.40:443
2020-08-26 17:25:011d32942e609d33a2601813a742cdd70aVirustotal results 2 / 69 (2.90%) 14.152.76.124:443
2020-08-26 17:25:011d32942e609d33a2601813a742cdd70aVirustotal results 2 / 69 (2.90%) 116.211.20.149:443
2020-08-11 09:50:331b571468a0598b904163c0e0a36ab28fn/a104.18.100.40:443
2020-07-12 13:22:14aa05fcc00da94cafd415a8325b8bbe7eVirustotal results 49 / 73 (67.12%) 104.18.100.40:443
2020-06-26 14:02:189b63386086d02b5603c6b7256a6354b7Virustotal results 45 / 74 (60.81%) 104.18.100.40:443
2020-06-26 13:45:549ae23d5dc699b191a8474fee396f8c81Virustotal results 45 / 73 (61.64%) 104.18.101.40:443
2020-05-22 00:42:19104c1c9ec207cc9769b7a2e808a403afVirustotal results 19 / 73 (26.03%) 104.18.101.40:443
2020-05-03 10:26:32b181f81cd098e62dc89ab272eca62189Virustotal results 25 / 72 (34.72%) 2.21.37.119:443
2020-04-16 05:21:30bbf841eb7a5a1be33296989686e29e94Virustotal results 49 / 73 (67.12%) 62.254.26.221:465
2020-04-16 05:21:30bbf841eb7a5a1be33296989686e29e94Virustotal results 49 / 73 (67.12%) 193.239.68.85:465
2020-04-16 05:21:29bbf841eb7a5a1be33296989686e29e94Virustotal results 49 / 73 (67.12%) 213.197.24.128:587
2020-04-16 05:21:29bbf841eb7a5a1be33296989686e29e94Virustotal results 49 / 73 (67.12%) 167.206.5.250:587
2020-04-15 23:29:22d621a78cf6343c38fa7356b7a2846dddVirustotal results 64 / 73 (87.67%) 109.123.210.15:465
2020-04-15 23:29:21d621a78cf6343c38fa7356b7a2846dddVirustotal results 64 / 73 (87.67%) 202.137.235.17:587
2020-04-08 19:07:4364973f901d651b517042992215d0f9efVirustotal results 42 / 73 (57.53%) 23.211.5.207:443
2020-03-29 22:23:33f7d66bb0bb618da703f6fd87ef45ba9aVirustotal results 64 / 73 (87.67%) 109.244.2.106:443
2020-03-29 22:23:33f7d66bb0bb618da703f6fd87ef45ba9aVirustotal results 64 / 73 (87.67%) 14.152.76.126:443
2020-03-29 20:01:181022bf5a12187529ee99567cfbe7138bVirustotal results 54 / 72 (75.00%) 195.206.40.175:587
2020-03-29 19:59:493fbdd253b9cf04880b507036cf4f7006n/a167.206.5.250:587
2020-03-29 19:43:11642de6bd90909dbb88d92c52a5e74aa9n/a167.206.5.250:587
2020-03-29 19:27:4383c6fa49c906279907c4d1a8096acd10n/a193.17.41.99:465
2020-03-29 19:26:398bf187ad55d69a0559f450da50d5d85cn/a68.87.20.6:587
2020-03-29 19:14:456983ad9c106dc7b8052c63c52270266fn/a206.152.134.66:587
2020-03-29 18:57:16d9c6d779a9957388ebd9810b36d67d07n/a213.46.255.69:465
2020-03-29 18:49:16e0622880c71489be90ad58ea1ef58d0fn/a91.220.42.220:587
2020-03-29 18:37:34a2aa593758aeed77aafc88840d25af0cn/a77.88.21.158:465
2020-03-29 18:37:33a2aa593758aeed77aafc88840d25af0cn/a23.211.5.207:443
2020-03-28 08:13:187d0d77195b18f47e203629bbd0044018n/a52.97.133.162:587
2020-03-28 00:44:33060d3c57ad3a89c6e600bb586cc814d0Virustotal results 19 / 65 (29.23%) 52.97.133.226:587
2020-03-27 08:06:4599b6fc26f6a4f013ae61cc3102e3a392n/a52.97.232.194:587
2020-03-26 19:49:31cdf6c5b37844378a0f1dfd0fcb89cda1Virustotal results 33 / 72 (45.83%) 52.97.189.98:587
2020-03-26 19:49:28cdf6c5b37844378a0f1dfd0fcb89cda1Virustotal results 33 / 72 (45.83%) 40.101.80.18:587
2020-03-26 19:49:25cdf6c5b37844378a0f1dfd0fcb89cda1Virustotal results 33 / 72 (45.83%) 52.97.232.210:587
2020-03-26 14:05:437563c96137f187d0dd3277f2b2e9fd77n/a52.97.176.34:587
2020-03-26 13:57:59d86b5aad90c5c2928fdff9718cb8ef24Virustotal results 21 / 71 (29.58%) 52.97.165.146:587

# of entries: 100 (max: 100)