JA3 Fingerprints

You can find further information about the JA3 fingerprint c0220cd64849a629397a9cb68f78a0ea, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:c0220cd64849a629397a9cb68f78a0ea
First seen:2019-03-24 00:12:32 UTC
Last seen:2021-07-31 00:26:06 UTC
Status:Blacklisted
Malware samples:2'779
Destination IPs:816
Malware:Tofsee -
Listing date:2020-01-09 14:28:36

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2023-02-07 00:28:34ae9dc34b6a8ea00485a79cc48fc59662Virustotal results 22 / 70 (31.43%) 23.3.85.133:443
2023-02-06 12:48:0008a4403e079a4f7fa39797970fa47fb7n/a13.224.103.189:443
2023-02-06 10:45:10a9d4046746dfbe7a71abbb18c7812f11n/a18.66.145.149:443
2023-01-24 05:00:21c6cc33caa155860c0cd62346d34d3fafn/a13.224.93.221:443
2023-01-21 08:02:206875a39ee42a3efcdb2dcd5017473e50n/a18.164.175.199:443
2023-01-20 21:23:49b9153dacde167baf96a60e3a2d602d98Virustotal results 50 / 70 (71.43%) 23.211.5.50:443
2023-01-18 19:58:20064e98568d01711372d2faa6482a4cf1Virustotal results 55 / 71 (77.46%) 104.85.5.189:443
2023-01-16 02:54:080ab08fa13cdd181b3ca348b4538fedb6Virustotal results 41 / 71 (57.75%) 13.224.102.17:443
2023-01-15 22:29:200c89a5c6fb07c84c0b57d9b113a47cabVirustotal results 49 / 69 (71.01%) 23.211.5.61:443
2023-01-11 01:33:03a5c04a506c39e897428021470fef3a95Virustotal results 50 / 69 (72.46%) 13.224.102.17:443
2023-01-09 15:01:350249eef46cf79b776989b202b54c5b78n/a162.219.226.83:443
2023-01-08 00:41:07a27588fcda27df268e4d65c9550f7556n/a13.224.102.17:443
2023-01-07 14:24:133a9b5876d398cf28d7cb54f27b348be0n/a108.156.58.47:443
2023-01-06 21:08:59315e8baa13a087385bb8a38ac5462d8bVirustotal results 40 / 68 (58.82%) 64.233.184.206:8883
2023-01-06 01:03:1807f7aebf76e29f1124d1a2dba86ab5ecVirustotal results 52 / 71 (73.24%) 13.224.102.17:443
2022-12-26 00:16:53b5440068d83a951eaa4cbf40e8bc463dn/a108.156.58.47:443
2022-12-22 12:01:04356a495ab073688e2b6bfcbef83342een/a104.85.6.101:443
2022-12-22 11:07:466b5006202b0ee235e321828c2ae1d3d6Virustotal results 29 / 72 (40.28%) 13.224.102.17:443
2022-12-09 14:25:5803339fd607f0db638587bc716021ba71Virustotal results 0 / 70 (0.00%) 34.204.63.26:443
2022-12-09 14:25:5803339fd607f0db638587bc716021ba71Virustotal results 0 / 70 (0.00%) 104.19.162.75:443
2022-11-07 02:47:15a86fbe00f12d1f2838b471fc02a9d4e0n/a23.211.5.50:443
2022-11-03 13:00:3903267e7d68ed0b4b1a0f195112277af1Virustotal results 48 / 72 (66.67%) 13.224.93.221:443
2022-10-28 20:47:43a803edddc8573dac3d8eb99718a90d43n/a52.222.142.236:443
2022-10-28 17:03:566629900d2b3e94530c5788932c458f50n/a13.224.102.17:443
2022-10-28 17:03:556629900d2b3e94530c5788932c458f50n/a13.224.93.221:443
2022-10-28 17:03:556629900d2b3e94530c5788932c458f50n/a162.219.225.118:443
2022-10-28 16:42:2647ecbf382dbfa5267a4f838646620fd4n/a65.9.86.187:443
2022-10-28 15:34:265fa10fd0e3d6470f158a68f2e3ebd812n/a13.224.102.17:443
2022-10-28 06:05:57768ed2cfc2caf8c4b6d8d18ce7e4d908n/a13.224.102.17:443
2022-10-28 05:55:184ebc92ec935a33b183b036a28f0472e6Virustotal results 25 / 68 (36.76%) 52.222.142.236:443
2022-10-28 05:50:02bd4300bec75aea4594b63753347b7aa6n/a162.219.225.118:443
2022-10-28 05:39:06621b519c3d70b7e14fa6723d72c544fen/a13.225.142.225:443
2022-10-28 05:38:345e0bf7b28bebe18defb564e7185829b5n/a18.66.129.19:443
2022-10-28 05:35:28851097b23fdd0b2b1bc94ed5f7dc2a28n/a162.219.225.118:443
2022-10-27 01:37:20887c8528c894d656a0926884fe546923n/a108.138.10.130:443
2022-10-24 13:35:173d09a350357016dd64bc7edde2c6147bn/a18.65.34.171:443
2022-10-19 17:09:224b2544790ac2be87b97e29763bfb3ecen/a162.219.225.118:443
2022-10-08 09:18:5411017138709b247ca3981b964a280298Virustotal results 57 / 72 (79.17%) 13.224.100.34:443
2022-10-07 10:38:22767e9b5e85ee09dae638a2773ccd1f01n/a13.224.100.34:443
2022-10-07 10:38:22767e9b5e85ee09dae638a2773ccd1f01n/a13.224.102.80:443
2022-10-07 10:30:247324df6163d339227df369781196468an/a13.224.100.34:443
2022-09-30 15:47:5652956747fe3d6f147bd8ff2c4c34b522n/a184.86.82.220:443
2022-09-19 03:20:175e06edba6327107cda11d6f491939ea7n/a23.204.249.185:443
2022-09-18 15:32:15206313dea041cfd3538e5a8a9da6bcf0Virustotal results 55 / 71 (77.46%) 13.224.90.218:443
2022-09-18 15:32:14206313dea041cfd3538e5a8a9da6bcf0Virustotal results 55 / 71 (77.46%) 162.219.225.118:443
2022-09-18 06:34:482b41f84453e275b0d8c4ebc6e39db931n/a23.204.249.185:443
2022-09-16 03:39:22427a6c7cda506488df9602a9a3823e5cn/a108.156.66.76:443
2022-09-16 03:39:22427a6c7cda506488df9602a9a3823e5cn/a65.9.72.157:443
2022-09-09 20:45:44e8e5d33d96f00e6766acc0850d660157n/a162.219.225.118:443
2022-09-09 20:45:43e8e5d33d96f00e6766acc0850d660157n/a13.224.90.218:443
2022-09-08 21:33:41218c86df7ec87b0a85ed3d11934a5651n/a104.85.241.139:443
2022-09-08 01:06:1387f73d8af02d0051ffcacb725c162a80n/a108.138.6.128:443
2022-09-07 13:50:43113654f70a4df71e02a0aa88a22011can/a18.66.128.229:443
2022-09-07 13:50:43113654f70a4df71e02a0aa88a22011can/a162.219.225.118:443
2022-09-06 17:16:56dab09f16630cdddf1371b70cea1f001fn/a13.224.90.218:443
2022-09-06 15:36:43ce75e0cffe33dd04b6d98a1923ff5e2cn/a65.9.72.157:443
2022-09-05 16:08:503fbae4ecd0c709ffd9285d96686a6217n/a54.230.234.29:443
2022-09-05 16:08:503fbae4ecd0c709ffd9285d96686a6217n/a108.156.66.76:443
2022-09-05 15:23:213da9cdcd769609e48de16d4791de5a11n/a162.219.225.118:443
2022-09-04 17:14:5813b32559bde679c4244559eaf8143826Virustotal results 54 / 71 (76.06%) 162.219.225.118:443
2022-09-04 00:44:2842e64bf3402abbf60f72f919808d5758n/a13.224.90.218:443
2022-09-04 00:44:2842e64bf3402abbf60f72f919808d5758n/a23.211.5.61:443
2022-09-03 09:47:290791aab88ec1a4b550fedc306931c75en/a162.219.225.118:443
2022-09-03 09:47:280791aab88ec1a4b550fedc306931c75en/a65.9.72.157:443
2022-09-02 21:18:3443b681331a5b66032d3cd23b7d5c5cb7Virustotal results 52 / 70 (74.29%) 162.219.225.118:443
2022-09-02 20:12:3867fb794418018e3fd38074c6f614353en/a108.156.66.76:443
2022-09-02 20:12:3867fb794418018e3fd38074c6f614353en/a65.9.72.157:443
2022-09-02 19:47:4953d0f9ac7b4a11ae9fa02fefe469b028n/a13.224.90.218:443
2022-09-02 19:47:4953d0f9ac7b4a11ae9fa02fefe469b028n/a162.219.225.118:443
2022-09-02 09:29:0137349598ab32739844750832c3bf2e92n/a104.75.90.57:443
2022-09-02 09:29:0137349598ab32739844750832c3bf2e92n/a162.219.225.118:443
2022-09-02 00:34:15010f6b7b7a76ae25637947ca6c970626n/a54.230.234.29:443
2022-09-01 15:49:481a239a5526ffe5101eab22261f05c65aVirustotal results 59 / 69 (85.51%) 162.219.224.22:443
2022-09-01 15:49:471a239a5526ffe5101eab22261f05c65aVirustotal results 59 / 69 (85.51%) 13.224.95.154:443
2022-09-01 09:26:23cf537177cbd60000ddee135706f0ac56n/a13.224.90.218:443
2022-09-01 09:26:22cf537177cbd60000ddee135706f0ac56n/a23.211.5.61:443
2022-09-01 09:13:44ad97e5403853769f00d2671b0d60307an/a108.156.66.76:443
2022-09-01 08:52:23a4ba7dd4270e864dd04f5457a510c5d8n/a23.211.5.61:443
2022-09-01 07:43:07b1523317b91ff4736e10413fa5a2b0cdn/a108.156.66.76:443
2022-09-01 06:30:269aaa4532f946b3163582cca9fc223991n/a13.224.90.218:443
2022-08-31 20:58:159e554dc575a60f22fef0856540505596n/a13.224.90.218:443
2022-08-31 20:58:159e554dc575a60f22fef0856540505596n/a184.86.82.222:443
2022-08-31 20:29:4290f49ad09f87a1cc22b917f14a3c3689n/a162.219.225.118:443
2022-08-31 20:29:42829c4a90a4470ffafe9a0420dcbabae9n/a162.219.225.118:443
2022-08-31 20:29:4290f49ad09f87a1cc22b917f14a3c3689n/a13.225.150.186:443
2022-08-31 10:24:286da0ff01f36a92475173af7096b683cdn/a65.9.72.157:443
2022-08-31 05:01:1664564502d424df7126d6c1df24bbd302n/a184.86.82.222:443
2022-08-31 05:01:1564564502d424df7126d6c1df24bbd302n/a13.224.90.218:443
2022-08-31 01:33:405ae045fb0d42a635e6641dc894598033n/a162.219.225.118:443
2022-08-31 01:25:405a5a1028fae02606f93c82032a01fdfcn/a108.156.66.76:443
2022-08-31 01:25:405a5a1028fae02606f93c82032a01fdfcn/a162.219.225.118:443
2022-08-30 19:02:0319505468af28e32c987acd357abab8b9Virustotal results 28 / 69 (40.58%) 13.224.90.218:443
2022-08-30 14:49:120bf67e4e33b7d5d7073f9c4e2db34890Virustotal results 43 / 70 (61.43%) 13.225.150.186:443
2022-08-30 03:49:341b2bd8a2896450bb870b16d52014561eVirustotal results 54 / 70 (77.14%) 13.224.90.218:443
2022-08-29 22:11:24366f817bf003354c19c5f090ea48ffa8Virustotal results 49 / 71 (69.01%) 162.219.225.118:443
2022-08-29 22:11:24366f817bf003354c19c5f090ea48ffa8Virustotal results 49 / 71 (69.01%) 13.224.90.218:443
2022-08-29 21:52:45430a3ba86b08d0d0ead9fa7026a82396n/a13.224.90.218:443
2022-08-28 00:33:3227bc82d8120e706626eee82dc6624060n/a13.224.90.218:443
2022-08-28 00:33:3227bc82d8120e706626eee82dc6624060n/a23.211.5.61:443
2022-08-26 23:01:098defc530caecfd189931580dd2ae1998n/a108.156.66.76:443

# of entries: 100 (max: 100)