JA3 Fingerprints

You can find further information about the JA3 fingerprint c0220cd64849a629397a9cb68f78a0ea, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:c0220cd64849a629397a9cb68f78a0ea
First seen:2019-03-24 00:12:32 UTC
Last seen:2020-11-25 11:28:24 UTC
Status:Blacklisted
Malware samples:831
Destination IPs:228
Malware:Tofsee -
Listing date:2020-01-09 14:28:36

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2020-11-25 11:28:24d8a7d3ff7ea2b1b68e059ed0cd32fa7en/a52.1.109.248:443
2020-11-25 11:28:24d8a7d3ff7ea2b1b68e059ed0cd32fa7en/a172.217.168.228:443
2020-11-25 11:04:03d7810f3c9c10fe1ca8597dc39d07be5eVirustotal results 44 / 70 (62.86%) 23.211.5.61:443
2020-11-25 11:04:03d7810f3c9c10fe1ca8597dc39d07be5eVirustotal results 44 / 70 (62.86%) 216.58.215.228:443
2020-11-25 11:04:03d7810f3c9c10fe1ca8597dc39d07be5eVirustotal results 44 / 70 (62.86%) 172.217.168.68:443
2020-11-25 11:04:02d7810f3c9c10fe1ca8597dc39d07be5eVirustotal results 44 / 70 (62.86%) 13.224.90.101:443
2020-11-25 09:53:39d3d17bada350a6851dbb257e5f91fc9eVirustotal results 53 / 72 (73.61%) 172.217.17.68:443
2020-11-25 09:53:39d3d17bada350a6851dbb257e5f91fc9eVirustotal results 53 / 72 (73.61%) 172.217.19.195:443
2020-11-25 08:54:53cb215e53347ca284c12f8852638b038eVirustotal results 38 / 72 (52.78%) 65.9.85.10:443
2020-11-25 08:15:02c4fff4ce318bb96e866569d859f0e214n/a65.9.85.10:443
2020-11-25 08:15:02c4fff4ce318bb96e866569d859f0e214n/a176.32.103.205:443
2020-11-25 08:15:02c4fff4ce318bb96e866569d859f0e214n/a34.194.88.13:443
2020-11-25 07:56:55c253d024ab9b294eef99ee62a2fd1106Virustotal results 53 / 71 (74.65%) 99.84.239.83:443
2020-11-25 07:56:55c253d024ab9b294eef99ee62a2fd1106Virustotal results 53 / 71 (74.65%) 143.204.159.26:443
2020-11-25 07:56:55c253d024ab9b294eef99ee62a2fd1106Virustotal results 53 / 71 (74.65%) 13.225.148.15:443
2020-11-25 07:56:55c253d024ab9b294eef99ee62a2fd1106Virustotal results 53 / 71 (74.65%) 13.225.47.216:443
2020-11-25 06:58:32ba35fd09237bc3f4e3e4f7230d8fa324Virustotal results 50 / 72 (69.44%) 23.211.5.61:443
2020-11-25 06:58:32ba35fd09237bc3f4e3e4f7230d8fa324Virustotal results 50 / 72 (69.44%) 13.224.90.101:443
2020-11-25 04:48:16adc6ab4d348e821c872a152200aed855Virustotal results 51 / 72 (70.83%) 3.220.83.93:443
2020-11-25 04:48:16adc6ab4d348e821c872a152200aed855Virustotal results 51 / 72 (70.83%) 52.71.223.34:443
2020-11-25 04:48:15adc6ab4d348e821c872a152200aed855Virustotal results 51 / 72 (70.83%) 34.195.3.186:443
2020-11-25 04:48:15adc6ab4d348e821c872a152200aed855Virustotal results 51 / 72 (70.83%) 13.224.90.101:443
2020-11-25 04:48:15adc6ab4d348e821c872a152200aed855Virustotal results 51 / 72 (70.83%) 52.5.199.160:443
2020-11-25 04:42:26ad766f7e6fea4b9c3aca4db91af4607dVirustotal results 55 / 71 (77.46%) 23.211.5.61:443
2020-11-25 04:42:24ad766f7e6fea4b9c3aca4db91af4607dVirustotal results 55 / 71 (77.46%) 54.204.115.52:443
2020-11-25 04:42:24ad766f7e6fea4b9c3aca4db91af4607dVirustotal results 55 / 71 (77.46%) 13.224.90.101:443
2020-11-25 04:13:33ac1d9584fea3c334a037d9225f03b120Virustotal results 55 / 72 (76.39%) 23.211.5.8:443
2020-11-25 04:13:33ac1d9584fea3c334a037d9225f03b120Virustotal results 55 / 72 (76.39%) 172.217.168.36:443
2020-11-25 04:13:33ac1d9584fea3c334a037d9225f03b120Virustotal results 55 / 72 (76.39%) 13.224.90.101:443
2020-11-25 04:13:33ac1d9584fea3c334a037d9225f03b120Virustotal results 55 / 72 (76.39%) 172.217.168.4:443
2020-11-25 03:39:34aacf7ed213945f1ffbd3c56954bf0110n/a35.173.166.200:443
2020-11-25 03:39:34aacf7ed213945f1ffbd3c56954bf0110n/a143.204.93.225:443
2020-11-25 03:39:34aacf7ed213945f1ffbd3c56954bf0110n/a3.232.148.177:443
2020-11-25 03:39:33aacf7ed213945f1ffbd3c56954bf0110n/a2.18.233.29:443
2020-11-25 03:26:22aa5541eede38a6c915ea40dc059a6030n/a23.211.5.61:443
2020-11-25 03:26:21aa5541eede38a6c915ea40dc059a6030n/a172.217.168.67:443
2020-11-25 00:27:24a57637d5857e23e4adfdcba19b0c1869Virustotal results 50 / 71 (70.42%) 13.226.236.158:443
2020-11-25 00:27:24a57637d5857e23e4adfdcba19b0c1869Virustotal results 50 / 71 (70.42%) 13.225.47.216:443
2020-11-25 00:02:28a2031e92d125c3fa5c7ec887efd83503Virustotal results 56 / 72 (77.78%) 13.224.90.101:443
2020-11-24 22:40:0677327c988b00213f86643184f731bb80Virustotal results 47 / 72 (65.28%) 172.217.168.36:443
2020-11-24 22:40:0677327c988b00213f86643184f731bb80Virustotal results 47 / 72 (65.28%) 3.212.83.203:443
2020-11-24 22:40:0677327c988b00213f86643184f731bb80Virustotal results 47 / 72 (65.28%) 34.193.5.242:443
2020-11-24 22:40:0577327c988b00213f86643184f731bb80Virustotal results 47 / 72 (65.28%) 23.211.5.61:443
2020-11-24 21:04:180f9d71c8d0b3c977f9741b257ed1a420n/a74.125.195.105:443
2020-11-24 21:04:180f9d71c8d0b3c977f9741b257ed1a420n/a13.226.255.145:443
2020-11-24 21:04:180f9d71c8d0b3c977f9741b257ed1a420n/a74.125.195.106:443
2020-11-24 21:04:170f9d71c8d0b3c977f9741b257ed1a420n/a104.75.142.182:443
2020-11-24 21:01:302100cc4a8465ec536c9a42dcb5ef3344Virustotal results 50 / 72 (69.44%) 13.224.90.101:443
2020-11-24 20:47:46b0a256a4ac3afc1c9175603dd8aa42daVirustotal results 40 / 72 (55.56%) 34.206.33.202:443
2020-11-24 20:47:45b0a256a4ac3afc1c9175603dd8aa42daVirustotal results 40 / 72 (55.56%) 172.217.17.68:443
2020-11-24 20:47:44b0a256a4ac3afc1c9175603dd8aa42daVirustotal results 40 / 72 (55.56%) 52.222.137.64:443
2020-11-24 20:47:43b0a256a4ac3afc1c9175603dd8aa42daVirustotal results 40 / 72 (55.56%) 52.3.71.143:443
2020-11-24 20:47:40b0a256a4ac3afc1c9175603dd8aa42daVirustotal results 40 / 72 (55.56%) 65.9.85.10:443
2020-11-24 18:36:39b19df136265d1379461ea7ba258458a0n/a176.32.98.166:443
2020-11-24 18:36:39b19df136265d1379461ea7ba258458a0n/a2.18.233.29:443
2020-11-24 18:36:39b19df136265d1379461ea7ba258458a0n/a52.0.37.128:443
2020-11-24 18:36:39b19df136265d1379461ea7ba258458a0n/a143.204.93.225:443
2020-11-24 17:56:14b0e3e0a3503766013658806597f291a6Virustotal results 49 / 71 (69.01%) 34.195.173.122:443
2020-11-24 17:56:14b0e3e0a3503766013658806597f291a6Virustotal results 49 / 71 (69.01%) 157.240.17.63:443
2020-11-24 17:56:14b0e3e0a3503766013658806597f291a6Virustotal results 49 / 71 (69.01%) 13.224.90.101:443
2020-11-22 02:49:11989bf2f2dd14ae1f5eb8022b9ad822cbVirustotal results 43 / 72 (59.72%) 23.72.96.17:443
2020-11-22 02:49:11989bf2f2dd14ae1f5eb8022b9ad822cbVirustotal results 43 / 72 (59.72%) 185.181.176.19:443
2020-11-21 02:00:10a14930ad11f80dd65f1a17a96f1a6214n/a185.181.176.19:443
2020-11-21 00:13:12794c3cc8ecbd5e89352b9416e50c12fcVirustotal results 48 / 70 (68.57%) 95.100.48.189:443
2020-11-20 13:20:53cb0d8fb8225da2ba6149f0fcb5a0aa7en/a184.25.217.115:443
2020-11-20 12:05:46ba1859750c281d7de2ef2ac6f2c0a3bbn/a95.100.48.189:443
2020-11-20 05:36:24a5d3c849e173d35cb11d66bffd83af09Virustotal results 55 / 72 (76.39%) 184.25.217.115:443
2020-11-20 05:36:24a5d3c849e173d35cb11d66bffd83af09Virustotal results 55 / 72 (76.39%) 185.181.176.19:443
2020-11-20 05:36:24a5d3c849e173d35cb11d66bffd83af09Virustotal results 55 / 72 (76.39%) 104.111.227.59:443
2020-11-18 10:46:08b03d557b300cc309a17fc112fb340dfdVirustotal results 46 / 71 (64.79%) 185.181.176.19:443
2020-11-14 06:35:50794b1162316b2d201dd8c3699b66e967n/a13.224.90.101:443
2020-11-14 06:35:50794b1162316b2d201dd8c3699b66e967n/a23.211.5.61:443
2020-11-13 17:37:0561b4f8c99c90c8c2173299aac4b9f306n/a52.222.137.64:443
2020-11-13 15:55:050a330d8dcffec5c40cbce1cc0086a93an/a23.211.5.61:443
2020-11-13 15:49:4430aa32d6df3953f1fd5c630deb1b3f35n/a23.67.137.78:443
2020-11-13 15:49:4430aa32d6df3953f1fd5c630deb1b3f35n/a176.32.98.166:443
2020-11-13 15:49:4430aa32d6df3953f1fd5c630deb1b3f35n/a143.204.93.225:443
2020-11-13 15:36:3934d46644b3f66a809ab14f8020b5c279n/a52.222.137.64:443
2020-11-13 15:23:0233cad99d88094a24ae8812e4456f1ab4n/a176.32.98.166:443
2020-11-13 15:23:0233cad99d88094a24ae8812e4456f1ab4n/a52.222.137.64:443
2020-11-13 15:21:1995e2a7923c02de413d910e8118206ed3n/a13.224.90.101:443
2020-11-13 15:21:1995e2a7923c02de413d910e8118206ed3n/a23.211.5.61:443
2020-11-13 15:21:1995e2a7923c02de413d910e8118206ed3n/a176.32.98.166:443
2020-11-13 14:59:50b5d63af3bb623f9fbf36c160fc562466Virustotal results 37 / 71 (52.11%) 23.37.56.24:443
2020-11-13 14:59:50b5d63af3bb623f9fbf36c160fc562466Virustotal results 37 / 71 (52.11%) 143.204.93.225:443
2020-11-13 13:57:34b47db81c1702ded6fc1f92a6b4ed01fen/a13.226.163.199:443
2020-11-13 13:57:34b47db81c1702ded6fc1f92a6b4ed01fen/a176.32.98.166:443
2020-11-13 04:57:17b0d11148683ccf7f7a9d404cc3af20c8Virustotal results 44 / 71 (61.97%) 13.224.90.101:443
2020-11-13 04:57:17b0d11148683ccf7f7a9d404cc3af20c8Virustotal results 44 / 71 (61.97%) 176.32.103.205:443
2020-11-13 04:36:34b040ae18565ee414592256994a371b31n/a23.211.5.61:443
2020-11-13 04:36:34b040ae18565ee414592256994a371b31n/a13.224.90.101:443
2020-11-13 04:34:06b0428b974d365565cac0812214158fd1Virustotal results 46 / 72 (63.89%) 23.62.133.214:443
2020-11-13 04:34:06b0428b974d365565cac0812214158fd1Virustotal results 46 / 72 (63.89%) 13.226.152.225:443
2020-11-13 04:34:06b0428b974d365565cac0812214158fd1Virustotal results 46 / 72 (63.89%) 52.222.137.64:443
2020-11-13 04:24:38aff9ab5bd7309235fdfc643d535f89daVirustotal results 46 / 72 (63.89%) 13.224.90.101:443
2020-11-13 04:24:37aff9ab5bd7309235fdfc643d535f89daVirustotal results 46 / 72 (63.89%) 23.211.5.61:443
2020-11-13 03:59:10aea6b58c89f52838ca02f0ec6bee0e81Virustotal results 43 / 72 (59.72%) 52.222.137.64:443
2020-11-13 03:59:10aea6b58c89f52838ca02f0ec6bee0e81Virustotal results 43 / 72 (59.72%) 95.100.197.10:443
2020-11-13 02:49:51a6c96806e782c2d6033990f64054b78en/a13.35.97.87:443
2020-11-13 02:49:51a6c96806e782c2d6033990f64054b78en/a104.75.142.182:443

# of entries: 100 (max: 100)