JA3 Fingerprints

You can find further information about the JA3 fingerprint c0220cd64849a629397a9cb68f78a0ea, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:c0220cd64849a629397a9cb68f78a0ea
First seen:2019-03-24 00:12:32 UTC
Last seen:2021-07-31 00:26:06 UTC
Status:Blacklisted
Malware samples:2'851
Destination IPs:861
Malware:Tofsee -
Listing date:2020-01-09 14:28:36

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2024-01-02 10:57:15ac13a118d4b504158016dde92287ba8cn/a52.97.135.98:443
2024-01-02 10:57:14ac13a118d4b504158016dde92287ba8cn/a13.107.42.22:443
2023-12-07 18:01:231b62b73224f069bbf9023ce167106e57Virustotal results 57 / 71 (80.28%) 13.107.42.22:443
2023-12-05 11:00:14ab47883f1cafa952369cb96789d4d25en/a104.237.62.212:443
2023-07-06 03:18:10b0134a0a8f3c072b7f386c546cbc87b5n/a18.165.180.80:443
2023-07-06 03:18:09b0134a0a8f3c072b7f386c546cbc87b5n/a162.219.224.231:443
2023-07-06 03:18:09b0134a0a8f3c072b7f386c546cbc87b5n/a162.219.226.231:443
2023-07-05 08:03:5113312131f49a2f1451a87f794a1f65e9n/a18.164.166.80:443
2023-07-05 03:10:56a3cae3f983eb87ad409aaa58fb7e8f3an/a99.84.202.21:443
2023-07-01 22:21:504624dddbe1a794e78d2b0c9014007c2en/a99.84.202.21:443
2023-07-01 22:21:504624dddbe1a794e78d2b0c9014007c2en/a13.225.139.89:443
2023-07-01 22:16:50f18c94e7d8c0eb55ca27f0389b48027bVirustotal results 31 / 71 (43.66%) 18.165.180.80:443
2023-07-01 22:14:26308062bf3087c15b63186e366d8eb119Virustotal results 30 / 71 (42.25%) 18.66.104.83:443
2023-07-01 22:14:26308062bf3087c15b63186e366d8eb119Virustotal results 30 / 71 (42.25%) 23.206.209.146:443
2023-07-01 22:14:25308062bf3087c15b63186e366d8eb119Virustotal results 30 / 71 (42.25%) 13.225.73.180:443
2023-07-01 16:29:38723603e88a90618acddbd638ed615202n/a18.66.104.83:443
2023-07-01 07:43:14daa9c6765a7c7fa643a8e374087c97b2n/a65.9.75.85:443
2023-07-01 07:36:53d7131bd86850054713dffe84e76930b2n/a13.225.139.89:443
2023-07-01 07:36:52d7131bd86850054713dffe84e76930b2n/a99.84.202.21:443
2023-07-01 07:36:51d7131bd86850054713dffe84e76930b2n/a13.225.149.74:443
2023-06-30 23:59:292ab3a0b70137c4cda8e9617ea0b24f36n/a18.66.104.83:443
2023-06-30 23:59:292ab3a0b70137c4cda8e9617ea0b24f36n/a18.65.36.211:443
2023-06-30 23:59:292ab3a0b70137c4cda8e9617ea0b24f36n/a65.9.75.85:443
2023-06-30 23:59:292ab3a0b70137c4cda8e9617ea0b24f36n/a52.222.140.89:443
2023-06-30 23:59:282ab3a0b70137c4cda8e9617ea0b24f36n/a23.206.209.146:443
2023-06-30 23:16:11d47d9b44ed788a66ccf1d5957182a0d9n/a173.223.117.155:443
2023-06-30 23:16:10d47d9b44ed788a66ccf1d5957182a0d9n/a104.85.5.189:443
2023-06-30 19:37:33a2cf6d0e5025f5b6f043be9d66b5d110n/a18.165.186.118:443
2023-06-30 18:47:36bf607ed7b7bab920a82f470820e28015n/a184.86.82.223:443
2023-06-30 18:47:36bf607ed7b7bab920a82f470820e28015n/a18.165.180.80:443
2023-06-30 15:41:44ea7be9cc7b5d1a2056de07aafdf3ca77n/a13.224.92.89:443
2023-06-30 15:41:44ea7be9cc7b5d1a2056de07aafdf3ca77n/a18.165.180.80:443
2023-06-30 15:41:44ea7be9cc7b5d1a2056de07aafdf3ca77n/a13.224.103.189:443
2023-06-30 15:41:43ea7be9cc7b5d1a2056de07aafdf3ca77n/a18.165.186.118:443
2023-06-30 13:06:19d00eecc78e3945fc9e60d391030ead38n/a18.165.180.80:443
2023-06-30 13:06:18d00eecc78e3945fc9e60d391030ead38n/a184.86.82.223:443
2023-06-30 10:17:13c5491856b9d83ee28f923b8db8ee88a2n/a18.65.36.211:443
2023-06-30 10:17:12c5491856b9d83ee28f923b8db8ee88a2n/a52.222.140.89:443
2023-06-30 10:17:12c5491856b9d83ee28f923b8db8ee88a2n/a65.9.75.85:443
2023-06-30 06:32:5417fc098775873adf824bec5368cd8ef9n/a173.223.117.155:443
2023-06-30 06:06:310b63d87eb6469de1edf3d56bd907b163Virustotal results 30 / 71 (42.25%) 52.222.140.89:443
2023-06-30 06:06:290b63d87eb6469de1edf3d56bd907b163Virustotal results 30 / 71 (42.25%) 65.9.75.85:443
2023-06-29 22:41:36d3671f6e25a30d3a9866318d1c825e47n/a108.138.0.98:443
2023-06-29 22:41:36d3671f6e25a30d3a9866318d1c825e47n/a108.138.0.98:443
2023-06-29 14:33:5233e590a61265ac87d076a29a2af57d61Virustotal results 56 / 70 (80.00%) 18.65.36.211:443
2023-06-29 14:33:5233e590a61265ac87d076a29a2af57d61Virustotal results 56 / 70 (80.00%) 104.85.6.102:443
2023-06-29 12:58:394b2c803278cb2fab303d8e28825bf804n/a23.219.42.142:443
2023-06-29 12:58:394b2c803278cb2fab303d8e28825bf804n/a23.219.42.59:443
2023-06-29 12:58:374b2c803278cb2fab303d8e28825bf804n/a13.225.147.148:443
2023-06-29 12:58:374b2c803278cb2fab303d8e28825bf804n/a13.225.139.89:443
2023-06-29 10:15:54c94a39e1a3b10185ca0d771ee8284e03n/a65.9.77.56:443
2023-06-29 08:18:26827f3c05a8c702c0be70d8e156b72f72n/a23.206.209.144:443
2023-06-29 08:18:26827f3c05a8c702c0be70d8e156b72f72n/a18.66.104.83:443
2023-06-28 13:13:59cb8b000a21d921af4bd884f452c3b0bbn/a18.65.36.211:443
2023-06-28 13:13:58cb8b000a21d921af4bd884f452c3b0bbn/a65.9.77.56:443
2023-06-28 09:57:148d9e9ac0c793d993be29100a95178e8cn/a13.225.147.148:443
2023-06-28 07:58:269efe30d143d886dc9bb1cc46069ad68dn/a13.225.147.148:443
2023-06-28 07:58:269efe30d143d886dc9bb1cc46069ad68dn/a13.225.149.74:443
2023-05-14 15:29:17c2b784bc5cbebacede96947bc1baaeb8n/a13.227.219.218:443
2023-05-09 16:08:084597cfda9793f195963fcceeb3a9b45fVirustotal results 53 / 70 (75.71%) 18.165.189.38:443
2023-05-04 10:19:33767d9d7c389206caf5c8d1398ca23c60n/a184.86.82.220:443
2023-04-28 14:43:182cabafbae6aee44309dab1a40063686bn/a13.227.219.218:443
2023-04-21 14:13:16b90744dbb7414e3965c47699877d82een/a35.244.217.13:443
2023-04-21 14:13:16b90744dbb7414e3965c47699877d82een/a172.66.40.82:443
2023-04-21 14:13:16b90744dbb7414e3965c47699877d82een/a34.160.120.42:443
2023-04-11 03:55:10b7ca2a44de27a758e7da7b6f6f8b6638n/a34.160.120.42:443
2023-04-11 03:55:09b7ca2a44de27a758e7da7b6f6f8b6638n/a172.66.40.82:443
2023-04-10 00:37:56c8a5092609dc6f3cf1209b1c042272ean/a172.66.43.174:443
2023-04-10 00:37:56c8a5092609dc6f3cf1209b1c042272ean/a35.244.217.13:443
2023-04-10 00:37:56c8a5092609dc6f3cf1209b1c042272ean/a34.160.120.42:443
2023-03-16 02:52:5474c871eadb2971aa86a86981c00b35c8n/a172.66.43.174:443
2023-03-16 02:52:5374c871eadb2971aa86a86981c00b35c8n/a34.160.120.42:443
2023-03-03 07:56:15d43c7f90f039b92f0907a8bb3704e021n/a18.165.189.188:443
2023-03-03 07:50:27a87fa5c009d828d666aac49e83c22021n/a184.86.82.222:443
2023-03-03 04:07:0382cc8985e0a923ca79e73caf9bd1531dn/a18.165.189.188:443
2023-03-02 23:10:176b3380253ac866dc06c43311aad23f96n/a184.86.82.222:443
2023-03-02 23:10:176b3380253ac866dc06c43311aad23f96n/a13.224.95.78:443
2023-03-02 20:03:495f97764565d39cdd7b5704d4c60e56f4n/a162.219.225.118:443
2023-03-02 20:03:485f97764565d39cdd7b5704d4c60e56f4n/a18.65.37.117:443
2023-03-02 19:40:40131babee5094c2d86ad8f5ee396511e3n/a18.165.189.188:443
2023-03-02 14:31:14167a025cd7926eb41df8593d4a70cc1an/a52.85.202.189:443
2023-03-02 14:31:12167a025cd7926eb41df8593d4a70cc1an/a184.24.197.196:443
2023-03-01 14:41:22e6633af95778725d06d9adc558c55040n/a162.219.225.118:443
2023-03-01 13:34:07e4925f827f21fc13975d1f8ebee99dban/a162.219.225.118:443
2023-03-01 13:34:07e4925f827f21fc13975d1f8ebee99dban/a18.66.120.232:443
2023-03-01 08:48:07dac632e30c775cd386be67711d05ffe1n/a18.165.189.188:443
2023-03-01 08:36:30e909024bc528d1a17e52079ca5276821n/a18.66.120.232:443
2023-03-01 08:08:27daa1f997980424cf83e529727e2bdab1n/a18.154.128.218:443
2023-03-01 08:08:27daa1f997980424cf83e529727e2bdab1n/a104.85.241.139:443
2023-02-28 19:01:39cefb18d7fe4fbd36bcf83b46930298ccn/a18.65.37.117:443
2023-02-28 17:03:06c9999ae0f8054781664e451a06a9ff0an/a18.165.189.188:443
2023-02-28 01:30:5184e5943122064af35a51830b607f617cn/a104.85.6.101:443
2023-02-28 00:00:347de86d8af2610d799f181ac80b1df56fn/a13.225.150.222:443
2023-02-27 11:41:050330015950b98193edd7e38b7ec0db58n/a18.65.37.117:443
2023-02-27 02:39:2549e86c62091f5ff98636d931f2f4d3c7n/a52.85.202.189:443
2023-02-27 01:36:48392708029b28148218fda3a741636930n/a23.211.5.61:443
2023-02-26 23:50:350e353d44db53ca1f8c85ded699547fbbVirustotal results 54 / 70 (77.14%) 108.138.5.166:443
2023-02-26 17:19:04badfd765f7f9e022f71d789279f7c405n/a104.75.90.57:443
2023-02-26 17:19:03badfd765f7f9e022f71d789279f7c405n/a18.66.142.157:443
2023-02-26 17:19:03badfd765f7f9e022f71d789279f7c405n/a52.222.229.16:443

# of entries: 100 (max: 100)