JA3 Fingerprints

You can find further information about the JA3 fingerprint c0220cd64849a629397a9cb68f78a0ea, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:c0220cd64849a629397a9cb68f78a0ea
First seen:2019-03-24 00:12:32 UTC
Last seen:2021-07-31 00:26:06 UTC
Status:Blacklisted
Malware samples:2'606
Destination IPs:756
Malware:Tofsee -
Listing date:2020-01-09 14:28:36

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2021-10-10 05:24:36a00c4eb528943e946efc048bf376baccn/a10.0.7.113:60191
2021-10-10 05:24:36a00c4eb528943e946efc048bf376baccn/a10.0.7.113:59265
2021-10-10 05:24:28a00c4eb528943e946efc048bf376baccn/a10.0.7.113:59141
2021-10-10 05:24:27a00c4eb528943e946efc048bf376baccn/a10.0.7.113:60190
2021-10-10 05:24:24a00c4eb528943e946efc048bf376baccn/a10.0.7.113:60137
2021-10-10 05:24:22a00c4eb528943e946efc048bf376baccn/a10.0.7.113:60234
2021-10-10 05:24:21a00c4eb528943e946efc048bf376baccn/a10.0.7.113:59822
2021-10-10 05:24:20a00c4eb528943e946efc048bf376baccn/a10.0.7.113:59744
2021-10-10 05:24:19a00c4eb528943e946efc048bf376baccn/a10.0.7.113:59933
2021-10-10 05:24:18a00c4eb528943e946efc048bf376baccn/a185.93.128.30:443
2021-10-10 05:24:18a00c4eb528943e946efc048bf376baccn/a10.0.7.113:60157
2021-10-10 05:24:17a00c4eb528943e946efc048bf376baccn/a10.0.7.113:59791
2021-10-10 05:24:16a00c4eb528943e946efc048bf376baccn/a10.0.7.113:59973
2021-10-10 05:24:16a00c4eb528943e946efc048bf376baccn/a10.0.7.113:59298
2021-10-10 05:24:15a00c4eb528943e946efc048bf376baccn/a10.0.7.113:59962
2021-10-10 05:24:15a00c4eb528943e946efc048bf376baccn/a10.0.7.113:59130
2021-10-10 05:24:14a00c4eb528943e946efc048bf376baccn/a167.98.14.236:443
2021-10-10 05:24:14a00c4eb528943e946efc048bf376baccn/a10.0.7.113:60444
2021-10-10 05:24:13a00c4eb528943e946efc048bf376baccn/a10.0.7.113:59901
2021-10-10 05:24:12a00c4eb528943e946efc048bf376baccn/a10.0.7.113:59336
2021-10-10 05:24:12a00c4eb528943e946efc048bf376baccn/a160.92.64.233:443
2021-10-10 05:24:10a00c4eb528943e946efc048bf376baccn/a10.0.7.113:59854
2021-10-10 05:24:09a00c4eb528943e946efc048bf376baccn/a10.0.7.113:59277
2021-10-10 05:24:08a00c4eb528943e946efc048bf376baccn/a10.0.7.113:59952
2021-10-10 05:24:06a00c4eb528943e946efc048bf376baccn/a10.0.7.113:60121
2021-10-10 05:24:05a00c4eb528943e946efc048bf376baccn/a10.0.7.113:59552
2021-10-10 05:24:04a00c4eb528943e946efc048bf376baccn/a10.0.7.113:59583
2021-10-10 05:24:04a00c4eb528943e946efc048bf376baccn/a10.0.7.113:60210
2021-10-10 05:24:03a00c4eb528943e946efc048bf376baccn/a10.0.7.113:59836
2021-10-10 05:24:01a00c4eb528943e946efc048bf376baccn/a10.0.7.113:59728
2021-10-10 05:23:59a00c4eb528943e946efc048bf376baccn/a217.69.14.192:443
2021-10-10 05:23:59a00c4eb528943e946efc048bf376baccn/a10.0.7.113:59324
2021-10-10 05:23:57a00c4eb528943e946efc048bf376baccn/a10.0.7.113:59897
2021-10-10 05:23:55a00c4eb528943e946efc048bf376baccn/a10.0.7.113:59529
2021-10-10 05:23:54a00c4eb528943e946efc048bf376baccn/a10.0.7.113:59845
2021-10-10 05:23:53a00c4eb528943e946efc048bf376baccn/a10.0.7.113:59311
2021-10-10 05:23:53a00c4eb528943e946efc048bf376baccn/a10.0.7.113:59672
2021-10-10 05:23:53a00c4eb528943e946efc048bf376baccn/a10.0.7.113:59707
2021-10-10 05:23:53a00c4eb528943e946efc048bf376baccn/a10.0.7.113:60289
2021-10-10 05:23:53a00c4eb528943e946efc048bf376baccn/a62.23.104.183:443
2021-10-10 05:23:53a00c4eb528943e946efc048bf376baccn/a10.0.7.113:59284
2021-10-10 05:23:50a00c4eb528943e946efc048bf376baccn/a213.41.41.214:443
2021-10-10 05:23:49a00c4eb528943e946efc048bf376baccn/a10.0.7.113:59797
2021-10-10 05:23:47a00c4eb528943e946efc048bf376baccn/a10.0.7.113:60171
2021-10-10 05:23:44a00c4eb528943e946efc048bf376baccn/a10.0.7.113:59162
2021-10-10 05:23:44a00c4eb528943e946efc048bf376baccn/a167.98.14.226:443
2021-10-10 05:23:43a00c4eb528943e946efc048bf376baccn/a10.0.7.113:60143
2021-10-10 05:23:39a00c4eb528943e946efc048bf376baccn/a10.0.7.113:59150
2021-10-10 05:23:38a00c4eb528943e946efc048bf376baccn/a10.0.7.113:59990
2021-10-10 05:23:37a00c4eb528943e946efc048bf376baccn/a10.0.7.113:60212
2021-10-10 05:23:37a00c4eb528943e946efc048bf376baccn/a10.0.7.113:59769
2021-10-10 05:23:37a00c4eb528943e946efc048bf376baccn/a10.0.7.113:59877
2021-10-10 05:23:37a00c4eb528943e946efc048bf376baccn/a10.0.7.113:59889
2021-10-10 05:23:35a00c4eb528943e946efc048bf376baccn/a10.0.7.113:59346
2021-10-10 05:23:34a00c4eb528943e946efc048bf376baccn/a10.0.7.113:60005
2021-10-10 05:23:32a00c4eb528943e946efc048bf376baccn/a10.0.7.113:59206
2021-10-10 05:23:30a00c4eb528943e946efc048bf376baccn/a10.0.7.113:59267
2021-10-10 05:23:30a00c4eb528943e946efc048bf376baccn/a10.0.7.113:60001
2021-10-10 05:23:28a00c4eb528943e946efc048bf376baccn/a10.0.7.113:59653
2021-10-10 05:23:26a00c4eb528943e946efc048bf376baccn/a151.101.1.204:443
2021-10-10 05:23:26a00c4eb528943e946efc048bf376baccn/a10.0.7.113:60168
2021-10-10 05:23:25a00c4eb528943e946efc048bf376baccn/a10.0.7.113:60490
2021-10-10 05:23:24a00c4eb528943e946efc048bf376baccn/a10.0.7.113:59253
2021-10-10 05:23:24a00c4eb528943e946efc048bf376baccn/a10.0.7.113:60156
2021-10-10 05:23:24a00c4eb528943e946efc048bf376baccn/a10.0.7.113:60250
2021-10-10 05:23:23a00c4eb528943e946efc048bf376baccn/a167.98.14.210:443
2021-10-10 05:23:22a00c4eb528943e946efc048bf376baccn/a10.0.7.113:60238
2021-10-10 05:23:22a00c4eb528943e946efc048bf376baccn/a10.0.7.113:59749
2021-10-10 05:23:19a00c4eb528943e946efc048bf376baccn/a10.0.7.113:59225
2021-10-10 05:23:19a00c4eb528943e946efc048bf376baccn/a10.0.7.113:59646
2021-10-10 05:23:19a00c4eb528943e946efc048bf376baccn/a10.0.7.113:59683
2021-10-10 05:23:18a00c4eb528943e946efc048bf376baccn/a10.0.7.113:60502
2021-10-10 05:23:15a00c4eb528943e946efc048bf376baccn/a10.0.7.113:59493
2021-10-10 05:23:14a00c4eb528943e946efc048bf376baccn/a151.101.2.87:443
2021-10-10 05:23:12a00c4eb528943e946efc048bf376baccn/a10.0.7.113:59238
2021-10-10 05:23:11a00c4eb528943e946efc048bf376baccn/a10.0.7.113:59981
2021-10-10 05:23:10a00c4eb528943e946efc048bf376baccn/a10.0.7.113:60460
2021-07-31 00:26:06edc611d04edc911987d1ff2e069b318eVirustotal results 57 / 70 (81.43%) 65.9.81.89:443
2021-07-31 00:26:06edc611d04edc911987d1ff2e069b318eVirustotal results 57 / 70 (81.43%) 65.9.81.89:443
2021-03-10 04:06:08a857d003e475d574d4e5d8678a6dde99Virustotal results 17 / 69 (24.64%) 10.0.1.77:50260
2021-03-10 04:06:08a857d003e475d574d4e5d8678a6dde99Virustotal results 17 / 69 (24.64%) 10.0.1.77:50205
2021-03-10 04:06:08a857d003e475d574d4e5d8678a6dde99Virustotal results 17 / 69 (24.64%) 10.0.1.77:50220
2021-03-10 04:06:08a857d003e475d574d4e5d8678a6dde99Virustotal results 17 / 69 (24.64%) 10.0.1.77:50180
2021-03-10 04:06:08a857d003e475d574d4e5d8678a6dde99Virustotal results 17 / 69 (24.64%) 157.240.17.174:443
2021-03-10 04:06:08a857d003e475d574d4e5d8678a6dde99Virustotal results 17 / 69 (24.64%) 10.0.1.77:50148
2021-03-10 04:06:08a857d003e475d574d4e5d8678a6dde99Virustotal results 17 / 69 (24.64%) 10.0.1.77:50260
2021-03-10 04:06:08a857d003e475d574d4e5d8678a6dde99Virustotal results 17 / 69 (24.64%) 10.0.1.77:50205
2021-03-10 04:06:08a857d003e475d574d4e5d8678a6dde99Virustotal results 17 / 69 (24.64%) 10.0.1.77:50220
2021-03-10 04:06:08a857d003e475d574d4e5d8678a6dde99Virustotal results 17 / 69 (24.64%) 10.0.1.77:50180
2021-03-10 04:06:08a857d003e475d574d4e5d8678a6dde99Virustotal results 17 / 69 (24.64%) 157.240.17.174:443
2021-03-10 04:06:08a857d003e475d574d4e5d8678a6dde99Virustotal results 17 / 69 (24.64%) 10.0.1.77:50148
2021-03-10 04:06:07a857d003e475d574d4e5d8678a6dde99Virustotal results 17 / 69 (24.64%) 10.0.1.77:50143
2021-03-10 04:06:07a857d003e475d574d4e5d8678a6dde99Virustotal results 17 / 69 (24.64%) 10.0.1.77:50146
2021-03-10 04:06:07a857d003e475d574d4e5d8678a6dde99Virustotal results 17 / 69 (24.64%) 10.0.1.77:50143
2021-03-10 04:06:07a857d003e475d574d4e5d8678a6dde99Virustotal results 17 / 69 (24.64%) 10.0.1.77:50146
2021-03-10 04:06:06a857d003e475d574d4e5d8678a6dde99Virustotal results 17 / 69 (24.64%) 157.240.17.63:443
2021-03-10 04:06:06a857d003e475d574d4e5d8678a6dde99Virustotal results 17 / 69 (24.64%) 10.0.1.77:50156
2021-03-10 04:06:06a857d003e475d574d4e5d8678a6dde99Virustotal results 17 / 69 (24.64%) 10.0.1.77:50339
2021-03-10 04:06:06a857d003e475d574d4e5d8678a6dde99Virustotal results 17 / 69 (24.64%) 157.240.17.63:443
2021-03-10 04:06:06a857d003e475d574d4e5d8678a6dde99Virustotal results 17 / 69 (24.64%) 10.0.1.77:50156

# of entries: 100 (max: 100)