JA3 Fingerprints

You can find further information about the JA3 fingerprint c0220cd64849a629397a9cb68f78a0ea, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:c0220cd64849a629397a9cb68f78a0ea
First seen:2019-03-24 00:12:32 UTC
Last seen:2020-08-16 06:14:38 UTC
Status:Blacklisted
Malware samples:281
Destination IPs:98
Malware:Tofsee -
Listing date:2020-01-09 14:28:36

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2020-08-16 06:14:38c3f5fac3f6a6392fcb8ce582a878d253Virustotal results 5 / 73 (6.85%) 64.233.184.206:8883
2020-08-13 07:32:221551b94290e7226b70470361368f5447Virustotal results 27 / 72 (37.50%) 142.93.108.123:443
2020-05-30 05:21:327a3f4ff5f17743604dbcbf9b0fa69626Virustotal results 24 / 73 (32.88%) 104.16.9.28:443
2020-05-30 05:21:307a3f4ff5f17743604dbcbf9b0fa69626Virustotal results 24 / 73 (32.88%) 35.167.134.89:443
2020-05-12 09:37:011884bd28c4990aa12f9e38416c30bd08n/a104.16.9.28:443
2020-05-10 07:04:262cbb35246e6605512d1822a768737b81Virustotal results 47 / 72 (65.28%) 172.217.168.196:443
2020-05-10 07:04:252cbb35246e6605512d1822a768737b81Virustotal results 47 / 72 (65.28%) 172.217.17.68:443
2020-05-10 00:05:541bff813f2f5b943dd3406d76f50d5719Virustotal results 34 / 73 (46.58%) 172.217.22.4:443
2020-05-10 00:05:531bff813f2f5b943dd3406d76f50d5719Virustotal results 34 / 73 (46.58%) 216.58.205.228:443
2020-05-09 21:53:3518324db8521654ac4af49bcba5b40521n/a172.217.168.196:443
2020-04-25 00:40:08979f34daa90f43a57a8460870ea116ceVirustotal results 28 / 72 (38.89%) 13.227.216.77:443
2020-04-21 17:08:52125c8c1bfe684223c36f5258b7aadbf4Virustotal results 41 / 72 (56.94%) 104.22.63.174:443
2020-04-21 17:08:41125c8c1bfe684223c36f5258b7aadbf4Virustotal results 41 / 72 (56.94%) 104.20.80.155:443
2020-04-21 17:08:41125c8c1bfe684223c36f5258b7aadbf4Virustotal results 41 / 72 (56.94%) 172.217.9.142:443
2020-04-21 17:08:29125c8c1bfe684223c36f5258b7aadbf4Virustotal results 41 / 72 (56.94%) 13.226.251.76:443
2020-04-17 11:57:5824e73f0a7e20914be81a030feafe06e4Virustotal results 17 / 72 (23.61%) 23.43.120.119:443
2020-03-26 11:35:56999dc6eef21218ed7c3fbb3bbb920052Virustotal results 35 / 73 (47.95%) 172.217.168.238:443
2020-03-21 06:04:18a4bf21a69fb30c57ec8688cbd7e3cf89Virustotal results 54 / 73 (73.97%) 104.78.177.246:443
2020-03-21 06:04:18a4bf21a69fb30c57ec8688cbd7e3cf89Virustotal results 54 / 73 (73.97%) 104.78.177.63:443
2020-03-21 06:04:16a4bf21a69fb30c57ec8688cbd7e3cf89Virustotal results 54 / 73 (73.97%) 96.16.108.7:443
2020-03-19 21:25:47a990bfa906c958fd3e735278ef046e41Virustotal results 54 / 73 (73.97%) 151.101.114.49:443
2020-03-19 21:25:46a990bfa906c958fd3e735278ef046e41Virustotal results 54 / 73 (73.97%) 184.25.218.6:443
2020-03-19 21:25:46a990bfa906c958fd3e735278ef046e41Virustotal results 54 / 73 (73.97%) 104.22.62.174:443
2020-03-19 21:25:46a990bfa906c958fd3e735278ef046e41Virustotal results 54 / 73 (73.97%) 151.101.114.133:443
2020-03-19 21:25:45a990bfa906c958fd3e735278ef046e41Virustotal results 54 / 73 (73.97%) 2.16.181.146:443
2020-03-13 14:32:426d4e4e5a5f547bc0920e4b1bda9de34eVirustotal results 58 / 72 (80.56%) 96.16.108.7:443
2020-03-13 14:32:416d4e4e5a5f547bc0920e4b1bda9de34eVirustotal results 58 / 72 (80.56%) 104.78.177.246:443
2020-03-13 14:32:406d4e4e5a5f547bc0920e4b1bda9de34eVirustotal results 58 / 72 (80.56%) 104.78.177.63:443
2020-03-07 19:04:48249e052b738ab40f0e9a1f9723da6761Virustotal results 54 / 72 (75.00%) 23.227.38.64:443
2020-03-06 19:46:0646c564d7bf821027725ac57fe9038526Virustotal results 34 / 72 (47.22%) 216.58.215.238:443
2020-03-04 09:52:397f500fd53344df1736b41e5a5b2f5827n/a92.122.200.67:443
2020-03-03 08:36:53c813b2ffcb21e12dd800f66c26845fceVirustotal results 54 / 72 (75.00%) 23.57.80.6:443
2020-03-03 08:36:51c813b2ffcb21e12dd800f66c26845fceVirustotal results 54 / 72 (75.00%) 104.80.21.166:443
2020-03-03 08:25:0308c59260ed9afff63d6a2df67c0473ddVirustotal results 54 / 72 (75.00%) 23.57.80.6:443
2020-03-03 08:25:0308c59260ed9afff63d6a2df67c0473ddVirustotal results 54 / 72 (75.00%) 104.80.21.166:443
2020-03-03 08:17:11cd7c4eb5bb984cc22b0c10426049a064n/a104.80.21.166:443
2020-03-03 07:53:067517c69dbcb8225720640f178d2ed421n/a23.57.80.6:443
2020-03-03 07:53:067517c69dbcb8225720640f178d2ed421n/a104.80.21.166:443
2020-02-29 04:03:00f4a8a9906a9e3b13855969b5d406b35dn/a104.80.23.97:443
2020-02-27 22:20:36b968747be8f91b8951b8b96f9f181555n/a104.80.21.166:443
2020-02-27 22:20:36b968747be8f91b8951b8b96f9f181555n/a23.57.80.6:443
2020-02-26 14:12:10bb69ec7270f3535579b342b7514139f4n/a92.122.200.67:443
2020-02-24 15:02:09e914fb98bc6c4d1e6c9fddb335bfbd55n/a104.80.21.166:443
2020-02-24 12:12:05b937831b4c6a0183e64d23a85cf879deVirustotal results 59 / 73 (80.82%) 104.80.21.166:443
2020-02-24 10:53:27a6bb0d10940b351b75f000676fa74a8bn/a104.80.21.166:443
2020-02-24 10:53:27a6bb0d10940b351b75f000676fa74a8bn/a104.80.23.97:443
2020-02-24 10:53:26a6bb0d10940b351b75f000676fa74a8bn/a23.57.80.6:443
2020-02-23 14:13:25afd92d17232d25be248341370588ebean/a23.57.80.6:443
2020-02-23 07:45:5432286ed8b4f02ea2288c05c534f07239n/a104.80.23.97:443
2020-02-23 07:45:5432286ed8b4f02ea2288c05c534f07239n/a23.57.80.6:443
2020-02-22 20:51:006b7370b89086982cd572d62bf4af5348n/a96.16.108.7:443
2020-02-22 20:47:06fd11dda2b5163c08cdde56845e83be24n/a96.16.108.7:443
2020-02-22 20:36:19d7fbd8f5b20f242482993ba69c9a9d2dn/a104.78.177.246:443
2020-02-22 20:29:50444c5243fc4da6ac0ced7944f8710aa2n/a104.78.177.246:443
2020-02-22 20:29:49444c5243fc4da6ac0ced7944f8710aa2n/a104.78.177.63:443
2020-02-22 20:29:49444c5243fc4da6ac0ced7944f8710aa2n/a96.16.108.7:443
2020-02-20 15:15:59b4db3a17d42526854c6c0f1166e05c0en/a104.78.177.246:443
2020-02-20 12:21:11a74be7e3bee055570dbf3bdaca514f68n/a104.78.177.246:443
2020-02-20 11:57:22b05b26fca78ff0044d3679c709f56181n/a104.78.177.63:443
2020-02-20 09:07:57bc7e159bd32ae48b798b1956e6cbec36n/a92.122.150.68:443
2020-02-20 06:31:04373246d064f42d4bc96a016174a88eacn/a104.106.196.30:443
2020-02-20 06:25:078944e4b7a97d0f0eb1cd70e9adbe10fcn/a92.122.150.68:443
2020-02-20 06:22:1801ecf9355254dc8c0c1fad330298fc88n/a104.106.196.30:443
2020-02-20 06:12:58ea2e8ed5310836654a9980b3321ddaa2n/a104.106.196.30:443
2020-02-20 06:11:348fbfc57b871d810af65b320a9e0b2a66n/a104.106.196.30:443
2020-02-20 06:11:348fbfc57b871d810af65b320a9e0b2a66n/a92.122.150.68:443
2020-02-20 06:02:06ee755a06186f44f6980120ea196190can/a92.122.150.68:443
2020-02-19 23:49:09aa2520df2b8def5d60b9bce325b2aba3n/a104.78.177.63:443
2020-02-19 16:52:5440500ea8db567ea7c44e5489b1a25961n/a96.16.108.7:443
2020-02-19 16:52:5440500ea8db567ea7c44e5489b1a25961n/a104.78.177.246:443
2020-02-19 09:33:58bb54d0dd72b6cf9d4cd4be7c5e5fdf01n/a96.16.108.7:443
2020-02-18 19:28:23c37ca5fe9f99386f6d498b2114bc3670n/a104.78.177.63:443
2020-02-18 19:28:23c37ca5fe9f99386f6d498b2114bc3670n/a104.78.177.246:443
2020-02-18 10:32:51522780ebf61301eea85ba86de0d7e131n/a104.78.177.63:443
2020-02-18 10:25:240f89fc6f45048ad904b6a1c721e28019n/a104.78.177.63:443
2020-02-18 10:16:5334cf2b9339709c87f3b88f3835e72375n/a96.16.108.7:443
2020-02-18 10:16:5134cf2b9339709c87f3b88f3835e72375n/a104.78.177.63:443
2020-02-18 10:16:17feabcc4ec27833fb19d3dc546945884bn/a104.78.177.63:443
2020-02-18 09:40:28e5c24f48a4ce4a4bc0f13b5ab243ec96n/a96.16.108.7:443
2020-02-18 09:36:147219855ad6ef3a36802fa494c7d76e14n/a104.78.177.63:443
2020-02-18 09:36:137219855ad6ef3a36802fa494c7d76e14n/a104.78.177.246:443
2020-02-18 09:36:137219855ad6ef3a36802fa494c7d76e14n/a96.16.108.7:443
2020-02-18 09:26:46963672a7a271b334cbf2860607f5c115n/a104.78.177.246:443
2020-02-18 09:26:46963672a7a271b334cbf2860607f5c115n/a96.16.108.7:443
2020-02-17 14:54:37130c8bd24889b7cd12b0394b52e30a81Virustotal results 31 / 72 (43.06%) 104.109.250.133:443
2020-02-17 14:54:36130c8bd24889b7cd12b0394b52e30a81Virustotal results 31 / 72 (43.06%) 104.18.27.108:443
2020-02-17 08:19:31b4f9df0b02d8094cacecba3afdbc5d31n/a104.78.177.63:443
2020-02-17 08:19:30b4f9df0b02d8094cacecba3afdbc5d31n/a96.16.108.7:443
2020-02-17 06:08:21b2dabd3cb7faae949bb8fecedf4946f4n/a96.16.108.7:443
2020-02-16 14:34:35917338f134a2d0d3bc37b45127aba8e3n/a96.16.108.7:443
2020-02-16 14:34:35917338f134a2d0d3bc37b45127aba8e3n/a104.78.177.246:443
2020-02-16 08:31:12d2c6f4852cece029ee071140cd7b05cen/a104.78.177.63:443
2020-02-16 06:44:53a88196443dea556a1e98b3e796e7662fn/a104.78.177.246:443
2020-02-15 13:56:3390a7d0d484f633e2a78fd18e05c42fa6n/a96.16.108.7:443
2020-02-15 11:26:251936b8b40e3921c996c4dbfa7310e460n/a96.16.108.7:443
2020-02-15 11:26:241936b8b40e3921c996c4dbfa7310e460n/a104.78.177.246:443
2020-02-07 09:50:27bdcf0b98628fbd22d5a9f9c16e449d78Virustotal results 37 / 71 (52.11%) 104.78.177.246:443
2020-02-04 22:04:58b35afd074427f4d202179d9118b323f5Virustotal results 24 / 72 (33.33%) 96.16.108.7:443
2020-01-30 14:08:079fba7fab4b09c77cd22e97b12e2a9538n/a104.80.23.97:443
2020-01-30 11:07:20ae3158f1242a91049332358fb32274e0Virustotal results 37 / 71 (52.11%) 2.21.36.249:443

# of entries: 100 (max: 100)