JA3 Fingerprints

You can find further information about the JA3 fingerprint c2b4710c6888a5d47befe865c8e6fb19, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:c2b4710c6888a5d47befe865c8e6fb19
First seen:2018-11-29 20:46:04 UTC
Last seen:2021-08-03 23:37:22 UTC
Status:Blacklisted
Malware samples:808
Destination IPs:132
Malware:Tofsee -
Listing date:2020-01-09 14:32:01

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2023-01-23 22:49:41aa78a35499fbe10334dcbd371f4b288fVirustotal results 45 / 70 (64.29%) 157.240.17.63:443
2023-01-23 07:44:055d258bff39eca5c6dc8a5c173546bd9dn/a157.240.11.52:443
2023-01-23 07:44:045d258bff39eca5c6dc8a5c173546bd9dn/a157.240.11.174:443
2023-01-09 10:20:248c6360af7f35502f8bfc3318a87c45a8n/a157.240.17.174:443
2023-01-09 07:19:592e40b706f95e6b545a19a7cb3b7f4e35Virustotal results 39 / 70 (55.71%) 157.240.17.63:443
2023-01-08 20:33:08e0636552609050d1ac2aa6aaaed44b22n/a157.240.17.174:443
2023-01-08 12:22:54fd6a2a7f0012647c1f7bc7ac7b89ce47Virustotal results 38 / 71 (53.52%) 157.240.17.63:443
2023-01-07 09:06:3412fcb597175811b0479808913f2f6bcfn/a157.240.17.63:443
2023-01-06 16:14:5174f8a1cdabfa14dcd06ca2d7d65d5d8cn/a185.60.216.52:443
2023-01-06 16:14:5074f8a1cdabfa14dcd06ca2d7d65d5d8cn/a157.240.20.174:443
2023-01-06 14:10:365cfa722238eb5bb8856cec294d882f48n/a157.240.17.174:443
2023-01-06 03:06:5705875193989334d02e3da24da28cfdffVirustotal results 53 / 71 (74.65%) 157.240.17.63:443
2023-01-02 17:58:49178ec5c69487d901011930bc9275af1fVirustotal results 56 / 71 (78.87%) 157.240.17.63:443
2023-01-01 15:34:13b8f175055e1c4bb1e5dbfed26fffb3fdn/a157.240.247.174:443
2022-12-24 20:29:14a81e5141ccf1c7bd6ba7646047b8a1f9Virustotal results 34 / 68 (50.00%) 157.240.17.63:443
2022-12-20 15:15:126af09adb9d9276847a4d623f0223d092n/a157.240.22.63:443
2022-12-03 06:45:2865c2af524c0d9304509187a25c1e3b02n/a157.240.11.52:443
2022-11-26 14:36:196823a108f80b535231ed71f4ff7cb3c7n/a157.240.17.174:443
2022-11-23 01:41:241d6f14f7ac1d5995c088a1fa9f8566cdVirustotal results 49 / 70 (70.00%) 157.240.17.63:443
2022-11-23 01:41:241d6f14f7ac1d5995c088a1fa9f8566cdVirustotal results 49 / 70 (70.00%) 157.240.17.174:443
2022-11-22 21:31:14776285cfda8920255128c6977b3ddc91n/a157.240.17.174:443
2022-11-21 04:24:5065020c8c80c54153ce386ff5e5e5c734n/a157.240.247.63:443
2022-11-17 07:00:054722a4ec1cb83ee2bc7aa46667a93e5bVirustotal results 26 / 71 (36.62%) 157.240.17.174:443
2022-11-16 06:50:03ba22945c63f35174ae8ac4615b8f6cfdn/a157.240.201.63:443
2022-11-12 00:47:469522f6a6968f9505bf75617ca5adb28en/a157.240.20.63:443
2022-11-03 20:51:433705386cd7326733384d5fd6e8f3fcdan/a157.240.17.174:443
2022-11-03 06:00:186269c18fc29b70fa742d48e7c38283e7n/a157.240.17.63:443
2022-11-03 03:39:4555ea6bbf837a447ba4f99bc2087f84d5n/a157.240.17.63:443
2022-11-02 23:41:13000fccc5a331ddd85e58a3b8f6fdd871n/a157.240.17.63:443
2022-11-02 19:51:443950d84bcd3c4ed6b96a41d46737fd4en/a157.240.17.174:443
2022-10-29 00:16:043427a69e05fbe98e36b2eafc9a48a90cVirustotal results 36 / 71 (50.70%) 10.0.7.101:53765
2022-10-29 00:14:223427a69e05fbe98e36b2eafc9a48a90cVirustotal results 36 / 71 (50.70%) 193.246.8.82:443
2022-10-29 00:14:013427a69e05fbe98e36b2eafc9a48a90cVirustotal results 36 / 71 (50.70%) 10.0.7.101:53733
2022-10-29 00:13:373427a69e05fbe98e36b2eafc9a48a90cVirustotal results 36 / 71 (50.70%) 10.0.7.101:53691
2022-10-27 10:26:246a4a18a6bc3f69d765f3f858c275c4b8n/a157.240.17.63:443
2022-10-23 07:13:27997c68d58288f380989c37b68ee81074Virustotal results 27 / 72 (37.50%) 157.240.11.174:443
2022-10-22 03:59:27b47be847e2687e674c9eb8037b84a03fn/a157.240.201.63:443
2022-10-21 19:34:57f823c3617733486da4d4b770aef17367n/a157.240.247.174:443
2022-10-21 19:34:57f823c3617733486da4d4b770aef17367n/a157.240.247.63:443
2022-10-21 12:31:400b00b0081a2473a74c7d74642add9797n/a157.240.17.63:443
2022-10-16 09:29:174327af18e0c857a3a2db124fb68cf4ban/a157.240.201.63:443
2022-10-16 09:29:164327af18e0c857a3a2db124fb68cf4ban/a157.240.201.174:443
2022-10-16 00:29:052f74526c9362e0d006ad9f7d1da6d79cVirustotal results 53 / 72 (73.61%) 157.240.17.63:443
2022-10-15 01:04:401c886466ca3ca9c60539af6f8e201158Virustotal results 48 / 72 (66.67%) 157.240.17.63:443
2022-10-10 18:02:101db2442a2b7e287e358759433dd68616Virustotal results 52 / 72 (72.22%) 157.240.201.63:443
2022-10-10 18:02:091db2442a2b7e287e358759433dd68616Virustotal results 52 / 72 (72.22%) 157.240.247.174:443
2022-10-10 18:02:091db2442a2b7e287e358759433dd68616Virustotal results 52 / 72 (72.22%) 157.240.247.63:443
2022-10-05 23:44:08214d700e020f936d92c6f90cf3afc456n/a157.240.17.63:443
2022-10-05 23:44:08214d700e020f936d92c6f90cf3afc456n/a157.240.17.174:443
2022-10-01 08:38:14bacd72506ebc8f36e8b15853321f9c97n/a157.240.247.174:443
2022-10-01 08:38:13bacd72506ebc8f36e8b15853321f9c97n/a157.240.247.63:443
2022-10-01 08:38:13bacd72506ebc8f36e8b15853321f9c97n/a157.240.201.63:443
2022-10-01 07:04:47a08fdde20f364ecd233811de34f10743n/a157.240.11.52:443
2022-10-01 07:04:47a08fdde20f364ecd233811de34f10743n/a157.240.22.63:443
2022-10-01 07:04:47a08fdde20f364ecd233811de34f10743n/a157.240.11.174:443
2022-09-30 21:12:186178806000823df68fc03b6dd53acce4n/a157.240.247.174:443
2022-09-30 21:12:186178806000823df68fc03b6dd53acce4n/a157.240.247.63:443
2022-09-30 21:12:176178806000823df68fc03b6dd53acce4n/a157.240.201.63:443
2022-09-28 19:09:440c3cdcf59c019f52e50f1b66b79e24e4Virustotal results 46 / 72 (63.89%) 157.240.20.63:443
2022-09-28 12:06:08d9607a714fc963c22caf53d3f9e85399n/a157.240.17.174:443
2022-09-28 12:06:07d9607a714fc963c22caf53d3f9e85399n/a157.240.17.63:443
2022-09-28 07:47:569b2ee55e8a6131b0d8a846f858aa59a2n/a157.240.20.63:443
2022-09-25 08:34:36c1e908ebf1f56a413ab4fdc29cbb8a89n/a157.240.17.174:443
2022-09-25 08:34:36c1e908ebf1f56a413ab4fdc29cbb8a89n/a157.240.17.63:443
2022-09-25 06:37:142e636c990dc2d04cc549d783da6f462en/a157.240.247.63:443
2022-09-25 06:37:142e636c990dc2d04cc549d783da6f462en/a157.240.247.63:443
2022-09-24 20:47:4204ddb9f876b3fa3956748135b50d7a9dVirustotal results 30 / 72 (41.67%) 157.240.247.63:443
2022-09-24 20:47:4104ddb9f876b3fa3956748135b50d7a9dVirustotal results 30 / 72 (41.67%) 157.240.247.174:443
2022-09-24 20:47:4104ddb9f876b3fa3956748135b50d7a9dVirustotal results 30 / 72 (41.67%) 157.240.201.63:443
2022-09-24 14:34:42805daf89461f2abf32affa17c008e9fan/a157.240.247.63:443
2022-09-24 03:58:57347244f6ce9649affe64f73867dc46f3n/a157.240.17.63:443
2022-09-24 00:42:417eb110930c7539343579fe9af633a5e9n/a157.240.17.63:443
2022-09-23 18:05:25861443b288eb50cf2e48462bbec4ad7en/a31.13.70.52:443
2022-09-23 18:05:25861443b288eb50cf2e48462bbec4ad7en/a157.240.11.52:443
2022-09-23 17:19:031ebb8f0fe31ce05c05069af0260a6772n/a157.240.17.63:443
2022-09-23 17:19:021ebb8f0fe31ce05c05069af0260a6772n/a157.240.17.174:443
2022-09-23 13:54:08d80f17936441b4f0cb24509fc8fe36c8n/a157.240.17.63:443
2022-09-23 06:13:2232c17571000e5e62e6427e72f30ae903n/a157.240.247.174:443
2022-09-23 06:13:2132c17571000e5e62e6427e72f30ae903n/a157.240.247.63:443
2022-09-23 06:13:2132c17571000e5e62e6427e72f30ae903n/a157.240.201.63:443
2022-09-23 06:12:034ae34c82169c259eca08f15555283fcbn/a157.240.17.63:443
2022-09-22 22:07:32a88fdfc984009f101e1c4989da66c8ffn/a157.240.247.63:443
2022-09-22 01:39:2859b0d588c8e25756c585842bf6e8343bn/a188.114.97.7:443
2022-09-22 01:39:2859b0d588c8e25756c585842bf6e8343bn/a188.114.96.7:443
2022-09-20 20:48:4823220a01161c3fb7ed5546994a8a8bbdn/a157.240.17.63:443
2022-09-18 15:25:41321172d51354b6b20517885ac5088f70Virustotal results 52 / 70 (74.29%) 157.240.17.63:443
2022-09-17 03:08:3107a966ac3117981a77c82828bdb650e2Virustotal results 55 / 71 (77.46%) 157.240.234.63:443
2022-09-15 01:43:12fb7cb93ba80b72c5ec801c8acefc22f8n/a157.240.247.174:443
2022-09-15 01:43:11fb7cb93ba80b72c5ec801c8acefc22f8n/a157.240.201.63:443
2022-09-15 01:43:11fb7cb93ba80b72c5ec801c8acefc22f8n/a157.240.247.63:443
2022-09-13 12:05:2863e8f08d6e633ab1d3442b896ccd428cVirustotal results 29 / 69 (42.03%) 157.240.17.174:443
2022-09-13 12:05:2763e8f08d6e633ab1d3442b896ccd428cVirustotal results 29 / 69 (42.03%) 157.240.17.63:443
2022-09-12 23:51:33cdbacfb335fbfab78000bc7828609259n/a157.240.17.174:443
2022-09-12 23:51:32cdbacfb335fbfab78000bc7828609259n/a157.240.17.63:443
2022-09-12 16:33:20401d38890fe0a833ebaf7dfc115a2f6en/a157.240.17.174:443
2022-09-04 14:45:05a5f6a903bba3a68de54ac476f36cf420n/a157.240.17.63:443
2022-09-04 08:38:229c0ad603a072cf69d3617a3de1d22a9bn/a157.240.17.63:443
2022-09-03 03:26:1617d6a4f1352227d97b4093e3303aae46Virustotal results 26 / 69 (37.68%) 157.240.17.63:443
2022-08-18 13:13:3656d59989d850974126ea10d62c4d1d42n/a157.240.17.63:443
2022-08-18 13:13:3656d59989d850974126ea10d62c4d1d42n/a157.240.17.174:443

# of entries: 100 (max: 100)