JA3 Fingerprints

You can find further information about the JA3 fingerprint c2b4710c6888a5d47befe865c8e6fb19, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:c2b4710c6888a5d47befe865c8e6fb19
First seen:2018-11-29 20:46:04 UTC
Last seen:2021-08-03 23:37:22 UTC
Status:Blacklisted
Malware samples:707
Destination IPs:123
Malware:Tofsee -
Listing date:2020-01-09 14:32:01

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2022-07-03 18:56:18be17913986a009c5d70c3ed6f3e0651cn/a157.240.17.174:443
2022-07-03 18:56:18be17913986a009c5d70c3ed6f3e0651cn/a157.240.17.63:443
2022-06-24 08:57:20de35fe789be6f86d5fb86f8a9683fbean/a157.240.201.63:443
2022-06-24 03:59:23ce4af8a7b76b443b75090bb1d1cb4e2dn/a157.240.17.174:443
2022-06-23 19:53:2774156bd4dfc57bbd58ca39b9aec8e8d9n/a157.240.17.63:443
2022-06-23 19:53:2674156bd4dfc57bbd58ca39b9aec8e8d9n/a157.240.17.174:443
2022-06-23 19:46:28705b398887e5dd27f1716d85efe01a7an/a157.240.17.63:443
2022-06-22 17:46:56abb655097c3c474f959cc4f65fd8d0a8n/a157.240.17.63:443
2022-06-20 16:06:13b440d803ab42f31567a4d4d61aa4ef94n/a31.13.64.174:443
2022-06-20 16:06:13b440d803ab42f31567a4d4d61aa4ef94n/a31.13.64.52:443
2022-06-20 16:06:12b440d803ab42f31567a4d4d61aa4ef94n/a157.240.201.63:443
2022-06-20 10:19:388c59fd44034638f1bb8faf8e176f9957n/a157.240.17.63:443
2022-06-18 07:19:398cf0e344bd5225c5c5056ec2ba929c34n/a157.240.17.63:443
2022-06-18 00:50:337d3af8674dca52d59b6fec1332d76060n/a157.240.201.63:443
2022-06-18 00:50:337d3af8674dca52d59b6fec1332d76060n/a157.240.201.174:443
2022-06-18 00:50:337d3af8674dca52d59b6fec1332d76060n/a31.13.64.52:443
2022-06-17 21:03:31673cdd67804f7fc5c3000c2673a4ac32n/a31.13.64.52:443
2022-06-17 21:03:31673cdd67804f7fc5c3000c2673a4ac32n/a157.240.201.63:443
2022-06-17 18:46:45201efae19978e8b9d7f89516571c8bf5Virustotal results 45 / 68 (66.18%) 31.13.64.52:443
2022-06-17 18:46:44201efae19978e8b9d7f89516571c8bf5Virustotal results 45 / 68 (66.18%) 31.13.64.174:443
2022-06-17 18:46:43201efae19978e8b9d7f89516571c8bf5Virustotal results 45 / 68 (66.18%) 157.240.201.63:443
2022-06-17 16:30:5171e69e2719d9a503abe125744a05cc8bn/a157.240.201.63:443
2022-06-15 23:31:431fd9c5e36b2823c986961603cdbcc3d2Virustotal results 51 / 66 (77.27%) 31.13.64.52:443
2022-06-15 15:54:31b36acc5c9eeb85172b6a2b7825669e44n/a157.240.20.63:443
2022-06-15 12:27:10e8cf8e8ea7c46ccf00fea85c09f72da5n/a185.60.216.174:443
2022-06-15 12:27:10e8cf8e8ea7c46ccf00fea85c09f72da5n/a185.60.216.52:443
2022-06-15 08:22:21485a4b456f85b2358376f40d0e612604n/a157.240.17.63:443
2022-06-14 01:38:5322b0833fc700846f3d6890497dc814b1n/a157.240.17.63:443
2022-06-14 01:38:5322b0833fc700846f3d6890497dc814b1n/a157.240.17.174:443
2022-06-10 04:04:28094df154a1e5e24e8faa8b5e077538f5Virustotal results 45 / 67 (67.16%) 157.240.20.63:443
2022-06-08 14:38:38bfa361f2d536220bdf5357500524c679n/a157.240.17.174:443
2022-06-08 14:38:37bfa361f2d536220bdf5357500524c679n/a157.240.9.52:443
2022-06-08 14:38:37bfa361f2d536220bdf5357500524c679n/a157.240.17.63:443
2022-06-08 12:20:5106ff7e78ae32d46bafde64407ae27ae5n/a185.60.217.63:443
2022-06-08 12:20:5106ff7e78ae32d46bafde64407ae27ae5n/a157.240.201.63:443
2022-06-08 12:20:5006ff7e78ae32d46bafde64407ae27ae5n/a185.60.217.174:443
2022-06-08 07:51:48b34995bca58a9d0c5a5d10f3910b3551n/a157.240.17.174:443
2022-06-08 07:51:47b34995bca58a9d0c5a5d10f3910b3551n/a157.240.17.63:443
2022-06-08 00:28:54ce02925be9f4e6559b15a37552b44c35n/a157.240.17.174:443
2022-06-08 00:28:53ce02925be9f4e6559b15a37552b44c35n/a157.240.17.63:443
2022-06-06 13:32:1195f3396965c2a0f54303f2abaaeae9dfn/a157.240.22.63:443
2022-06-06 13:32:1095f3396965c2a0f54303f2abaaeae9dfn/a157.240.11.52:443
2022-06-06 13:32:1095f3396965c2a0f54303f2abaaeae9dfn/a31.13.70.52:443
2022-06-06 13:32:1095f3396965c2a0f54303f2abaaeae9dfn/a157.240.11.174:443
2022-06-06 09:48:42de9efe710505ba1c853be385bd87bcaen/a157.240.17.63:443
2022-06-06 09:07:14075f14a07e17015cf2a0285518ada2cen/a185.60.217.63:443
2022-06-06 07:45:004c515811474bc9bebf889099cde0329en/a157.240.201.63:443
2022-06-06 07:45:004c515811474bc9bebf889099cde0329en/a185.60.217.174:443
2022-06-05 20:05:585c91bd85be127a0522ea8d24e857c675n/a185.60.217.63:443
2022-06-05 19:57:29f4358961b07728cc44078646e18d5b6en/a157.240.17.174:443
2022-06-05 19:57:29f4358961b07728cc44078646e18d5b6en/a157.240.17.63:443
2022-06-05 19:27:56573b4d1509a8e28f3c823538332f9cd1n/a185.60.216.52:443
2022-06-05 19:22:029dd923205102d1b2d4da4b597e2a4eden/a157.240.17.174:443
2022-06-05 17:36:00bb54de735eff65757844c79d281b7770n/a157.240.201.63:443
2022-06-05 17:24:07db5abfda5854f17939b12a13b6accecfn/a157.240.17.63:443
2022-06-05 16:33:43b20cf306a1e5f6ada69f9ce5f7a7dd53n/a157.240.17.174:443
2022-06-05 16:33:43b20cf306a1e5f6ada69f9ce5f7a7dd53n/a157.240.17.63:443
2022-06-05 14:41:17b65fb494d21769da9e884d103b986c0dn/a157.240.17.63:443
2022-06-05 08:47:176315298cc85b7da39e36b6332c73b399n/a31.13.72.53:443
2022-06-05 08:14:395744b2adddfd9ef7d143291a8f78e555n/a185.60.216.52:443
2022-06-05 03:58:310a16f5fe48660f453da4d32664390477n/a157.240.17.174:443
2022-06-05 03:58:310a16f5fe48660f453da4d32664390477n/a157.240.17.63:443
2022-06-05 03:24:01b50f0dc5c7ee3c652ee02fa51d54ad12n/a157.240.17.63:443
2022-06-05 03:16:16bf8a485fd480e084cfce08870bdf6e9an/a185.60.216.52:443
2022-06-05 03:16:16bf8a485fd480e084cfce08870bdf6e9an/a157.240.20.63:443
2022-06-05 01:32:02a1f56bfecb723eaaf37e244883fd9894n/a157.240.17.63:443
2022-06-05 01:32:02a1f56bfecb723eaaf37e244883fd9894n/a157.240.234.63:443
2022-06-05 01:32:02a1f56bfecb723eaaf37e244883fd9894n/a157.240.17.174:443
2022-06-05 00:23:47bc19fc1e49f0db01cd4fe4697b67d99fn/a157.240.17.63:443
2022-06-04 18:09:130dbf6d3cc1a2af87d384ba6a74c93777n/a157.240.17.63:443
2022-06-04 15:24:40e29178c6e374ba449a1548d88e07b442n/a157.240.22.63:443
2022-06-04 15:24:39e29178c6e374ba449a1548d88e07b442n/a157.240.11.52:443
2022-06-04 07:24:56abd47dec914ceaf7a1d1232e3c6c2fa9n/a157.240.17.63:443
2022-06-04 06:50:084752740c5fa838faf4a7b8f9bd0d5e49n/a157.240.17.63:443
2022-06-01 20:19:57b31c800f052563742a34094ec79d9bc4Virustotal results 48 / 69 (69.57%) 157.240.17.63:443
2022-05-31 04:52:541eab4e27ec9267573eb3948ea576376cn/a157.240.17.63:443
2022-05-30 23:27:234aa9042a654f07a303f42c080607e323n/a157.240.17.63:443
2022-05-30 19:03:47b9d8dfc3962018552884c94d7a12f294n/a31.13.64.52:443
2022-05-30 18:11:39066d530fe2c387eed7489c03bc58a3e5n/a31.13.64.52:443
2022-05-30 12:52:21b63ac936bbef858be13da67293e7d418n/a157.240.20.63:443
2022-05-30 12:52:21b63ac936bbef858be13da67293e7d418n/a185.60.216.52:443
2022-05-30 11:38:364f2915e558bdabfba07732f8d782396bn/a157.240.20.63:443
2022-05-30 06:41:12b9d8c7998cd2a77f54075af3b71ddd2bn/a157.240.17.63:443
2022-05-30 06:41:12b9d8c7998cd2a77f54075af3b71ddd2bn/a157.240.9.52:443
2022-05-29 22:09:3691d7962ab9876f249517a49d7629aa6bn/a157.240.17.63:443
2022-05-29 18:36:038ecbad7f6f7bcdd0efee75004a57f6fbVirustotal results 49 / 66 (74.24%) 157.240.22.63:443
2022-05-29 18:36:028ecbad7f6f7bcdd0efee75004a57f6fbVirustotal results 49 / 66 (74.24%) 157.240.11.52:443
2022-05-29 15:18:4108b5d39e5ad4974c93408d3cddcceb51Virustotal results 45 / 65 (69.23%) 157.240.229.63:443
2022-05-29 15:18:4008b5d39e5ad4974c93408d3cddcceb51Virustotal results 45 / 65 (69.23%) 157.240.11.52:443
2022-05-29 15:18:4008b5d39e5ad4974c93408d3cddcceb51Virustotal results 45 / 65 (69.23%) 31.13.70.52:443
2022-05-28 19:37:366971814ed5f60448ff85775c446d0d17n/a31.13.64.52:443
2022-05-28 16:31:55280d1dda83ad63e82651635e32f7dc02Virustotal results 44 / 69 (63.77%) 157.240.17.63:443
2022-05-28 12:59:198282eea637cec1272e5dafa3c6082b64n/a157.240.17.63:443
2022-05-26 23:16:0354585d79bc6462601d0f1c084b25bb09n/a31.13.64.52:443
2022-05-26 21:05:13193ebec2cebbe5172bb8e7f96daa0a39Virustotal results 54 / 69 (78.26%) 157.240.17.63:443
2022-05-26 19:44:140c1bcd4bf9fe3306b328638af78783ccn/a31.13.64.52:443
2022-05-24 21:14:379bd0ebc979a682a9e529b47198af85a0n/a157.240.17.63:443
2022-05-24 20:40:437d69e685d74fd3002180a47265dc639en/a31.13.64.52:443
2022-05-22 15:27:570bca159f40cc306403a895b8fe3a7630n/a157.240.17.63:443
2022-05-20 18:58:52b6d2060e0ad76c4804c156dc92a0752bn/a157.240.17.63:443

# of entries: 100 (max: 100)