JA3 Fingerprints

You can find further information about the JA3 fingerprint c5deb9465d47232dd48772f9c4d14679, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:c5deb9465d47232dd48772f9c4d14679
First seen:2018-03-22 15:42:48 UTC
Last seen:2020-04-01 11:21:09 UTC
Status:Blacklisted
Malware samples:524
Destination IPs:157
Malware:Tofsee -
Listing date:2020-01-09 14:24:44

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2020-04-01 11:21:091e0ddfa782e3331c71c69a4f8657b6c1Virustotal results 21 / 72 (29.17%) 212.82.100.140:443
2020-04-01 08:30:17f4dbbc9778150e9849a3129cdfa62f28Virustotal results 22 / 73 (30.14%) 217.72.196.142:443
2020-03-30 06:06:46c20c40a400c8f93f4b74d16928244d99Virustotal results 54 / 72 (75.00%) 87.250.250.22:443
2020-03-29 20:02:23326f2c90f50530e51ae7dc5458fe5d1en/a87.250.250.22:443
2020-03-29 20:01:191022bf5a12187529ee99567cfbe7138bVirustotal results 54 / 72 (75.00%) 87.250.250.22:443
2020-03-29 18:33:24e65123f30d11a0c92686b5c52b591ec6Virustotal results 42 / 73 (57.53%) 87.250.250.22:443
2020-03-29 11:03:26c42491d9ddbaa9409f0b63a09a880488Virustotal results 56 / 73 (76.71%) 87.250.250.22:443
2020-03-29 08:34:06c260b388b3a0a6a42d1dc18f67eb1b5eVirustotal results 31 / 72 (43.06%) 87.250.250.22:443
2020-03-29 08:34:05c260b388b3a0a6a42d1dc18f67eb1b5eVirustotal results 31 / 72 (43.06%) 78.155.198.17:443
2020-03-29 08:34:05c260b388b3a0a6a42d1dc18f67eb1b5eVirustotal results 31 / 72 (43.06%) 185.72.147.25:443
2020-03-29 08:34:05c260b388b3a0a6a42d1dc18f67eb1b5eVirustotal results 31 / 72 (43.06%) 89.249.18.162:443
2020-03-29 08:34:04c260b388b3a0a6a42d1dc18f67eb1b5eVirustotal results 31 / 72 (43.06%) 82.202.172.91:443
2020-03-29 08:34:04c260b388b3a0a6a42d1dc18f67eb1b5eVirustotal results 31 / 72 (43.06%) 178.248.237.144:443
2020-03-29 08:34:03c260b388b3a0a6a42d1dc18f67eb1b5eVirustotal results 31 / 72 (43.06%) 31.31.198.154:443
2020-03-29 00:54:11aabf7a7dfd185f1e3969712068f359a8Virustotal results 38 / 73 (52.05%) 87.250.250.22:443
2020-03-28 18:46:28761a3d8f7c9951e648ceb75e1ee03463n/a87.250.250.22:443
2020-03-28 18:42:4957c12d5973eea454adc97df22437c677n/a87.250.250.22:443
2020-03-28 11:08:09cc116150b8cfdfa2f572101a8d42a00dVirustotal results 30 / 73 (41.10%) 87.250.250.22:443
2020-03-28 06:32:332fa08b5df03fa494f7ae182ca4019115n/a212.82.100.140:443
2020-03-27 21:44:554082e3cd8aa4fa38ef8b0d819bea7125Virustotal results 53 / 73 (72.60%) 213.180.204.120:443
2020-03-27 21:44:554082e3cd8aa4fa38ef8b0d819bea7125Virustotal results 53 / 73 (72.60%) 87.250.251.153:443
2020-03-27 21:44:554082e3cd8aa4fa38ef8b0d819bea7125Virustotal results 53 / 73 (72.60%) 78.155.198.22:443
2020-03-27 21:44:554082e3cd8aa4fa38ef8b0d819bea7125Virustotal results 53 / 73 (72.60%) 87.250.250.22:443
2020-03-27 21:44:554082e3cd8aa4fa38ef8b0d819bea7125Virustotal results 53 / 73 (72.60%) 188.120.246.122:443
2020-03-27 16:28:22df9803868c79bf013c113b1eaa7723d2n/a212.82.100.140:443
2020-03-26 19:16:050619175efa50887152aa01e9b06b96dcVirustotal results 21 / 72 (29.17%) 204.79.197.200:443
2020-03-26 11:35:56999dc6eef21218ed7c3fbb3bbb920052Virustotal results 35 / 73 (47.95%) 109.236.87.82:443
2020-03-25 16:19:4939b961c13850e7910d07c9d1993b47a7Virustotal results 20 / 72 (27.78%) 82.165.230.102:443
2020-03-25 16:19:4939b961c13850e7910d07c9d1993b47a7Virustotal results 20 / 72 (27.78%) 31.13.92.174:443
2020-03-25 16:19:4939b961c13850e7910d07c9d1993b47a7Virustotal results 20 / 72 (27.78%) 216.58.205.228:443
2020-03-25 16:19:3939b961c13850e7910d07c9d1993b47a7Virustotal results 20 / 72 (27.78%) 217.72.196.142:443
2020-03-25 16:19:3839b961c13850e7910d07c9d1993b47a7Virustotal results 20 / 72 (27.78%) 212.82.100.140:443
2020-03-25 14:18:49c0d90be5de2fbba760a3ae94c4cdbf85Virustotal results 22 / 72 (30.56%) 212.82.100.140:443
2020-03-20 07:41:4704c165a8c81caedda4674496bc402350n/a87.250.250.22:443
2020-03-19 21:25:46a990bfa906c958fd3e735278ef046e41Virustotal results 54 / 73 (73.97%) 109.236.87.82:443
2020-03-19 21:25:45a990bfa906c958fd3e735278ef046e41Virustotal results 54 / 73 (73.97%) 172.217.19.196:443
2020-03-19 18:31:5809e05ceb5a88f23167fbcd5c2eb275fen/a87.250.250.22:443
2020-03-19 13:36:2118ea52a7b0a533ef2b2050ed50e06cdbn/a87.250.250.22:443
2020-03-18 16:55:12053954d663fb1affe65486cf59418ffdn/a87.250.250.22:443
2020-03-14 15:43:315d5b0279c5e9c756a5de74d956ac323fn/a87.250.250.22:443
2020-03-07 19:04:49249e052b738ab40f0e9a1f9723da6761Virustotal results 54 / 72 (75.00%) 109.236.87.82:443
2020-03-06 19:46:0446c564d7bf821027725ac57fe9038526Virustotal results 34 / 72 (47.22%) 109.236.87.82:443
2020-03-04 14:35:51b6998cb5462145b9e41c7ae11c82c91dVirustotal results 50 / 69 (72.46%) 87.250.250.22:443
2020-03-03 08:45:0617f81b3b1181838f77b597c52c35853cn/a87.250.250.22:443
2020-03-01 12:51:18bb94fdb841462c232054949eb2550d37Virustotal results 54 / 73 (73.97%) 87.250.250.22:443
2020-03-01 12:17:080c87fb34a642e9e33c4ee715adaa8c1dVirustotal results 55 / 73 (75.34%) 87.250.250.22:443
2020-03-01 09:36:43bb1e570d71b9a8e14f528ccd5887f5dan/a87.250.250.22:443
2020-02-29 21:21:33b480b7991a57cba5c4461baad95bfdd6n/a87.250.250.22:443
2020-02-29 11:30:42b0638dd093b2c82a9f9cccf870fbe130n/a87.250.250.22:443
2020-02-29 07:50:08b715a90e471d3ec299f0b2a6c1cf22c1Virustotal results 54 / 73 (73.97%) 87.250.250.22:443
2020-02-29 05:48:0715817f74ccc3d6a9e222b1ae904c25a9n/a87.250.250.22:443
2020-02-29 04:01:59298cbe4c3068f250d389eb93463d7ec6n/a87.250.250.22:443
2020-02-29 04:00:56481c78c691f256e77c3968b0e0f0ed62n/a87.250.250.22:443
2020-02-29 03:35:391f51e4f1c4c3f5f58625d7649c904471n/a87.250.250.22:443
2020-02-28 23:57:249b44ebbaf69ff3b4577f80fb93debebbn/a87.250.250.22:443
2020-02-28 17:05:3088d7aac529862842bd3512a06c715762n/a87.250.250.22:443
2020-02-26 12:20:003cd87060a68caab2b05793aab21d1885Virustotal results 41 / 72 (56.94%) 109.236.87.82:443
2020-02-24 15:15:39540d76aa19b7c959db21efe9cf21b8a5n/a87.250.250.22:443
2020-02-24 15:02:10e914fb98bc6c4d1e6c9fddb335bfbd55n/a87.250.250.22:443
2020-02-24 13:13:39bce3600d3ca1ebd996398e25cb1eb035n/a87.250.250.22:443
2020-02-23 07:43:07be4cdba67862e0a0d2025f221c30c549n/a78.140.220.143:443
2020-02-23 07:43:07be4cdba67862e0a0d2025f221c30c549n/a87.250.250.22:443
2020-02-23 07:43:07be4cdba67862e0a0d2025f221c30c549n/a5.188.196.181:443
2020-02-23 07:43:07be4cdba67862e0a0d2025f221c30c549n/a5.45.123.180:443
2020-02-23 07:43:07be4cdba67862e0a0d2025f221c30c549n/a95.213.246.92:443
2020-02-23 07:43:06be4cdba67862e0a0d2025f221c30c549n/a178.248.233.81:443
2020-02-23 07:43:06be4cdba67862e0a0d2025f221c30c549n/a89.249.21.3:443
2020-02-23 07:19:1576aec0264cba39949a586879bcd51d99n/a87.250.250.22:443
2020-02-23 05:52:17a95b2e8d48b4b319f07d8362bc2bfe41n/a87.250.250.22:443
2020-02-23 01:33:24a295f1406d873d89f0028042570e52c9Virustotal results 54 / 73 (73.97%) 87.250.250.22:443
2020-02-22 20:49:1007d1970ccbd410293be73b16456c6ccbn/a87.250.250.22:443
2020-02-22 20:46:003de69811aad6f71b067f7ba28d9b97b7n/a87.250.250.22:443
2020-02-22 20:40:27fb0d4851304914b0cdbaaa9b3b53766cn/a87.250.250.22:443
2020-02-22 20:40:06807fe83b67fe08af9ba6624ba830556dn/a87.250.250.22:443
2020-02-22 20:32:00275816dec1a6c49fb32ea7ceb989cdd2n/a87.250.250.22:443
2020-02-22 20:06:26744bb447edcd1032f9a74857b09ef05bn/a87.250.250.22:443
2020-02-22 19:27:0087edba8fc274fd8dda4d53aa96ad4e3cn/a87.250.250.22:443
2020-02-21 16:21:55a62e03b34bc40049852c2fc5681ed9a7Virustotal results 53 / 71 (74.65%) 87.250.250.22:443
2020-02-20 17:27:10bfad7e7985de77b64baf55ac96803707n/a87.250.250.22:443
2020-02-20 16:31:07ad774de9c1a59558104af925ba377f24n/a87.250.250.22:443
2020-02-20 09:07:58bc7e159bd32ae48b798b1956e6cbec36n/a87.250.250.22:443
2020-02-20 06:12:58ea2e8ed5310836654a9980b3321ddaa2n/a87.250.250.22:443
2020-02-20 06:08:2534af2870135e323c332fa5f4a5005d62n/a87.250.250.22:443
2020-02-20 06:04:34c51c68fc2684926d90b92158d5ebb069n/a87.250.250.22:443
2020-02-20 06:02:04c7e3fe634687d46e99332d3d24b8043fn/a87.250.250.22:443
2020-02-20 05:21:56b536d4bcc4ad85227fcb07abff564077n/a87.250.250.22:443
2020-02-20 02:05:31a9973f42de55b7f9c3f5c72f831e8a6en/a87.250.250.22:443
2020-02-19 17:17:16ca244f75aa72fe52b1b0c8aae5b9a79fn/a87.250.250.22:443
2020-02-19 16:19:421df246796ece9cb080bb761c79a80cacn/a87.250.250.22:443
2020-02-19 12:05:36ac6ae36c16b869653bdef159b0fd3a6fn/a87.250.250.22:443
2020-02-19 09:42:52a95c04297b3c62226333f94c629afc9cn/a87.250.250.22:443
2020-02-19 09:33:58bb54d0dd72b6cf9d4cd4be7c5e5fdf01n/a87.250.250.22:443
2020-02-19 01:23:41a5c41b91e9da697120422edcb601193fn/a87.250.250.22:443
2020-02-18 23:39:04a3635ae41067c645160ee33bb30a9ea8n/a87.250.250.22:443
2020-02-18 18:53:40ad0f8b926ac0b2a9d84dee20d83f2388n/a87.250.250.22:443
2020-02-18 18:30:12c1fa0e2651eac6779ce070e2dddfce0bn/a87.250.250.22:443
2020-02-18 10:38:39eca495e2fe4293db3f92f3c574b541e1n/a87.250.250.22:443
2020-02-18 10:29:42f1c127d900080c0f4c6e5675f928bf0dVirustotal results 53 / 71 (74.65%) 87.250.250.22:443
2020-02-18 10:26:42b10fe3f0ca2cc15c74356bb0976deaa1n/a87.250.250.22:443
2020-02-18 10:25:240f89fc6f45048ad904b6a1c721e28019n/a87.250.250.22:443

# of entries: 100 (max: 100)