JA3 Fingerprints

You can find further information about the JA3 fingerprint e3b2ab1f9a56f2fb4c9248f2f41631fa, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:e3b2ab1f9a56f2fb4c9248f2f41631fa
First seen:2018-03-15 01:06:34 UTC
Last seen:2021-03-25 10:56:13 UTC
Status:Blacklisted
Malware samples:8'447
Destination IPs:392
Malware:Tofsee -
Listing date:2018-11-14 12:13:52

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2021-03-25 10:56:13e187ac89caac8aa6d4cc2935d871c104Virustotal results 43 / 70 (61.43%) 173.201.192.129:993
2021-03-25 10:56:13e187ac89caac8aa6d4cc2935d871c104Virustotal results 43 / 70 (61.43%) 209.91.128.17:993
2021-03-25 05:14:118a0720e93365c33876a77c94946604beVirustotal results 35 / 71 (49.30%) 17.42.251.32:993
2021-03-23 23:43:463de338204ce8f651d942c8192beb5c4dVirustotal results 39 / 71 (54.93%) 77.92.64.117:993
2021-03-20 02:22:22674b04540b00d9e3efb770c3ca8c0c36Virustotal results 44 / 70 (62.86%) 67.222.38.67:443
2021-03-20 01:47:508c5421a4e3a2180ff7f92f0d2e03f0b4Virustotal results 47 / 70 (67.14%) 81.27.85.12:443
2021-03-20 01:47:498c5421a4e3a2180ff7f92f0d2e03f0b4Virustotal results 47 / 70 (67.14%) 172.67.186.177:443
2021-03-20 01:47:498c5421a4e3a2180ff7f92f0d2e03f0b4Virustotal results 47 / 70 (67.14%) 104.21.68.60:443
2021-03-19 23:30:56603a226b92fc654f0c4dd819eafa4377Virustotal results 52 / 70 (74.29%) 172.67.187.159:443
2021-03-19 23:30:55603a226b92fc654f0c4dd819eafa4377Virustotal results 52 / 70 (74.29%) 104.21.92.65:443
2021-03-19 23:30:55603a226b92fc654f0c4dd819eafa4377Virustotal results 52 / 70 (74.29%) 104.21.1.239:443
2021-03-19 20:55:2206a4103b3c8ab3fffafa7051bde06154Virustotal results 46 / 71 (64.79%) 3.7.246.28:443
2021-03-19 01:01:005f7724c74fdf88862490b5c49ad5cfa1n/a104.21.40.197:443
2021-03-18 16:12:36a9b1f17e7e440417e0f1bc35389c86faVirustotal results 46 / 70 (65.71%) 198.71.233.51:443
2021-03-18 16:12:35a9b1f17e7e440417e0f1bc35389c86faVirustotal results 46 / 70 (65.71%) 92.114.94.46:443
2021-03-18 10:51:27a614e96f022bf639e5e8323e4aa91112Virustotal results 43 / 71 (60.56%) 216.239.34.21:443
2021-03-18 10:51:27a614e96f022bf639e5e8323e4aa91112Virustotal results 43 / 71 (60.56%) 216.239.36.21:443
2021-03-18 09:17:01a5ab245f477650eb1e758824e2443e01Virustotal results 44 / 70 (62.86%) 216.239.32.21:443
2021-03-18 08:46:433b507ce33886076523fe53cc234a60a0Virustotal results 40 / 70 (57.14%) 216.239.34.21:443
2021-03-18 08:18:1072a9e97b147ddebe43085011bafcc7d6Virustotal results 33 / 69 (47.83%) 216.239.32.21:443
2021-03-18 08:18:0972a9e97b147ddebe43085011bafcc7d6Virustotal results 33 / 69 (47.83%) 31.13.65.36:443
2021-03-18 08:18:0972a9e97b147ddebe43085011bafcc7d6Virustotal results 33 / 69 (47.83%) 216.239.36.21:443
2021-03-18 08:18:0972a9e97b147ddebe43085011bafcc7d6Virustotal results 33 / 69 (47.83%) 216.239.34.21:443
2021-03-18 08:16:1276690c475b24fa245e4ddf9aeb6a0e18n/a216.239.32.21:443
2021-03-18 08:14:0427249ddd43bb1f528790fc970c754b50n/a216.239.34.21:443
2021-03-18 08:14:0427249ddd43bb1f528790fc970c754b50n/a216.239.38.21:443
2021-03-18 08:13:3883a2aacd101fa63ab23ed8a7f34769e1Virustotal results 32 / 71 (45.07%) 216.239.34.21:443
2021-03-18 08:13:3883a2aacd101fa63ab23ed8a7f34769e1Virustotal results 32 / 71 (45.07%) 216.239.36.21:443
2021-03-18 08:08:33803a4abb3bab5db79750934f1382fadan/a216.239.32.21:443
2021-03-18 08:08:32803a4abb3bab5db79750934f1382fadan/a216.239.38.21:443
2021-03-18 08:08:32803a4abb3bab5db79750934f1382fadan/a104.21.26.13:443
2021-03-18 08:08:32803a4abb3bab5db79750934f1382fadan/a216.239.34.21:443
2021-03-18 08:02:283dba4b21e16909d8d0bffe03b789f6cdVirustotal results 50 / 70 (71.43%) 216.239.38.21:443
2021-03-18 07:58:152c507cde6d1b15dbd482bf7d95a6c0fcn/a216.239.36.21:443
2021-03-18 07:58:152c507cde6d1b15dbd482bf7d95a6c0fcn/a216.239.34.21:443
2021-03-18 07:58:152c507cde6d1b15dbd482bf7d95a6c0fcn/a216.239.38.21:443
2021-03-18 07:56:5272f7c9b951548f91093e930652016603Virustotal results 45 / 73 (61.64%) 216.239.36.21:443
2021-03-18 07:36:3822f6b5aa2b77bc2023b310b439105537n/a216.239.38.21:443
2021-03-18 07:32:551bf9fcfb55e364f90fbe96c4443a359aVirustotal results 49 / 70 (70.00%) 216.239.36.21:443
2021-03-18 07:32:551bf9fcfb55e364f90fbe96c4443a359aVirustotal results 49 / 70 (70.00%) 216.239.38.21:443
2021-03-18 07:32:541bf9fcfb55e364f90fbe96c4443a359aVirustotal results 49 / 70 (70.00%) 31.13.65.36:443
2021-03-18 07:32:541bf9fcfb55e364f90fbe96c4443a359aVirustotal results 49 / 70 (70.00%) 216.239.34.21:443
2021-03-18 07:10:1986edef24222bf5cbb9982f988f8a61b2n/a216.239.32.21:443
2021-03-18 07:10:1986edef24222bf5cbb9982f988f8a61b2n/a216.239.38.21:443
2021-03-18 06:56:0077de98d2fe7c17acb8b341f71d34e01dn/a216.239.32.21:443
2021-03-18 06:56:0077de98d2fe7c17acb8b341f71d34e01dn/a216.239.34.21:443
2021-03-18 06:55:5977de98d2fe7c17acb8b341f71d34e01dn/a216.239.36.21:443
2021-03-18 06:52:11a33e4031d4b119ae6b46a5437a760b3cVirustotal results 55 / 70 (78.57%) 216.239.36.21:443
2021-03-18 06:48:165673ecae9381ef13038e15c9c5622979n/a216.239.32.21:443
2021-03-18 06:45:498b1b5025e2c67a8e2b28d479178a2e3aVirustotal results 50 / 69 (72.46%) 216.239.32.21:443
2021-03-18 06:45:488b1b5025e2c67a8e2b28d479178a2e3aVirustotal results 50 / 69 (72.46%) 216.239.36.21:443
2021-03-18 06:42:0083d90e9b2728ae93213f9b362e353749Virustotal results 45 / 70 (64.29%) 216.239.34.21:443
2021-03-18 06:37:13239b874a442edf9d1857057eee6d885cVirustotal results 46 / 67 (68.66%) 216.239.38.21:443
2021-03-18 06:37:13239b874a442edf9d1857057eee6d885cVirustotal results 46 / 67 (68.66%) 216.239.36.21:443
2021-03-18 06:37:12239b874a442edf9d1857057eee6d885cVirustotal results 46 / 67 (68.66%) 216.239.34.21:443
2021-03-18 06:33:2448dc84c649e0d2ea6c75aef3ae913d61n/a216.239.38.21:443
2021-03-18 06:33:2448dc84c649e0d2ea6c75aef3ae913d61n/a172.64.131.35:443
2021-03-18 06:32:1982b90c959bb1affe126ead5ebcb8ff16n/a108.177.122.104:443
2021-03-18 06:32:1982b90c959bb1affe126ead5ebcb8ff16n/a216.239.34.21:443
2021-03-18 06:32:1982b90c959bb1affe126ead5ebcb8ff16n/a148.66.138.148:443
2021-03-18 06:32:1982b90c959bb1affe126ead5ebcb8ff16n/a216.239.36.21:443
2021-03-18 06:32:1982b90c959bb1affe126ead5ebcb8ff16n/a139.59.46.88:443
2021-03-18 06:32:1982b90c959bb1affe126ead5ebcb8ff16n/a108.177.122.139:443
2021-03-18 06:32:1982b90c959bb1affe126ead5ebcb8ff16n/a50.87.145.186:443
2021-03-18 06:30:473cb90f5bcd35a6c1fbb4d0ff3a865a05Virustotal results 42 / 69 (60.87%) 216.239.34.21:443
2021-03-18 06:27:469b09c76dc159cf674a174273d84e3993n/a216.239.36.21:443
2021-03-18 06:27:459b09c76dc159cf674a174273d84e3993n/a216.239.38.21:443
2021-03-18 05:58:485eda3495bf876dcef2ea3eadbd30e334Virustotal results 47 / 71 (66.20%) 216.239.32.21:443
2021-03-18 05:58:03216cc4f4a6e11c5a1350cf0779c57161Virustotal results 38 / 70 (54.29%) 216.239.34.21:443
2021-03-18 05:38:536274724df970cc1dffb31bc4061e3fecn/a216.239.36.21:443
2021-03-18 05:38:536274724df970cc1dffb31bc4061e3fecn/a216.239.34.21:443
2021-03-18 05:38:026b8aac0c2713f1f7ca3860731ee2e93en/a216.239.32.21:443
2021-03-18 05:38:026b8aac0c2713f1f7ca3860731ee2e93en/a216.239.36.21:443
2021-03-18 05:35:1117379c619703009abeb76323f4042225n/a216.239.38.21:443
2021-03-18 05:35:1117379c619703009abeb76323f4042225n/a216.239.36.21:443
2021-03-18 05:35:1117379c619703009abeb76323f4042225n/a34.102.136.180:443
2021-03-18 05:35:1017379c619703009abeb76323f4042225n/a216.239.32.21:443
2021-03-18 05:32:16513862ca3e9510726553a72041cf6d6fn/a216.239.36.21:443
2021-03-18 05:32:15513862ca3e9510726553a72041cf6d6fn/a216.239.32.21:443
2021-03-18 05:10:252874470b62bb018646bdd93edface681Virustotal results 39 / 70 (55.71%) 216.239.32.21:443
2021-03-18 05:07:57a053830c30d8ab2a2f8c9af6254e014bVirustotal results 45 / 71 (63.38%) 216.239.34.21:443
2021-03-18 05:07:57a053830c30d8ab2a2f8c9af6254e014bVirustotal results 45 / 71 (63.38%) 172.67.210.57:443
2021-03-18 05:07:57a053830c30d8ab2a2f8c9af6254e014bVirustotal results 45 / 71 (63.38%) 216.239.36.21:443
2021-03-18 04:49:3721e95c2d7fe0c31511c4356570eb6f36n/a216.239.32.21:443
2021-03-18 04:49:3721e95c2d7fe0c31511c4356570eb6f36n/a216.239.38.21:443
2021-03-18 04:32:2702b892edf6df056ffce1b50c79e5b461n/a216.239.34.21:443
2021-03-18 04:11:39a149c3790b13a89c699094d1010ee755Virustotal results 42 / 71 (59.15%) 216.239.32.21:443
2021-03-18 03:37:319ea4a2b4e8a4274bfe08267cf833050fn/a216.239.36.21:443
2021-03-18 03:37:319ea4a2b4e8a4274bfe08267cf833050fn/a216.239.32.21:443
2021-03-18 03:00:3162769cf9e3cf29bbb3abbd8bfffe7967Virustotal results 49 / 71 (69.01%) 216.239.32.21:443
2021-03-18 02:49:345db4a92e67c37d6d41f8b62cf3e127c8n/a216.239.32.21:443
2021-03-18 02:06:30921a86be7299958faf041b72894f3cb2n/a216.239.32.21:443
2021-03-18 02:01:2690af6179f35f2c8e0ce0df1fa345d6b2n/a216.239.38.21:443
2021-03-18 01:49:024cbadc5422cbe38c85af0c1e705c8600Virustotal results 41 / 70 (58.57%) 216.239.34.21:443
2021-03-18 01:49:024cbadc5422cbe38c85af0c1e705c8600Virustotal results 41 / 70 (58.57%) 144.76.159.130:443
2021-03-18 01:49:024cbadc5422cbe38c85af0c1e705c8600Virustotal results 41 / 70 (58.57%) 216.239.32.21:443
2021-03-18 01:49:024cbadc5422cbe38c85af0c1e705c8600Virustotal results 41 / 70 (58.57%) 216.239.36.21:443
2021-03-18 01:35:125c7a63fb0ccac870ebeaa4f50016807fn/a216.239.38.21:443
2021-03-18 01:35:115c7a63fb0ccac870ebeaa4f50016807fn/a216.239.32.21:443
2021-03-18 01:35:108d0523c434e07811ac29df2f36d0887dVirustotal results 41 / 69 (59.42%) 216.239.32.21:443

# of entries: 100 (max: 100)