JA3 Fingerprints

You can find further information about the JA3 fingerprint e3b2ab1f9a56f2fb4c9248f2f41631fa, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:e3b2ab1f9a56f2fb4c9248f2f41631fa
First seen:2018-03-15 01:06:34 UTC
Last seen:2020-03-29 11:03:27 UTC
Status:Blacklisted
Malware samples:1'687
Destination IPs:108
Malware:Tofsee -
Listing date:2018-11-14 12:13:52

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2020-03-29 11:03:27c42491d9ddbaa9409f0b63a09a880488Virustotal results 56 / 73 (76.71%) 216.239.38.21:443
2020-03-29 10:15:24bc41f6a21a0955a1b0a78bfd01764fdfVirustotal results 55 / 72 (76.39%) 216.239.34.21:443
2020-03-29 08:34:06c260b388b3a0a6a42d1dc18f67eb1b5eVirustotal results 31 / 72 (43.06%) 216.239.34.21:443
2020-03-29 08:34:04c260b388b3a0a6a42d1dc18f67eb1b5eVirustotal results 31 / 72 (43.06%) 216.239.32.21:443
2020-03-29 00:54:10aabf7a7dfd185f1e3969712068f359a8Virustotal results 38 / 73 (52.05%) 216.239.34.21:443
2020-03-29 00:54:09aabf7a7dfd185f1e3969712068f359a8Virustotal results 38 / 73 (52.05%) 216.239.38.21:443
2020-03-28 22:50:45308cd4f1fd3e886c71224c3e4e7bd04bn/a216.239.34.21:443
2020-03-28 18:48:281f5a136b42a01c263022e9b7288080d5n/a216.239.32.21:443
2020-03-28 18:48:271f5a136b42a01c263022e9b7288080d5n/a216.239.34.21:443
2020-03-28 18:46:28761a3d8f7c9951e648ceb75e1ee03463n/a195.216.243.155:443
2020-03-28 18:46:28761a3d8f7c9951e648ceb75e1ee03463n/a34.241.19.185:443
2020-03-28 18:46:28761a3d8f7c9951e648ceb75e1ee03463n/a104.22.15.144:443
2020-03-28 18:46:28761a3d8f7c9951e648ceb75e1ee03463n/a216.58.198.206:443
2020-03-28 18:46:28761a3d8f7c9951e648ceb75e1ee03463n/a216.239.34.21:443
2020-03-28 18:46:28761a3d8f7c9951e648ceb75e1ee03463n/a216.239.38.21:443
2020-03-28 18:42:4957c12d5973eea454adc97df22437c677n/a216.239.36.21:443
2020-03-28 18:42:02f5261daf2935d35dfb5ec60fd074c2a2n/a216.239.34.21:443
2020-03-28 18:31:490281690cdec25b153cf23544e1ba5cf8n/a216.239.34.21:443
2020-03-28 18:31:490281690cdec25b153cf23544e1ba5cf8n/a157.240.220.35:443
2020-03-28 18:31:480281690cdec25b153cf23544e1ba5cf8n/a216.239.36.21:443
2020-03-28 18:29:44bff3f9b5b862053cf7ac76484e6f8f2bn/a216.239.38.21:443
2020-03-28 18:29:44bff3f9b5b862053cf7ac76484e6f8f2bn/a216.239.32.21:443
2020-03-28 18:27:4029bab3886add948bb6983c0a74ddde81n/a216.239.38.21:443
2020-03-28 18:27:3929bab3886add948bb6983c0a74ddde81n/a216.239.34.21:443
2020-03-28 18:26:42577952d6dd10fd7442e421ca7aee7a09n/a216.239.34.21:443
2020-03-28 18:26:41577952d6dd10fd7442e421ca7aee7a09n/a216.239.36.21:443
2020-03-28 14:29:42b7fecc2b7d6d435b3f7c48da7c5950eeVirustotal results 51 / 68 (75.00%) 216.239.32.21:443
2020-03-28 11:08:10cc116150b8cfdfa2f572101a8d42a00dVirustotal results 30 / 73 (41.10%) 216.239.34.21:443
2020-03-28 11:08:09cc116150b8cfdfa2f572101a8d42a00dVirustotal results 30 / 73 (41.10%) 216.239.38.21:443
2020-03-27 21:44:554082e3cd8aa4fa38ef8b0d819bea7125Virustotal results 53 / 73 (72.60%) 216.239.38.21:443
2020-03-27 21:44:554082e3cd8aa4fa38ef8b0d819bea7125Virustotal results 53 / 73 (72.60%) 216.239.36.21:443
2020-03-27 21:44:554082e3cd8aa4fa38ef8b0d819bea7125Virustotal results 53 / 73 (72.60%) 216.239.34.21:443
2020-03-27 15:13:37926941535345db23a2f45b3995939b80Virustotal results 22 / 72 (30.56%) 157.240.20.174:443
2020-03-27 08:00:51cd0f9d101208331d0682a14607fb8935Virustotal results 55 / 73 (75.34%) 216.239.32.21:443
2020-03-26 21:13:42803c7e7340e9f2e3c492662eadc5afa6Virustotal results 22 / 73 (30.14%) 216.239.34.21:443
2020-03-26 21:13:39803c7e7340e9f2e3c492662eadc5afa6Virustotal results 22 / 73 (30.14%) 157.240.20.174:443
2020-03-26 10:00:53a17de24e8a893504fceae182a3aaafc8Virustotal results 19 / 71 (26.76%) 216.239.38.21:443
2020-03-26 08:29:14e555fd4b024defbad63d013da50c592dn/a216.239.38.21:443
2020-03-26 08:29:14e555fd4b024defbad63d013da50c592dn/a216.239.36.21:443
2020-03-26 07:09:16e9258526d540b0d6b7f7d5b00097da6dVirustotal results 54 / 71 (76.06%) 216.239.38.21:443
2020-03-26 07:09:15e9258526d540b0d6b7f7d5b00097da6dVirustotal results 54 / 71 (76.06%) 216.239.32.21:443
2020-03-26 06:40:49ce5cc15fd1d4421d551f0d834807c8e2n/a216.239.34.21:443
2020-03-26 06:40:48ce5cc15fd1d4421d551f0d834807c8e2n/a216.239.32.21:443
2020-03-25 19:14:12283379943f74ca13f4b8b68ce5555e34Virustotal results 55 / 73 (75.34%) 157.240.220.35:443
2020-03-25 19:14:12283379943f74ca13f4b8b68ce5555e34Virustotal results 55 / 73 (75.34%) 216.239.38.21:443
2020-03-25 18:08:07617757adfdd08f4de7bb1a7c763e1354n/a216.239.38.21:443
2020-03-25 17:48:457d99738ae0fbfe01e9b4e0b2734505b9n/a216.239.32.21:443
2020-03-25 17:48:447d99738ae0fbfe01e9b4e0b2734505b9n/a157.240.220.35:443
2020-03-25 17:32:37cf92e6ae4e936cdf68aa927d4f5e5493n/a216.239.36.21:443
2020-03-25 17:32:36cf92e6ae4e936cdf68aa927d4f5e5493n/a216.239.34.21:443
2020-03-25 17:32:35cf92e6ae4e936cdf68aa927d4f5e5493n/a216.239.38.21:443
2020-03-25 08:25:51e4927c69ab20efd10f8ad729a209001cn/a216.239.32.21:443
2020-03-24 17:35:1703388e4249259a52fb8ecbd834071e33n/a216.239.38.21:443
2020-03-24 17:33:4633eec12ec46b73bad66ed066f856d6b4n/a216.239.32.21:443
2020-03-24 17:28:56fc0c9d0deb92208c5aff3e6506e1dec2n/a216.239.36.21:443
2020-03-24 17:28:56fc0c9d0deb92208c5aff3e6506e1dec2n/a216.239.38.21:443
2020-03-24 16:15:36a762b5e04a15393837dda914cebab4edn/a216.239.36.21:443
2020-03-24 15:14:00c9352249d4a37aceee0e7bc8c6bb6fbeVirustotal results 50 / 67 (74.63%) 216.239.36.21:443
2020-03-24 15:14:00c9352249d4a37aceee0e7bc8c6bb6fbeVirustotal results 50 / 67 (74.63%) 216.239.34.21:443
2020-03-24 14:52:11aec484873a803a3002bf9c68950f37ddn/a216.239.38.21:443
2020-03-24 10:47:18015cf6ea89bb81b627974c9285d383a0Virustotal results 54 / 72 (75.00%) 216.239.32.21:443
2020-03-24 09:08:387667b6f0e8959af9483c55e5fdec1a5aVirustotal results 55 / 73 (75.34%) 216.239.36.21:443
2020-03-24 09:08:387667b6f0e8959af9483c55e5fdec1a5aVirustotal results 55 / 73 (75.34%) 216.239.32.21:443
2020-03-24 07:35:10a4850117544b44a2ca5be5f6c3436339Virustotal results 55 / 73 (75.34%) 216.239.32.21:443
2020-03-24 07:35:09a4850117544b44a2ca5be5f6c3436339Virustotal results 55 / 73 (75.34%) 216.239.36.21:443
2020-03-24 07:22:05fb5d99056bbec8b5c63a601e354fc338n/a157.240.220.35:443
2020-03-24 07:22:04fb5d99056bbec8b5c63a601e354fc338n/a216.239.36.21:443
2020-03-24 07:22:04fb5d99056bbec8b5c63a601e354fc338n/a216.239.38.21:443
2020-03-24 07:22:04fb5d99056bbec8b5c63a601e354fc338n/a216.239.34.21:443
2020-03-24 07:14:33f9838b48b76cd2e54b8a23f97eccd07fn/a216.239.32.21:443
2020-03-24 04:36:16b485bc0512c504cb7bbbc7376718970eVirustotal results 55 / 73 (75.34%) 216.239.36.21:443
2020-03-24 03:32:325d2e7ec8465be49b01d7a210edb6021fVirustotal results 55 / 73 (75.34%) 216.239.32.21:443
2020-03-24 02:30:23bccbe9a729c1266b744b2474206cb1b5n/a216.239.34.21:443
2020-03-24 02:30:22bccbe9a729c1266b744b2474206cb1b5n/a216.239.38.21:443
2020-03-24 02:30:21bccbe9a729c1266b744b2474206cb1b5n/a216.239.36.21:443
2020-03-24 01:39:15b4f86261b0f670996e3565eb26f75d66n/a216.239.34.21:443
2020-03-24 01:39:14b4f86261b0f670996e3565eb26f75d66n/a216.239.32.21:443
2020-03-24 01:39:13b4f86261b0f670996e3565eb26f75d66n/a216.239.36.21:443
2020-03-24 00:43:19498712c2e86e43156e61b25b00ff4391n/a216.239.32.21:443
2020-03-24 00:43:16498712c2e86e43156e61b25b00ff4391n/a216.239.38.21:443
2020-03-23 22:47:48de87b69bef15aedf7a3b9c9e0c4e269cVirustotal results 55 / 73 (75.34%) 216.239.32.21:443
2020-03-23 21:35:10105f3170f2d32e00dbf86376f9df2cdfn/a216.239.32.21:443
2020-03-23 03:25:16c88c9a759a75c75845ee562243a89fb1n/a216.239.36.21:443
2020-03-23 03:25:16c88c9a759a75c75845ee562243a89fb1n/a216.239.38.21:443
2020-03-22 12:32:35a61d1763c317f2f43e45ce868087c921Virustotal results 53 / 72 (73.61%) 216.239.34.21:443
2020-03-22 12:32:35a61d1763c317f2f43e45ce868087c921Virustotal results 53 / 72 (73.61%) 216.239.32.21:443
2020-03-22 07:13:4686de17135ab673001482b6735f5bcfb0n/a216.239.38.21:443
2020-03-22 07:13:4686de17135ab673001482b6735f5bcfb0n/a216.239.34.21:443
2020-03-22 07:13:337b16c7ab53f5ab79d73a22efbfec41dbn/a216.239.32.21:443
2020-03-22 07:13:337b16c7ab53f5ab79d73a22efbfec41dbn/a216.239.38.21:443
2020-03-22 07:13:327b16c7ab53f5ab79d73a22efbfec41dbn/a216.239.34.21:443
2020-03-22 07:01:23da89b5ed05a5819f578e88f14a98e17cn/a216.239.34.21:443
2020-03-22 07:01:23da89b5ed05a5819f578e88f14a98e17cn/a216.239.32.21:443
2020-03-22 06:58:0028bf98dceb68f569073c49d4cf21b5fdn/a216.239.34.21:443
2020-03-22 06:57:5928bf98dceb68f569073c49d4cf21b5fdn/a216.239.32.21:443
2020-03-22 06:57:233406c4398121a897f25d4e67023e7259n/a216.239.34.21:443
2020-03-22 06:56:4870c4c1cf0348043dda74b21fb5ae38e6n/a216.239.34.21:443
2020-03-22 06:56:4870c4c1cf0348043dda74b21fb5ae38e6n/a216.239.36.21:443
2020-03-22 06:52:451e2b1f625c92dd88611fc31bfa9e2b85n/a216.239.36.21:443
2020-03-22 06:52:441e2b1f625c92dd88611fc31bfa9e2b85n/a216.239.38.21:443

# of entries: 100 (max: 100)