JA3 Fingerprints

You can find further information about the JA3 fingerprint e3b2ab1f9a56f2fb4c9248f2f41631fa, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:e3b2ab1f9a56f2fb4c9248f2f41631fa
First seen:2018-03-15 01:06:34 UTC
Last seen:2021-07-02 21:51:49 UTC
Status:Blacklisted
Malware samples:8'449
Destination IPs:393
Malware:Tofsee -
Listing date:2018-11-14 12:13:52

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2021-07-02 21:51:498b601e0a802650fcf8be4dfbc44cddfbVirustotal results 48 / 70 (68.57%) 34.117.59.81:443
2021-07-02 21:51:498b601e0a802650fcf8be4dfbc44cddfbVirustotal results 48 / 70 (68.57%) 34.117.59.81:443
2021-07-02 19:57:4573aa0fe90fc58373bfa9cb62db6dbb33Virustotal results 52 / 70 (74.29%) 34.117.59.81:443
2021-07-02 19:57:4573aa0fe90fc58373bfa9cb62db6dbb33Virustotal results 52 / 70 (74.29%) 34.117.59.81:443
2021-03-25 10:56:13e187ac89caac8aa6d4cc2935d871c104Virustotal results 43 / 70 (61.43%) 173.201.192.129:993
2021-03-25 10:56:13e187ac89caac8aa6d4cc2935d871c104Virustotal results 43 / 70 (61.43%) 209.91.128.17:993
2021-03-25 10:56:13e187ac89caac8aa6d4cc2935d871c104Virustotal results 43 / 70 (61.43%) 173.201.192.129:993
2021-03-25 10:56:13e187ac89caac8aa6d4cc2935d871c104Virustotal results 43 / 70 (61.43%) 209.91.128.17:993
2021-03-25 05:14:118a0720e93365c33876a77c94946604beVirustotal results 35 / 71 (49.30%) 17.42.251.32:993
2021-03-25 05:14:118a0720e93365c33876a77c94946604beVirustotal results 35 / 71 (49.30%) 17.42.251.32:993
2021-03-23 23:43:463de338204ce8f651d942c8192beb5c4dVirustotal results 39 / 71 (54.93%) 77.92.64.117:993
2021-03-23 23:43:463de338204ce8f651d942c8192beb5c4dVirustotal results 39 / 71 (54.93%) 77.92.64.117:993
2021-03-20 02:22:22674b04540b00d9e3efb770c3ca8c0c36Virustotal results 44 / 70 (62.86%) 67.222.38.67:443
2021-03-20 02:22:22674b04540b00d9e3efb770c3ca8c0c36Virustotal results 44 / 70 (62.86%) 67.222.38.67:443
2021-03-20 01:47:508c5421a4e3a2180ff7f92f0d2e03f0b4Virustotal results 47 / 70 (67.14%) 81.27.85.12:443
2021-03-20 01:47:508c5421a4e3a2180ff7f92f0d2e03f0b4Virustotal results 47 / 70 (67.14%) 81.27.85.12:443
2021-03-20 01:47:498c5421a4e3a2180ff7f92f0d2e03f0b4Virustotal results 47 / 70 (67.14%) 172.67.186.177:443
2021-03-20 01:47:498c5421a4e3a2180ff7f92f0d2e03f0b4Virustotal results 47 / 70 (67.14%) 104.21.68.60:443
2021-03-20 01:47:498c5421a4e3a2180ff7f92f0d2e03f0b4Virustotal results 47 / 70 (67.14%) 172.67.186.177:443
2021-03-20 01:47:498c5421a4e3a2180ff7f92f0d2e03f0b4Virustotal results 47 / 70 (67.14%) 104.21.68.60:443
2021-03-19 23:30:56603a226b92fc654f0c4dd819eafa4377Virustotal results 52 / 70 (74.29%) 172.67.187.159:443
2021-03-19 23:30:56603a226b92fc654f0c4dd819eafa4377Virustotal results 52 / 70 (74.29%) 172.67.187.159:443
2021-03-19 23:30:55603a226b92fc654f0c4dd819eafa4377Virustotal results 52 / 70 (74.29%) 104.21.92.65:443
2021-03-19 23:30:55603a226b92fc654f0c4dd819eafa4377Virustotal results 52 / 70 (74.29%) 104.21.1.239:443
2021-03-19 23:30:55603a226b92fc654f0c4dd819eafa4377Virustotal results 52 / 70 (74.29%) 104.21.92.65:443
2021-03-19 23:30:55603a226b92fc654f0c4dd819eafa4377Virustotal results 52 / 70 (74.29%) 104.21.1.239:443
2021-03-19 20:55:2206a4103b3c8ab3fffafa7051bde06154Virustotal results 46 / 71 (64.79%) 3.7.246.28:443
2021-03-19 20:55:2206a4103b3c8ab3fffafa7051bde06154Virustotal results 46 / 71 (64.79%) 3.7.246.28:443
2021-03-19 01:01:005f7724c74fdf88862490b5c49ad5cfa1n/a104.21.40.197:443
2021-03-19 01:01:005f7724c74fdf88862490b5c49ad5cfa1n/a104.21.40.197:443
2021-03-18 16:12:36a9b1f17e7e440417e0f1bc35389c86faVirustotal results 46 / 70 (65.71%) 198.71.233.51:443
2021-03-18 16:12:36a9b1f17e7e440417e0f1bc35389c86faVirustotal results 46 / 70 (65.71%) 198.71.233.51:443
2021-03-18 16:12:35a9b1f17e7e440417e0f1bc35389c86faVirustotal results 46 / 70 (65.71%) 92.114.94.46:443
2021-03-18 16:12:35a9b1f17e7e440417e0f1bc35389c86faVirustotal results 46 / 70 (65.71%) 92.114.94.46:443
2021-03-18 10:51:27a614e96f022bf639e5e8323e4aa91112Virustotal results 43 / 71 (60.56%) 216.239.34.21:443
2021-03-18 10:51:27a614e96f022bf639e5e8323e4aa91112Virustotal results 43 / 71 (60.56%) 216.239.36.21:443
2021-03-18 10:51:27a614e96f022bf639e5e8323e4aa91112Virustotal results 43 / 71 (60.56%) 216.239.34.21:443
2021-03-18 10:51:27a614e96f022bf639e5e8323e4aa91112Virustotal results 43 / 71 (60.56%) 216.239.36.21:443
2021-03-18 09:17:01a5ab245f477650eb1e758824e2443e01Virustotal results 44 / 70 (62.86%) 216.239.32.21:443
2021-03-18 09:17:01a5ab245f477650eb1e758824e2443e01Virustotal results 44 / 70 (62.86%) 216.239.32.21:443
2021-03-18 08:46:433b507ce33886076523fe53cc234a60a0Virustotal results 40 / 70 (57.14%) 216.239.34.21:443
2021-03-18 08:46:433b507ce33886076523fe53cc234a60a0Virustotal results 40 / 70 (57.14%) 216.239.34.21:443
2021-03-18 08:18:1072a9e97b147ddebe43085011bafcc7d6Virustotal results 33 / 69 (47.83%) 216.239.32.21:443
2021-03-18 08:18:1072a9e97b147ddebe43085011bafcc7d6Virustotal results 33 / 69 (47.83%) 216.239.32.21:443
2021-03-18 08:18:0972a9e97b147ddebe43085011bafcc7d6Virustotal results 33 / 69 (47.83%) 31.13.65.36:443
2021-03-18 08:18:0972a9e97b147ddebe43085011bafcc7d6Virustotal results 33 / 69 (47.83%) 216.239.36.21:443
2021-03-18 08:18:0972a9e97b147ddebe43085011bafcc7d6Virustotal results 33 / 69 (47.83%) 216.239.34.21:443
2021-03-18 08:18:0972a9e97b147ddebe43085011bafcc7d6Virustotal results 33 / 69 (47.83%) 31.13.65.36:443
2021-03-18 08:18:0972a9e97b147ddebe43085011bafcc7d6Virustotal results 33 / 69 (47.83%) 216.239.36.21:443
2021-03-18 08:18:0972a9e97b147ddebe43085011bafcc7d6Virustotal results 33 / 69 (47.83%) 216.239.34.21:443
2021-03-18 08:16:1276690c475b24fa245e4ddf9aeb6a0e18n/a216.239.32.21:443
2021-03-18 08:16:1276690c475b24fa245e4ddf9aeb6a0e18n/a216.239.32.21:443
2021-03-18 08:14:0427249ddd43bb1f528790fc970c754b50n/a216.239.34.21:443
2021-03-18 08:14:0427249ddd43bb1f528790fc970c754b50n/a216.239.38.21:443
2021-03-18 08:14:0427249ddd43bb1f528790fc970c754b50n/a216.239.34.21:443
2021-03-18 08:14:0427249ddd43bb1f528790fc970c754b50n/a216.239.38.21:443
2021-03-18 08:13:3883a2aacd101fa63ab23ed8a7f34769e1Virustotal results 32 / 71 (45.07%) 216.239.34.21:443
2021-03-18 08:13:3883a2aacd101fa63ab23ed8a7f34769e1Virustotal results 32 / 71 (45.07%) 216.239.36.21:443
2021-03-18 08:13:3883a2aacd101fa63ab23ed8a7f34769e1Virustotal results 32 / 71 (45.07%) 216.239.34.21:443
2021-03-18 08:13:3883a2aacd101fa63ab23ed8a7f34769e1Virustotal results 32 / 71 (45.07%) 216.239.36.21:443
2021-03-18 08:08:33803a4abb3bab5db79750934f1382fadan/a216.239.32.21:443
2021-03-18 08:08:33803a4abb3bab5db79750934f1382fadan/a216.239.32.21:443
2021-03-18 08:08:32803a4abb3bab5db79750934f1382fadan/a216.239.38.21:443
2021-03-18 08:08:32803a4abb3bab5db79750934f1382fadan/a104.21.26.13:443
2021-03-18 08:08:32803a4abb3bab5db79750934f1382fadan/a216.239.34.21:443
2021-03-18 08:08:32803a4abb3bab5db79750934f1382fadan/a216.239.38.21:443
2021-03-18 08:08:32803a4abb3bab5db79750934f1382fadan/a104.21.26.13:443
2021-03-18 08:08:32803a4abb3bab5db79750934f1382fadan/a216.239.34.21:443
2021-03-18 08:02:283dba4b21e16909d8d0bffe03b789f6cdVirustotal results 50 / 70 (71.43%) 216.239.38.21:443
2021-03-18 08:02:283dba4b21e16909d8d0bffe03b789f6cdVirustotal results 50 / 70 (71.43%) 216.239.38.21:443
2021-03-18 07:58:152c507cde6d1b15dbd482bf7d95a6c0fcn/a216.239.36.21:443
2021-03-18 07:58:152c507cde6d1b15dbd482bf7d95a6c0fcn/a216.239.34.21:443
2021-03-18 07:58:152c507cde6d1b15dbd482bf7d95a6c0fcn/a216.239.38.21:443
2021-03-18 07:58:152c507cde6d1b15dbd482bf7d95a6c0fcn/a216.239.36.21:443
2021-03-18 07:58:152c507cde6d1b15dbd482bf7d95a6c0fcn/a216.239.34.21:443
2021-03-18 07:58:152c507cde6d1b15dbd482bf7d95a6c0fcn/a216.239.38.21:443
2021-03-18 07:56:5272f7c9b951548f91093e930652016603Virustotal results 45 / 73 (61.64%) 216.239.36.21:443
2021-03-18 07:56:5272f7c9b951548f91093e930652016603Virustotal results 45 / 73 (61.64%) 216.239.36.21:443
2021-03-18 07:36:3822f6b5aa2b77bc2023b310b439105537n/a216.239.38.21:443
2021-03-18 07:36:3822f6b5aa2b77bc2023b310b439105537n/a216.239.38.21:443
2021-03-18 07:32:551bf9fcfb55e364f90fbe96c4443a359aVirustotal results 49 / 70 (70.00%) 216.239.36.21:443
2021-03-18 07:32:551bf9fcfb55e364f90fbe96c4443a359aVirustotal results 49 / 70 (70.00%) 216.239.38.21:443
2021-03-18 07:32:551bf9fcfb55e364f90fbe96c4443a359aVirustotal results 49 / 70 (70.00%) 216.239.36.21:443
2021-03-18 07:32:551bf9fcfb55e364f90fbe96c4443a359aVirustotal results 49 / 70 (70.00%) 216.239.38.21:443
2021-03-18 07:32:541bf9fcfb55e364f90fbe96c4443a359aVirustotal results 49 / 70 (70.00%) 31.13.65.36:443
2021-03-18 07:32:541bf9fcfb55e364f90fbe96c4443a359aVirustotal results 49 / 70 (70.00%) 216.239.34.21:443
2021-03-18 07:32:541bf9fcfb55e364f90fbe96c4443a359aVirustotal results 49 / 70 (70.00%) 31.13.65.36:443
2021-03-18 07:32:541bf9fcfb55e364f90fbe96c4443a359aVirustotal results 49 / 70 (70.00%) 216.239.34.21:443
2021-03-18 07:10:1986edef24222bf5cbb9982f988f8a61b2n/a216.239.32.21:443
2021-03-18 07:10:1986edef24222bf5cbb9982f988f8a61b2n/a216.239.38.21:443
2021-03-18 07:10:1986edef24222bf5cbb9982f988f8a61b2n/a216.239.32.21:443
2021-03-18 07:10:1986edef24222bf5cbb9982f988f8a61b2n/a216.239.38.21:443
2021-03-18 06:56:0077de98d2fe7c17acb8b341f71d34e01dn/a216.239.32.21:443
2021-03-18 06:56:0077de98d2fe7c17acb8b341f71d34e01dn/a216.239.34.21:443
2021-03-18 06:56:0077de98d2fe7c17acb8b341f71d34e01dn/a216.239.32.21:443
2021-03-18 06:56:0077de98d2fe7c17acb8b341f71d34e01dn/a216.239.34.21:443
2021-03-18 06:55:5977de98d2fe7c17acb8b341f71d34e01dn/a216.239.36.21:443
2021-03-18 06:55:5977de98d2fe7c17acb8b341f71d34e01dn/a216.239.36.21:443
2021-03-18 06:52:11a33e4031d4b119ae6b46a5437a760b3cVirustotal results 55 / 70 (78.57%) 216.239.36.21:443
2021-03-18 06:52:11a33e4031d4b119ae6b46a5437a760b3cVirustotal results 55 / 70 (78.57%) 216.239.36.21:443

# of entries: 100 (max: 100)