JA3 Fingerprints

You can find further information about the JA3 fingerprint e3b2ab1f9a56f2fb4c9248f2f41631fa, including the corresponding malware samples as well as the associated botnet C&Cs.

Database Entry


JA3 Fingerprint:e3b2ab1f9a56f2fb4c9248f2f41631fa
First seen:2018-03-15 01:06:34 UTC
Last seen:2019-05-20 10:42:00 UTC
Status:Blacklisted
Malware samples:192
Destination IPs:47
Malware:Tofsee -
Listing date:2018-11-14 12:13:52

Malware Samples


The table below documents all malware samples associated with this JA3 Fingerprint.

Timestamp (UTC)Malware Sample (MD5 hash)VTBotnet C&C (IP:port)
2019-05-20 10:42:001e4e1e20f97c442419bdd394427b1c4aVirustotal results 29/72 (40.28%) 216.239.38.21:443
2019-05-19 18:04:49a1dacf35ccfb982a92829690a32dbf24Virustotal results 51/72 (70.83%) 157.240.11.35:443
2019-05-12 16:36:36b5bc03484af3d3b1e10e201c6ea316d6n/a216.239.38.21:443
2019-05-12 12:06:1114f5528d1d1126dbe6b89b29e68c174cn/a216.239.38.21:443
2019-05-10 19:51:36c86d6f29364b0cd0043c76114e10cb41n/a216.239.36.21:443
2019-05-09 09:13:596f9ee02afa7b8942daebd4d0d516ee57n/a157.240.2.35:443
2019-05-01 15:15:18583aa1a7a4c81a03b57a8d808f01c1aan/a216.239.38.21:443
2019-04-25 06:48:042f5baa0f0b3d24c792ad901ebcaf9181Virustotal results 19/67 (28.36%) 216.239.32.21:443
2019-04-13 23:03:117f88938cd871441badf6ecce16ae702an/a216.239.38.21:443
2019-04-13 07:11:30dc01b7fce9a08332ab428b4e9970276cn/a157.240.14.35:443
2019-04-12 12:05:14cc89735d61ea4bdb9eef360dd8825dban/a104.28.26.204:443
2019-04-11 04:54:49f1c4d05c8c0764c2267b56d9f7d33b25n/a157.240.14.35:443
2019-04-08 23:52:2235c1d3e396422925521262d31b23a3eeVirustotal results 18/71 (25.35%) 157.240.14.35:443
2019-04-06 21:31:361c255d44a884c872c3c14338ba2cb0dfn/a216.239.34.21:443
2019-04-04 17:11:01f6ff62266948c8a9516f4c49d6421a52n/a67.199.248.10:443
2019-04-04 17:11:00f6ff62266948c8a9516f4c49d6421a52n/a216.58.204.110:443
2019-04-04 11:07:564417ba7cde3c9e8f87b78778b9d66e31n/a157.240.14.35:443
2019-04-04 11:07:564417ba7cde3c9e8f87b78778b9d66e31n/a216.239.32.21:443
2019-04-03 06:34:300fba4b08cce1ba318e281253d25fcb8eVirustotal results 44/67 (65.67%) 216.239.34.21:443
2019-03-27 22:11:038352f19171d93ddb3cd4d5f5c49cab6bVirustotal results 41/65 (63.08%) 157.240.2.35:443
2019-02-12 01:34:486ec711bccc0ecc02197d3f8534bc445bVirustotal results 46/70 (65.71%) 216.239.32.21:443
2019-02-10 01:40:089c3e69b6aca6a7b7e6885650f0af5a61Virustotal results 45/70 (64.29%) 31.13.66.35:443
2019-02-10 01:40:089c3e69b6aca6a7b7e6885650f0af5a61Virustotal results 45/70 (64.29%) 176.32.98.166:443
2019-02-09 04:45:0885999fafc0b3cbf49e7f3ac466c5b9a7Virustotal results 46/70 (65.71%) 185.84.108.14:443
2019-01-22 14:23:0838295c84ee9cf761fc486143613f6f75Virustotal results 33/70 (47.14%) 176.32.98.166:443
2019-01-20 14:31:399e6df0e4d260e0e5bf7f23c150e82a4bVirustotal results 34/71 (47.89%) 216.239.34.21:443
2019-01-05 19:56:33a26dd9ab29f62033ad37ebc874a20a7cn/a216.239.38.21:443
2019-01-03 19:12:59ec40ccaad63f8855d8de31a42b7c67acVirustotal results 28/69 (40.58%) 216.239.38.21:443
2019-01-02 09:30:536a27b1eaaa1a56377a0a1fd0a14fdd57n/a216.239.34.21:443
2018-12-27 19:29:284577728e7e6ea0c371746efd0341813aVirustotal results 46/71 (64.79%) 216.239.32.21:443
2018-12-27 19:29:284577728e7e6ea0c371746efd0341813aVirustotal results 46/71 (64.79%) 216.239.34.21:443
2018-12-24 22:19:07424f7b8edf5d150c7a248ad789512bc4Virustotal results 39/69 (56.52%) 216.239.32.21:443
2018-12-24 22:19:07424f7b8edf5d150c7a248ad789512bc4Virustotal results 39/69 (56.52%) 157.240.2.35:443
2018-12-19 20:54:5861f4fa70b33c54bb2e9e049359c3a03en/a176.32.103.205:443
2018-12-19 20:54:5861f4fa70b33c54bb2e9e049359c3a03en/a216.239.36.21:443
2018-12-19 20:54:5861f4fa70b33c54bb2e9e049359c3a03en/a31.13.65.36:443
2018-12-17 21:30:18c84fdb9bf81240c39381022530c0cdd0Virustotal results 24/68 (35.29%) 52.17.132.61:443
2018-12-16 20:17:5678c050980246f58ecc5dfc373d81c6f8Virustotal results 37/71 (52.11%) 216.239.36.21:443
2018-12-13 23:56:198bb5bd6750d9a98e2eab9665dc0907b5n/a216.239.36.21:443
2018-12-13 20:30:4639e07898d58e72ee3be94015fa178552Virustotal results 22/70 (31.43%) 216.239.32.21:443
2018-12-13 20:12:454b2405676f726333a5ad5754ae3af6b4Virustotal results 36/68 (52.94%) 216.239.38.21:443
2018-12-10 23:44:03dac816d1c7b4ac33bc491a2c26ef83c2n/a216.239.38.21:443
2018-12-09 00:59:4399baca5d78a6427843dba64a5fc0c083Virustotal results 39/71 (54.93%) 216.239.36.21:443
2018-12-08 11:55:1754aaa042e75d20b5b9b22763639024b8Virustotal results 39/70 (55.71%) 216.239.36.21:443
2018-12-07 06:32:511493bba5bf03b8580e145de4453b8287Virustotal results 15/70 (21.43%) 216.239.38.21:443
2018-12-07 04:17:015919f2f95678c9689bb2ab633f04ecedVirustotal results 40/69 (57.97%) 216.239.38.21:443
2018-12-05 07:04:196a9c5dea5eed27a993cd13041c567fe2Virustotal results 39/70 (55.71%) 216.239.38.21:443
2018-12-05 06:15:27f0a3e4eca113df7d09bbff6c3678ff27Virustotal results 35/69 (50.72%) 157.240.2.35:443
2018-12-05 06:15:27f0a3e4eca113df7d09bbff6c3678ff27Virustotal results 35/69 (50.72%) 216.239.32.21:443
2018-12-05 06:15:27f0a3e4eca113df7d09bbff6c3678ff27Virustotal results 35/69 (50.72%) 176.32.98.166:443
2018-11-26 08:28:398c2a233173810d4f53df1cc5de624d50Virustotal results 35/70 (50.00%) 216.239.34.21:443
2018-11-25 16:01:2205754754e9926dfc92751235f56f1fd8Virustotal results 36/69 (52.17%) 216.239.36.21:443
2018-11-24 21:53:206b6a43af4478cad774e6703bf3f54813Virustotal results 39/69 (56.52%) 216.239.32.21:443
2018-11-24 11:53:37526d0aa2e3d2980f6f66c4dd4106c8c5Virustotal results 41/70 (58.57%) 54.68.5.46:443
2018-11-23 04:28:05162c6f6b1e73f0733e3a932d8b07dc2eVirustotal results 37/68 (54.41%) 216.239.36.21:443
2018-11-03 15:59:1303fe25b72e3ec087d90409b482d31985Virustotal results 36/68 (52.94%) 205.251.242.103:443
2018-11-02 14:54:2188e28b13e57de6fdc2255ca8f437a08aVirustotal results 29/68 (42.65%) 176.32.103.205:443
2018-10-16 08:59:4349e432e58bd163f1ed814f54b7bed9f3Virustotal results 37/67 (55.22%) 31.13.93.35:443
2018-10-16 08:59:3849e432e58bd163f1ed814f54b7bed9f3Virustotal results 37/67 (55.22%) 205.251.242.103:443
2018-10-09 04:51:52e16582bbc7a4adcc0d7791b6b3ae6ca7Virustotal results 37/69 (53.62%) 31.13.65.36:443
2018-10-09 04:51:51e16582bbc7a4adcc0d7791b6b3ae6ca7Virustotal results 37/69 (53.62%) 176.32.98.166:443
2018-10-06 15:12:37fa4da11707ffb21046b362c7210eed90Virustotal results 15/68 (22.06%) 205.251.242.103:443
2018-10-06 03:10:33a84c251bd0191808f5b819e2b13f2a3dVirustotal results 36/68 (52.94%) 65.52.20.8:443
2018-10-06 03:10:32a84c251bd0191808f5b819e2b13f2a3dVirustotal results 36/68 (52.94%) 176.32.98.166:443
2018-09-30 01:38:160c79c9884f04a63edad772041ecd50b5Virustotal results 28/68 (41.18%) 176.32.98.166:443
2018-09-25 21:24:2317b28eae4c3ef0e41549951f2fa73ce9Virustotal results 32/69 (46.38%) 205.251.242.103:443
2018-09-25 21:24:2317b28eae4c3ef0e41549951f2fa73ce9Virustotal results 32/69 (46.38%) 65.52.20.8:443
2018-09-24 15:35:2599d88b733d1b0203e4ceb92100a837f3Virustotal results 40/69 (57.97%) 31.13.71.36:443
2018-09-24 15:35:2499d88b733d1b0203e4ceb92100a837f3Virustotal results 40/69 (57.97%) 176.32.103.205:443
2018-09-24 11:51:015793ba55688f17cfd1a5e730ea2e98b5Virustotal results 41/69 (59.42%) 176.32.98.166:443
2018-09-23 22:32:01c5b3ca71d7f1f05c00f48741c3950247Virustotal results 33/69 (47.83%) 65.52.20.8:443
2018-09-23 22:32:00c5b3ca71d7f1f05c00f48741c3950247Virustotal results 33/69 (47.83%) 176.32.98.166:443
2018-09-23 12:51:380b38568ec7adb2f5d2977e5c1976c108Virustotal results 35/68 (51.47%) 205.251.242.103:443
2018-09-23 12:51:380b38568ec7adb2f5d2977e5c1976c108Virustotal results 35/68 (51.47%) 31.13.71.36:443
2018-09-23 06:47:335652220f6a75f7f7dee8dfe8a8d93ff8Virustotal results 17/67 (25.37%) 31.13.71.36:443
2018-09-23 06:47:325652220f6a75f7f7dee8dfe8a8d93ff8Virustotal results 17/67 (25.37%) 176.32.98.166:443
2018-09-21 13:38:2186492826dd31d483cfaaf5487af1c245Virustotal results 42/69 (60.87%) 31.13.71.36:443
2018-09-21 13:38:2086492826dd31d483cfaaf5487af1c245Virustotal results 42/69 (60.87%) 176.32.98.166:443
2018-09-20 08:27:05f84127119454c0c202bb1dd6f820bf5cVirustotal results 36/68 (52.94%) 205.251.242.103:443
2018-09-20 08:27:05f84127119454c0c202bb1dd6f820bf5cVirustotal results 36/68 (52.94%) 31.13.65.36:443
2018-08-26 03:25:17104b66e2ff9ccd28ef2e0590b7b046a4Virustotal results 36/68 (52.94%) 176.32.103.205:443
2018-08-21 23:46:5559b2d88d5704527cccbdf1993f6b964cVirustotal results 40/68 (58.82%) 176.32.103.205:443
2018-08-21 23:46:5559b2d88d5704527cccbdf1993f6b964cVirustotal results 40/68 (58.82%) 31.13.65.36:443
2018-08-13 18:35:043f8f318fbe72fd714b3767443e8c18a8Virustotal results 38/68 (55.88%) 176.32.103.205:443
2018-08-13 18:35:043f8f318fbe72fd714b3767443e8c18a8Virustotal results 38/68 (55.88%) 157.240.2.35:443
2018-08-07 18:21:274fe8afdadf0ddec643493308652620a0Virustotal results 40/67 (59.70%) 176.32.98.166:443
2018-08-07 18:21:274fe8afdadf0ddec643493308652620a0Virustotal results 40/67 (59.70%) 31.13.65.36:443
2018-08-07 13:03:234b0fab311b25c26229effa2b81ce99dbVirustotal results 26/68 (38.24%) 205.251.242.103:443
2018-08-07 13:03:234b0fab311b25c26229effa2b81ce99dbVirustotal results 26/68 (38.24%) 157.240.2.35:443
2018-08-04 23:26:51d407e629d933030739dfc629142ff8deVirustotal results 35/68 (51.47%) 176.32.98.166:443
2018-08-02 06:13:15746eb72fe4d5096d836aefce59d06590Virustotal results 38/68 (55.88%) 205.251.242.103:443
2018-08-02 06:13:15746eb72fe4d5096d836aefce59d06590Virustotal results 38/68 (55.88%) 157.240.2.35:443
2018-08-02 06:13:15746eb72fe4d5096d836aefce59d06590Virustotal results 38/68 (55.88%) 157.240.2.38:443
2018-08-01 11:13:037bc29ec429894305af39db1655f21bebVirustotal results 25/68 (36.76%) 205.251.242.103:443
2018-08-01 11:13:037bc29ec429894305af39db1655f21bebVirustotal results 25/68 (36.76%) 157.240.2.35:443
2018-07-29 09:02:49b0e660a771ff4d8610fdab236e48ba7aVirustotal results 43/67 (64.18%) 176.32.98.166:443
2018-07-29 09:02:49b0e660a771ff4d8610fdab236e48ba7aVirustotal results 43/67 (64.18%) 157.240.2.35:443
2018-07-29 09:02:49b0e660a771ff4d8610fdab236e48ba7aVirustotal results 43/67 (64.18%) 157.240.2.38:443
2018-07-29 07:38:1327c67a7d1b63da485ed0657fe471a47aVirustotal results 17/68 (25.00%) 176.32.103.205:443
2018-07-29 07:38:1327c67a7d1b63da485ed0657fe471a47aVirustotal results 17/68 (25.00%) 157.240.2.35:443

# of entries: 100 (max: 100)