JA4 TLS client fingerprint
t12i130500_2d7513195f68_021165082e1c
Seen 2026-02-21 to 2026-09-24 across the retained window.
The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS211680 sends an email when it next hits a sensor.
45
Source IPs
4
Networks
3
Countries
7
Ports hit
106
Events
11
IPs / network
Top networks
Countries
PT 37US 7NL 1
What it requests
User agents claimed
Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.6312.86 Safari/537.3637 IPs71
Mozilla/5.0 zgrab/0.x7 IPs31
Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/44.0.2403.157 Safari/537.361 IPs4
Source IPCCNetwork
Last seenEvents
About this fingerprint
JA4 is a fingerprint of the TLS Client Hello: the version, cipher suites, extensions and signature algorithms a client offers when it opens an HTTPS connection. Clients built on the same library and version produce the same JA4, which makes it a durable handle on the tool behind the traffic.