JA4 TLS client fingerprint
t12i130500_2d7513195f68_e51b7354d87f
Seen 2026-02-19 to 2026-09-22 across the retained window.
1.3K
Source IPs
14
Networks
13
Countries
914
Ports hit
63.1K
Events
90
IPs / network
Top networks
Countries
US 1.2KMN 23DE 4RO 4FR 3JP 2IN 2SG 2NL 1AT 1
What it requests
User agents claimed
Mozilla/5.0 zgrab/0.x197 IPs455
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4844.51 Safari/537.36144 IPs376
Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:102.0) Gecko/20100101 Firefox/102.0140 IPs374
Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:136.0) Gecko/20100101 Firefox/136.0151 IPs369
Mozilla/5.0 (Macintosh; Intel Mac OS X 14_4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36158 IPs369
Source IPCCNetwork
Last seenEvents
About this fingerprint
JA4 is a fingerprint of the TLS Client Hello: the version, cipher suites, extensions and signature algorithms a client offers when it opens an HTTPS connection. Clients built on the same library and version produce the same JA4, which makes it a durable handle on the tool behind the traffic.