JA4 TLS client fingerprint
t12i210600_76e208dd3e22_2dae41c691ec
Seen 2026-03-10 to 2026-09-24 across the retained window.
The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS9009 sends an email when it next hits a sensor.
28
Source IPs
5
Networks
6
Countries
440
Ports hit
786
Events
6
IPs / network
Top networks
Countries
IR 13RU 8DE 3US 2AT 1UA 1
What it requests
User agents claimed
Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.025 IPs588
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36 Edg/151.0.0.01 IPs1
Source IPCCNetwork
Last seenEvents
About this fingerprint
JA4 is a fingerprint of the TLS Client Hello: the version, cipher suites, extensions and signature algorithms a client offers when it opens an HTTPS connection. Clients built on the same library and version produce the same JA4, which makes it a durable handle on the tool behind the traffic.