HoneyLabs

JA4 TLS client fingerprint

t12i520600_3874cc0afe49_d74d77c6171b

Seen 2026-02-22 to 2026-09-23 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS396982 sends an email when it next hits a sensor.

124

Source IPs

1

Networks

2

Countries

123

Ports hit

129

Events

124

IPs / network

This fingerprint is concentrated: many addresses on very few networks, which is what a single coordinated operation tends to look like.

Top networks

Countries

US 83GB 41

Ports targeted

What it requests

GET/128

User agents claimed

Hello from Palo Alto Networks, find out more about our scans in https://docs-cortex.paloaltonetworks.com/r/1/Cortex-Xpanse/Scanning-activity124 IPs129
Source IPCCNetwork Last seenEvents
147.185.133.179AS0 Google LLC2026-08-282
35.203.211.241AS0 Google LLC2026-08-282
35.203.211.167AS0 Google LLC2026-08-292
35.203.210.134AS0 Google LLC2026-08-292
35.203.210.23AS0 Google LLC2026-09-042
162.216.149.29AS0 Google LLC2026-08-271
147.185.132.35AS0 Google LLC2026-09-021
147.185.132.223AS0 Google LLC2026-09-011
147.185.133.174AS0 Google LLC2026-09-041
162.216.149.32AS0 Google LLC2026-08-301
35.203.211.228AS0 Google LLC2026-08-281
147.185.132.41AS0 Google LLC2026-09-021
35.203.210.31AS0 Google LLC2026-08-291
162.216.149.93AS0 Google LLC2026-08-281
162.216.149.160AS0 Google LLC2026-09-031
147.185.133.24AS0 Google LLC2026-08-281
162.216.150.44AS0 Google LLC2026-08-281
198.235.24.76AS0 Google LLC2026-08-281
35.203.211.250AS0 Google LLC2026-08-281
205.210.31.16AS0 Google LLC2026-08-281

About this fingerprint

JA4 is a fingerprint of the TLS Client Hello: the version, cipher suites, extensions and signature algorithms a client offers when it opens an HTTPS connection. Clients built on the same library and version produce the same JA4, which makes it a durable handle on the tool behind the traffic.