HoneyLabs

JA4 TLS client fingerprint

t12i570500_2a2bed94251f_a1e935682795

Seen 2026-02-19 to 2026-09-28 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS10439 sends an email when it next hits a sensor.

21

Source IPs

5

Networks

4

Countries

53

Ports hit

666

Events

4

IPs / network

Top networks

Countries

US 11NL 5CA 5GB 4

Ports targeted

What it requests

GET/491

User agents claimed

Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/98.0.4758.102 Safari/537.3621 IPs491
Source IPCCNetwork Last seenEvents
71.6.199.23USAS10439 CariNet, Inc.2026-09-2872
93.174.95.106NLAS202425 IP Volume inc2026-09-2767
71.6.135.131USAS10439 CariNet, Inc.2026-09-2865
89.248.167.131NLAS202425 IP Volume inc2026-09-2447
80.82.77.139NLAS202425 IP Volume inc2026-09-2847
86.54.31.38CAAS12989 Black HOST Ltd2026-09-2845
66.240.192.138USAS10439 CariNet, Inc.2026-09-2845
86.54.31.34CAAS12989 Black HOST Ltd2026-09-2637
86.54.31.40CAAS12989 Black HOST Ltd2026-09-2536
94.102.49.193NLAS202425 IP Volume inc2026-09-2834
71.6.158.166USAS10439 CariNet, Inc.2026-09-2831
66.240.236.119USAS10439 CariNet, Inc.2026-09-2728
80.82.77.33NLAS202425 IP Volume inc2026-09-2828
86.54.31.32CAAS12989 Black HOST Ltd2026-09-2627
207.90.244.14USAS174 Cogent Communications, LLC2026-09-2725
71.6.165.200USAS10439 CariNet, Inc.2026-09-2621
86.54.31.46CAAS12989 Black HOST Ltd2026-09-244
71.6.167.142USAS10439 CariNet, Inc.2026-09-284
66.240.219.146USAS10439 CariNet, Inc.2026-09-271
71.6.146.186USAS10439 CariNet, Inc.2026-09-281

About this fingerprint

JA4 is a fingerprint of the TLS Client Hello: the version, cipher suites, extensions and signature algorithms a client offers when it opens an HTTPS connection. Clients built on the same library and version produce the same JA4, which makes it a durable handle on the tool behind the traffic.