HoneyLabs

JA4 TLS client fingerprint

t12i990600_a40d17a72bcb_4446390ac224

Seen 2026-02-22 to 2026-09-24 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS37963 sends an email when it next hits a sensor.

30

Source IPs

4

Networks

2

Countries

199

Ports hit

321

Events

8

IPs / network

Top networks

Countries

CN 29ZA 1

Ports targeted

What it requests

GET/115
POST/sdk25
GET/HNAP118

User agents claimed

Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)24 IPs181
Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.2623.112 Safari/537.362 IPs20
Source IPCCNetwork Last seenEvents
112.124.56.253AS0 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-1140
47.94.138.70AS0 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-0929
47.95.209.77AS0 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-0928
121.43.117.235AS0 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-1626
115.231.78.11AS0 CT-HangZhou-IDC2026-09-0223
121.41.165.169AS0 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-0716
47.95.210.78AS0 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-1016
121.40.47.199AS0 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-0915
47.94.165.91AS0 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-0913
121.41.170.8AS0 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-0512
168.76.20.229AS0 ASLINE LIMITED2026-09-2411
121.199.160.207AS0 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-0510
121.41.169.123AS0 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-0910
47.94.82.6AS0 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-108
121.40.43.226AS0 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-077
39.100.83.5AS0 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-167
47.99.109.105AS0 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-057
112.124.22.223AS0 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-015
121.40.47.87AS0 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-095
112.124.56.43AS0 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-014

About this fingerprint

JA4 is a fingerprint of the TLS Client Hello: the version, cipher suites, extensions and signature algorithms a client offers when it opens an HTTPS connection. Clients built on the same library and version produce the same JA4, which makes it a durable handle on the tool behind the traffic.