HoneyLabs

JA4 TLS client fingerprint

t13d131100_f57a46bbacb6_ab7e3b40a677

Seen 2026-03-13 to 2026-09-28 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS396982 sends an email when it next hits a sensor.

27

Source IPs

6

Networks

4

Countries

5

Ports hit

30

Events

4

IPs / network

Top networks

Countries

US 24CY 1FR 1BE 1

Ports targeted

What it requests

GET/22

User agents claimed

Hello from Palo Alto Networks, find out more about our scans in https://docs-cortex.paloaltonetworks.com/r/1/Cortex-Xpanse/Scanning-activity16 IPs16
Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)8 IPs8
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.361 IPs3
Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.361 IPs2
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.361 IPs1
Source IPCCNetwork Last seenEvents
128.0.241.150CYAS6866 Cyprus Telecommunications Authority2026-09-123
37.59.123.164FRAS16276 OVH SAS2026-09-022
205.210.31.206USAS396982 Google LLC2026-09-231
198.235.24.184USAS396982 Google LLC2026-09-111
199.45.155.21USAS398722 Censys, Inc.2026-09-261
198.235.24.76USAS396982 Google LLC2026-09-261
198.235.24.99USAS396982 Google LLC2026-09-121
205.210.31.146USAS396982 Google LLC2026-09-281
205.210.31.228USAS396982 Google LLC2026-09-251
205.210.31.30USAS396982 Google LLC2026-09-281
66.132.224.237USAS398324 Censys, Inc.2026-09-261
199.45.154.56USAS398722 Censys, Inc.2026-09-271
199.45.154.47USAS398722 Censys, Inc.2026-09-271
147.185.132.46USAS396982 Google LLC2026-09-231
66.132.172.210USAS398324 Censys, Inc.2026-09-271
205.210.31.23USAS396982 Google LLC2026-09-231
205.210.31.11USAS396982 Google LLC2026-09-271
198.235.24.49USAS396982 Google LLC2026-09-131
147.185.132.150USAS396982 Google LLC2026-09-261
205.210.31.197USAS396982 Google LLC2026-09-261

About this fingerprint

JA4 is a fingerprint of the TLS Client Hello: the version, cipher suites, extensions and signature algorithms a client offers when it opens an HTTPS connection. Clients built on the same library and version produce the same JA4, which makes it a durable handle on the tool behind the traffic.