HoneyLabs

JA4 TLS client fingerprint

t13d2512h1_b78ed14e2fd0_ab7e3b40a677

Seen 2026-09-23 to 2026-09-24 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS16509 sends an email when it next hits a sensor.

25

Source IPs

1

Networks

1

Countries

10

Ports hit

29

Events

25

IPs / network

This fingerprint is concentrated: many addresses on very few networks, which is what a single coordinated operation tends to look like.

Top networks

Countries

US 25

Ports targeted

What it requests

GET/12

User agents claimed

Mozilla/5.0 (compatible; wpbot/1.4; +https://forms.gle/ajBaxygz9jSR8p8G9)25 IPs29
Source IPCCNetwork Last seenEvents
35.95.87.94AS0 Amazon.com, Inc.2026-09-242
35.87.225.239AS0 Amazon.com, Inc.2026-09-232
44.234.119.239AS0 Amazon.com, Inc.2026-09-232
35.93.94.245AS0 Amazon.com, Inc.2026-09-232
35.86.198.192AS0 Amazon.com, Inc.2026-09-231
44.243.52.6AS0 Amazon.com, Inc.2026-09-241
35.80.33.26AS0 Amazon.com, Inc.2026-09-241
44.242.171.142AS0 Amazon.com, Inc.2026-09-231
34.223.88.29AS0 Amazon.com, Inc.2026-09-241
32.184.9.131AS0 Amazon.com, Inc.2026-09-231
35.87.186.117AS0 Amazon.com, Inc.2026-09-231
35.81.167.163AS0 Amazon.com, Inc.2026-09-241
44.242.141.17AS0 Amazon.com, Inc.2026-09-231
35.80.14.99AS0 Amazon.com, Inc.2026-09-231
184.33.240.178AS0 Amazon.com, Inc.2026-09-231
35.84.179.95AS0 Amazon.com, Inc.2026-09-241
35.95.79.0AS0 Amazon.com, Inc.2026-09-241
44.250.208.184AS0 Amazon.com, Inc.2026-09-231
16.146.156.184AS0 Amazon.com, Inc.2026-09-241
44.234.121.37AS0 Amazon.com, Inc.2026-09-231

About this fingerprint

JA4 is a fingerprint of the TLS Client Hello: the version, cipher suites, extensions and signature algorithms a client offers when it opens an HTTPS connection. Clients built on the same library and version produce the same JA4, which makes it a durable handle on the tool behind the traffic.