JA4 TLS client fingerprint
t13d311100_e8f1e7e78f70_801c830e80cf
Seen 2026-02-19 to 2026-09-28 across the retained window.
The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked.
Or watch the top network: AS10439 sends an email when it next hits a sensor.
Countries
US 11NL 5CA 5GB 4
Source IPCCNetwork
Last seenEvents
93.174.95.106NLAS202425 IP Volume inc2026-09-2764 71.6.135.131USAS10439 CariNet, Inc.2026-09-2861 71.6.199.23USAS10439 CariNet, Inc.2026-09-2857 86.54.31.38CAAS12989 Black HOST Ltd2026-09-2848 80.82.77.139NLAS202425 IP Volume inc2026-09-2845 89.248.167.131NLAS202425 IP Volume inc2026-09-2442 86.54.31.34CAAS12989 Black HOST Ltd2026-09-2836 94.102.49.193NLAS202425 IP Volume inc2026-09-2834 71.6.158.166USAS10439 CariNet, Inc.2026-09-2832 66.240.192.138USAS10439 CariNet, Inc.2026-09-2832 80.82.77.33NLAS202425 IP Volume inc2026-09-2831 86.54.31.40CAAS12989 Black HOST Ltd2026-09-2531 86.54.31.32CAAS12989 Black HOST Ltd2026-09-2625 71.6.165.200USAS10439 CariNet, Inc.2026-09-2624 66.240.236.119USAS10439 CariNet, Inc.2026-09-2722 207.90.244.14USAS174 Cogent Communications, LLC2026-09-277 71.6.167.142USAS10439 CariNet, Inc.2026-09-285 71.6.146.186USAS10439 CariNet, Inc.2026-09-282 86.54.31.46CAAS12989 Black HOST Ltd2026-09-241 66.240.219.146USAS10439 CariNet, Inc.2026-09-271
About this fingerprint
JA4 is a fingerprint of the TLS Client Hello: the version, cipher suites, extensions and signature algorithms a client offers when it opens an HTTPS connection. Clients built on the same library and version produce the same JA4, which makes it a durable handle on the tool behind the traffic.