HoneyLabs

JA4 TLS client fingerprint

t13i1113h2_5e2a75874763_89e9e4bb3419

Seen 2026-04-16 to 2026-07-27 across the retained window.

11

Source IPs

2

Networks

2

Countries

280

Ports hit

674

Events

6

IPs / network

Top networks

Countries

DE 10VU 1

Ports targeted

Source IPCCNetworkEvents
88.214.25.134DEAS35042 Layer7 Networks GmbH88
88.214.25.130DEAS35042 Layer7 Networks GmbH87
88.214.25.137DEAS35042 Layer7 Networks GmbH82
88.214.25.138DEAS35042 Layer7 Networks GmbH76
88.214.25.135DEAS35042 Layer7 Networks GmbH73
88.214.25.131DEAS35042 Layer7 Networks GmbH72
88.214.25.136DEAS35042 Layer7 Networks GmbH66
88.214.25.132DEAS35042 Layer7 Networks GmbH64
88.214.25.133DEAS35042 Layer7 Networks GmbH59
88.214.25.59DEAS35042 Layer7 Networks GmbH6
147.45.112.222VUAS209132 Alviva Holding Limited1

About this fingerprint

JA4 is a fingerprint of the TLS Client Hello: the version, cipher suites, extensions and signature algorithms a client offers when it opens an HTTPS connection. Clients built on the same library and version produce the same JA4, which makes it a durable handle on the tool behind the traffic.