HoneyLabs

JA4 TLS client fingerprint

t13i1311h2_f57a46bbacb6_f50d94e863eb

Seen 2026-09-01 to 2026-09-24 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS45102 sends an email when it next hits a sensor.

2.4K

Source IPs

3

Networks

5

Countries

2.1K

Ports hit

7.7K

Events

783

IPs / network

This fingerprint is concentrated: many addresses on very few networks, which is what a single coordinated operation tends to look like.

Top networks

Countries

US 683JP 464DE 446MY 401SG 356

Ports targeted

What it requests

GET/6.3K
GET/@hmr72

User agents claimed

curl/7.74.02.3K IPs6.2K
vitesweep/13 IPs1.1K
Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.361 IPs462
Mozilla/5.0 (compatible; Crusader/1.0)2 IPs3
Source IPCCNetwork Last seenEvents
67.213.121.153AS0 Latitude.sh2026-09-11970
64.34.81.199AS0 Latitude.sh2026-09-20312
67.213.122.19AS0 Latitude.sh2026-09-20275
47.251.37.0AS0 Alibaba (US) Technology Co., Ltd.2026-09-2410
47.251.141.39AS0 Alibaba (US) Technology Co., Ltd.2026-09-2410
8.211.13.101AS0 Alibaba (US) Technology Co., Ltd.2026-09-209
47.245.142.224AS0 Alibaba (US) Technology Co., Ltd.2026-09-249
8.211.15.153AS0 Alibaba (US) Technology Co., Ltd.2026-09-219
47.250.121.46AS0 Alibaba (US) Technology Co., Ltd.2026-09-218
47.251.141.235AS0 Alibaba (US) Technology Co., Ltd.2026-09-238
47.251.118.137AS0 Alibaba (US) Technology Co., Ltd.2026-09-248
8.211.46.74AS0 Alibaba (US) Technology Co., Ltd.2026-09-228
47.250.127.65AS0 Alibaba (US) Technology Co., Ltd.2026-09-228
47.250.93.211AS0 Alibaba (US) Technology Co., Ltd.2026-09-228
47.250.14.85AS0 Alibaba (US) Technology Co., Ltd.2026-09-238
8.216.9.247AS0 Alibaba (US) Technology Co., Ltd.2026-09-248
47.245.143.238AS0 Alibaba (US) Technology Co., Ltd.2026-09-238
47.250.180.183AS0 Alibaba (US) Technology Co., Ltd.2026-09-228
47.254.167.143AS0 Alibaba (US) Technology Co., Ltd.2026-09-238
8.209.83.9AS0 Alibaba (US) Technology Co., Ltd.2026-09-248

About this fingerprint

JA4 is a fingerprint of the TLS Client Hello: the version, cipher suites, extensions and signature algorithms a client offers when it opens an HTTPS connection. Clients built on the same library and version produce the same JA4, which makes it a durable handle on the tool behind the traffic.