HoneyLabs

JA4 TLS client fingerprint

t13i140900_cbb2034c60b8_e7c285222651

Seen 2026-02-19 to 2026-09-30 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS396982 sends an email when it next hits a sensor.

658

Source IPs

23

Networks

15

Countries

1.5K

Ports hit

17.0K

Events

29

IPs / network

Top networks

Unattributed4 IPs12

Countries

US 516GB 106NL 17DE 7RU 2BG 1SG 1JP 1RO 1VN 1

Ports targeted

What it requests

POST/944
POST/query38
POST/resolve38
GET/ws29

User agents claimed

Hello from Palo Alto Networks, find out more about our scans in https://docs-cortex.paloaltonetworks.com/r/1/Cortex-Xpanse/Scanning-activity605 IPs15.3K
Mozilla/5.05 IPs574
Go-http-client/1.17 IPs457
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.362 IPs290
Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.367 IPs149
Source IPCCNetwork Last seenEvents
94.154.43.203NLAS219502 Storm Industries LLC2026-09-25524
185.218.86.25BGAS218785 Tc Datacenter Limited2026-09-19284
35.203.210.12GBAS396982 Google LLC2026-09-27214
147.185.133.201USAS396982 Google LLC2026-09-13203
162.216.150.16USAS396982 Google LLC2026-09-20201
35.203.210.97GBAS396982 Google LLC2026-09-06197
162.216.149.42USAS396982 Google LLC2026-09-27185
35.203.210.11GBAS396982 Google LLC2026-09-13183
162.216.150.105USAS396982 Google LLC2026-09-06172
35.203.210.6GBAS396982 Google LLC2026-09-06171
147.185.132.238USAS396982 Google LLC2026-09-13167
162.216.150.126USAS396982 Google LLC2026-09-27160
162.216.149.105USAS396982 Google LLC2026-09-13154
35.203.210.116GBAS396982 Google LLC2026-09-27144
162.216.149.252USAS396982 Google LLC2026-09-20134
35.203.211.87GBAS396982 Google LLC2026-09-13130
35.203.210.207GBAS396982 Google LLC2026-09-20129
162.216.149.235USAS396982 Google LLC2026-09-13122
35.203.210.247GBAS396982 Google LLC2026-09-06122
147.185.133.77USAS396982 Google LLC2026-09-13121

About this fingerprint

JA4 is a fingerprint of the TLS Client Hello: the version, cipher suites, extensions and signature algorithms a client offers when it opens an HTTPS connection. Clients built on the same library and version produce the same JA4, which makes it a durable handle on the tool behind the traffic.