JA4 TLS client fingerprint
t13i140900_cbb2034c60b8_e7c285222651
Seen 2026-02-19 to 2026-09-30 across the retained window.
The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS396982 sends an email when it next hits a sensor.
658
Source IPs
23
Networks
15
Countries
1.5K
Ports hit
17.0K
Events
29
IPs / network
Top networks
Unattributed4 IPs12
Countries
US 516GB 106NL 17DE 7RU 2BG 1SG 1JP 1RO 1VN 1
What it requests
User agents claimed
Hello from Palo Alto Networks, find out more about our scans in https://docs-cortex.paloaltonetworks.com/r/1/Cortex-Xpanse/Scanning-activity605 IPs15.3K
Mozilla/5.05 IPs574
Go-http-client/1.17 IPs457
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.362 IPs290
Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.367 IPs149
Source IPCCNetwork
Last seenEvents
About this fingerprint
JA4 is a fingerprint of the TLS Client Hello: the version, cipher suites, extensions and signature algorithms a client offers when it opens an HTTPS connection. Clients built on the same library and version produce the same JA4, which makes it a durable handle on the tool behind the traffic.