JA4 TLS client fingerprint
t13i141000_cbb2034c60b8_e5728521abd4
Seen 2026-03-17 to 2026-09-19 across the retained window.
10
Source IPs
9
Networks
6
Countries
101
Ports hit
27.1K
Events
1
IPs / network
This fingerprint is spread thinly across many networks, which is the shape of a common, widely-used client.
Top networks
Countries
NL 3US 2DE 2BG 1BE 1JP 1
What it requests
User agents claimed
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.363 IPs3.4K
Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:125.0) Gecko/20100101 Firefox/125.03 IPs3.4K
Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.5 Safari/605.1.153 IPs3.3K
Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.363 IPs3.3K
Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:126.0) Gecko/20100101 Firefox/126.03 IPs3.2K
Source IPCCNetwork
Last seenEvents
About this fingerprint
JA4 is a fingerprint of the TLS Client Hello: the version, cipher suites, extensions and signature algorithms a client offers when it opens an HTTPS connection. Clients built on the same library and version produce the same JA4, which makes it a durable handle on the tool behind the traffic.