HoneyLabs

JA4 TLS client fingerprint

t13i1515h2_8daaf6152771_e5627efa2ab1

Seen 2026-02-26 to 2026-06-28 across the retained window.

11

Source IPs

6

Networks

3

Countries

9

Ports hit

143

Events

2

IPs / network

This fingerprint is spread thinly across many networks, which is the shape of a common, widely-used client.

Top networks

Countries

CN 8GB 2US 1

Ports targeted

Source IPCCNetworkEvents
185.77.218.6USAS51765 Oy Crea Nova Hosting Solution Ltd52
146.70.119.22GBAS9009 M247 Europe SRL52
194.164.127.235GBAS8560 IONOS SE31
61.132.217.130CNAS4134 Chinanet1
49.112.136.3CNAS4134 Chinanet1
1.192.18.4CNAS4134 Chinanet1
111.172.6.50CNAS4134 Chinanet1
123.150.138.194CNAS17638 ASN for TIANJIN Provincial Net of CT1
171.83.2.151CNAS137266 CHINATELECOM Hubei province Wuhan 5G network1
59.52.226.146CNAS4134 Chinanet1
118.114.19.190CNAS4134 Chinanet1

About this fingerprint

JA4 is a fingerprint of the TLS Client Hello: the version, cipher suites, extensions and signature algorithms a client offers when it opens an HTTPS connection. Clients built on the same library and version produce the same JA4, which makes it a durable handle on the tool behind the traffic.