HoneyLabs

JA4 TLS client fingerprint

t13i1516h2_8daaf6152771_b1ff8ab2d16f

Seen 2026-04-10 to 2026-10-04 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS202425 sends an email when it next hits a sensor.

6

Source IPs

2

Networks

2

Countries

121

Ports hit

209

Events

3

IPs / network

Top networks

Countries

NL 5CA 1

Ports targeted

What it requests

GET/172
POST/home1
GET/.env1
GET/info1

User agents claimed

Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.365 IPs170
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.361 IPs39
Source IPCCNetwork Last seenEvents
93.174.93.12NLAS202425 IP Volume inc2026-10-0453
89.248.171.24NLAS202425 IP Volume inc2026-10-0343
62.93.167.153CAAS212238 Datacamp Limited2026-09-2139
80.82.77.202NLAS202425 IP Volume inc2026-10-0438
89.248.172.33NLAS202425 IP Volume inc2026-10-0434
89.248.171.23NLAS202425 IP Volume inc2026-09-062

About this fingerprint

JA4 is a fingerprint of the TLS Client Hello: the version, cipher suites, extensions and signature algorithms a client offers when it opens an HTTPS connection. Clients built on the same library and version produce the same JA4, which makes it a durable handle on the tool behind the traffic.