HoneyLabs

JA4 TLS client fingerprint

t13i171000_ab0a1bf427ad_8e6e362c5eac

Seen 2026-06-23 to 2026-09-20 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS200373 sends an email when it next hits a sensor.

87

Source IPs

9

Networks

5

Countries

35

Ports hit

117

Events

10

IPs / network

Top networks

Countries

US 81CN 3ID 1HK 1SG 1

Ports targeted

What it requests

GET/6

User agents claimed

Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/129.0.0.0 Safari/537.3678 IPs78
curl/8.7.13 IPs26
Mozilla/5.03 IPs8
Ollama-asset-audit/1.01 IPs2
ollama-instance-inventory/1.01 IPs1
Source IPCCNetwork Last seenEvents
37.19.200.137AS0 Datacamp Limited2026-09-0214
155.2.191.24AS0 Host Universal Pty Ltd2026-09-028
118.99.91.132AS0 BIZNET NETWORKS2026-09-176
23.234.72.197AS0 tzulo, inc.2026-09-024
183.199.195.14AS0 Hebei Mobile Communication Company Limited2026-08-302
84.17.57.118AS0 Datacamp Limited2026-08-272
216.26.237.245AS0 3xK Tech GmbH2026-09-201
209.50.165.114AS0 3xK Tech GmbH2026-09-201
209.50.163.93AS0 3xK Tech GmbH2026-09-201
65.111.9.241AS0 3xK Tech GmbH2026-09-201
216.26.226.39AS0 3xK Tech GmbH2026-09-201
65.111.3.233AS0 3xK Tech GmbH2026-09-201
65.111.11.205AS0 3xK Tech GmbH2026-09-201
104.207.43.43AS0 3xK Tech GmbH2026-09-201
45.3.33.238AS0 3xK Tech GmbH2026-09-201
65.111.0.209AS0 3xK Tech GmbH2026-09-201
216.26.233.10AS0 3xK Tech GmbH2026-09-201
65.111.3.27AS0 3xK Tech GmbH2026-09-201
45.3.37.115AS0 3xK Tech GmbH2026-09-201
209.50.164.122AS0 3xK Tech GmbH2026-09-201

About this fingerprint

JA4 is a fingerprint of the TLS Client Hello: the version, cipher suites, extensions and signature algorithms a client offers when it opens an HTTPS connection. Clients built on the same library and version produce the same JA4, which makes it a durable handle on the tool behind the traffic.