JA4 TLS client fingerprint
t13i180900_85036bcba153_1f22a2ca17c4
Seen 2026-02-23 to 2026-09-17 across the retained window.
54
Source IPs
3
Networks
11
Countries
5
Ports hit
55
Events
18
IPs / network
This fingerprint is concentrated: many addresses on very few networks, which is what a single coordinated operation tends to look like.
Top networks
Countries
US 12AU 6FI 6CH 5BR 5NL 4GB 4DE 4BE 3DZ 3
Ports targeted
What it requests
User agents claimed
Mozilla/5.03 IPs3
Source IPCCNetwork
Last seenEvents
About this fingerprint
JA4 is a fingerprint of the TLS Client Hello: the version, cipher suites, extensions and signature algorithms a client offers when it opens an HTTPS connection. Clients built on the same library and version produce the same JA4, which makes it a durable handle on the tool behind the traffic.