HoneyLabs

JA4 TLS client fingerprint

t13i181000_85036bcba153_d41ae481755e

Seen 2026-02-20 to 2026-09-28 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS201579 sends an email when it next hits a sensor.

Known fingerprint

[Python]

67

Source IPs

33

Networks

23

Countries

36

Ports hit

1.2K

Events

2

IPs / network

Top networks

Countries

GB 12PT 10US 9FR 7NL 6ES 2KR 2IN 2RU 2SE 2

Ports targeted

What it requests

POST/371
GET/WuEL33
GET/a32

User agents claimed

Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.61 Safari/537.3616 IPs456
Mozilla/5.019 IPs100
Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0; ; NCLIENT50_AAPCDA5841E333)16 IPs33
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.361 IPs11
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.362 IPs11
Source IPCCNetwork Last seenEvents
193.32.126.225FRAS39351 31173 Services AB2026-09-16204
84.32.41.99GBAS201579 Hostgnome Ltd2026-09-1996
91.237.124.244GBAS201579 Hostgnome Ltd2026-09-2783
193.138.195.45GBAS201579 Hostgnome Ltd2026-09-2669
91.237.124.248GBAS201579 Hostgnome Ltd2026-09-2667
185.91.69.77GBAS201579 Hostgnome Ltd2026-09-1364
91.237.124.246GBAS201579 Hostgnome Ltd2026-09-1562
57.128.237.218PLAS16276 OVH SAS2026-09-2460
96.126.104.20USAS63949 Akamai Connected Cloud2026-09-2855
193.138.195.140GBAS201579 Hostgnome Ltd2026-09-1146
193.138.195.128GBAS201579 Hostgnome Ltd2026-09-1637
88.151.33.178NLAS41608 NextGenWebs, S.L.2026-09-2432
88.151.33.172NLAS41608 NextGenWebs, S.L.2026-09-2732
185.91.69.33GBAS201579 Hostgnome Ltd2026-09-0332
195.170.172.215ESAS41608 NextGenWebs, S.L.2026-09-1932
88.151.33.176NLAS41608 NextGenWebs, S.L.2026-09-0832
84.32.41.248GBAS201579 Hostgnome Ltd2026-09-2730
193.138.195.188GBAS201579 Hostgnome Ltd2026-09-1922
185.91.69.128GBAS201579 Hostgnome Ltd2026-09-1516
185.209.15.121EEAS61254 ESTOXY OU2026-09-2111

About this fingerprint

JA4 is a fingerprint of the TLS Client Hello: the version, cipher suites, extensions and signature algorithms a client offers when it opens an HTTPS connection. Clients built on the same library and version produce the same JA4, which makes it a durable handle on the tool behind the traffic.