JA4 TLS client fingerprint
t13i1811h1_85036bcba153_b26ce05bbdd6
Seen 2026-02-19 to 2026-09-23 across the retained window.
The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS135377 sends an email when it next hits a sensor.
50
Source IPs
18
Networks
24
Countries
18
Ports hit
1.5K
Events
3
IPs / network
Top networks
Countries
US 10PL 5TH 5HK 5FR 3NL 2IN 2PH 2ID 1MA 1
What it requests
User agents claimed
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.362 IPs804
Mozilla/5.0 (iPad; CPU OS 17_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Mobile/15E148 Safari/604.11 IPs94
Mozilla/5.0 (Linux; Android 14; Pixel 8) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.6099.144 Mobile Safari/537.361 IPs93
Mozilla/5.0 (Macintosh; Intel Mac OS X 14_3_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3.1 Safari/605.1.151 IPs78
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36 Edg/121.0.0.01 IPs77
Source IPCCNetwork
Last seenEvents
About this fingerprint
JA4 is a fingerprint of the TLS Client Hello: the version, cipher suites, extensions and signature algorithms a client offers when it opens an HTTPS connection. Clients built on the same library and version produce the same JA4, which makes it a durable handle on the tool behind the traffic.