JA4 TLS client fingerprint
t13i1811h1_85036bcba153_d41ae481755e
Seen 2026-02-19 to 2026-09-24 across the retained window.
The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS21859 sends an email when it next hits a sensor.
66
Source IPs
23
Networks
12
Countries
29
Ports hit
992
Events
3
IPs / network
Top networks
Countries
PT 25US 16PL 5CN 4FR 4IN 3GB 3SG 2BG 1NL 1
What it requests
User agents claimed
Python/3.10 aiohttp/3.13.11 IPs96
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.0.0 Safari/537.361 IPs91
python-httpx/0.28.133 IPs82
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:110.0) Gecko/20100101 Firefox/110.01 IPs63
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Edge/113.0.1774.571 IPs57
Source IPCCNetwork
Last seenEvents
About this fingerprint
JA4 is a fingerprint of the TLS Client Hello: the version, cipher suites, extensions and signature algorithms a client offers when it opens an HTTPS connection. Clients built on the same library and version produce the same JA4, which makes it a durable handle on the tool behind the traffic.