JA4 TLS client fingerprint
t13i1909h1_9dc949149365_97f8aa674fd9
Seen 2026-02-19 to 2026-09-24 across the retained window.
The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS396982 sends an email when it next hits a sensor.
382
Source IPs
7
Networks
11
Countries
858
Ports hit
25.9K
Events
55
IPs / network
Top networks
Countries
US 251PT 92FR 31DE 1IN 1GB 1NL 1SG 1CA 1AU 1
What it requests
User agents claimed
Mozilla/5.0 (compatible; GenomeCrawlerd/1.0; +https://www.nokia.com/genomecrawler)280 IPs25.8K
Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.6312.86 Safari/537.3692 IPs121
Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:156.0) Gecko/20100101 Firefox/156.08 IPs8
Mozilla/5.0 zgrab/0.x1 IPs4
Mozilla/5.0 (compatible; idxd/1.0; +https://idxd.io/)1 IPs2
Source IPCCNetwork
Last seenEvents
About this fingerprint
JA4 is a fingerprint of the TLS Client Hello: the version, cipher suites, extensions and signature algorithms a client offers when it opens an HTTPS connection. Clients built on the same library and version produce the same JA4, which makes it a durable handle on the tool behind the traffic.