JA4 TLS client fingerprint
t13i191000_9dc949149365_e5728521abd4
Seen 2026-02-19 to 2026-09-24 across the retained window.
The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS14061 sends an email when it next hits a sensor.
202
Source IPs
36
Networks
19
Countries
100
Ports hit
8.8K
Events
6
IPs / network
Top networks
Countries
DE 97HK 30CN 18US 15RO 14IN 4NL 4BG 3SI 3RU 3
What it requests
User agents claimed
l9explore/1.2.25 IPs6.4K
Go-http-client/1.1100 IPs1.7K
l9tcpid/v1.1.04 IPs138
Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.019 IPs85
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 Chrome/120.0.0.0 Safari/537.3612 IPs78
Source IPCCNetwork
Last seenEvents
About this fingerprint
JA4 is a fingerprint of the TLS Client Hello: the version, cipher suites, extensions and signature algorithms a client offers when it opens an HTTPS connection. Clients built on the same library and version produce the same JA4, which makes it a durable handle on the tool behind the traffic.