HoneyLabs

JA4 TLS client fingerprint

t13i300900_3c43a67630b3_e7c285222651

Seen 2026-02-19 to 2026-09-24 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS211298 sends an email when it next hits a sensor.

147

Source IPs

1

Networks

1

Countries

41

Ports hit

170

Events

147

IPs / network

This fingerprint is concentrated: many addresses on very few networks, which is what a single coordinated operation tends to look like.

Top networks

Countries

GB 147

Ports targeted

What it requests

GET/115

User agents claimed

Mozilla/5.0 (compatible; InternetMeasurement/1.0; +https://internet-measurement.com/)112 IPs115
Source IPCCNetwork Last seenEvents
195.96.139.212AS0 Driftnet Ltd2026-09-244
195.96.139.190AS0 Driftnet Ltd2026-09-233
87.236.176.144AS0 Driftnet Ltd2026-09-243
195.96.139.208AS0 Driftnet Ltd2026-09-232
87.236.176.166AS0 Driftnet Ltd2026-09-242
185.247.137.155AS0 Driftnet Ltd2026-09-242
195.96.139.252AS0 Driftnet Ltd2026-09-242
87.236.176.209AS0 Driftnet Ltd2026-09-232
195.96.139.146AS0 Driftnet Ltd2026-09-242
87.236.176.147AS0 Driftnet Ltd2026-09-242
87.236.176.161AS0 Driftnet Ltd2026-09-242
195.96.139.155AS0 Driftnet Ltd2026-09-242
87.236.176.176AS0 Driftnet Ltd2026-09-242
87.236.176.203AS0 Driftnet Ltd2026-08-312
87.236.176.74AS0 Driftnet Ltd2026-09-222
87.236.176.222AS0 Driftnet Ltd2026-09-232
195.96.139.206AS0 Driftnet Ltd2026-09-042
87.236.176.155AS0 Driftnet Ltd2026-09-242
87.236.176.182AS0 Driftnet Ltd2026-09-232
195.96.139.114AS0 Driftnet Ltd2026-09-141

About this fingerprint

JA4 is a fingerprint of the TLS Client Hello: the version, cipher suites, extensions and signature algorithms a client offers when it opens an HTTPS connection. Clients built on the same library and version produce the same JA4, which makes it a durable handle on the tool behind the traffic.