HoneyLabs

JA4 TLS client fingerprint

t13i301000_1d37bd780c83_0d46a1bf4a7c

Seen 2026-07-01 to 2026-09-18 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS16509 sends an email when it next hits a sensor.

319

Source IPs

1

Networks

1

Countries

51

Ports hit

375

Events

319

IPs / network

This fingerprint is concentrated: many addresses on very few networks, which is what a single coordinated operation tends to look like.

Top networks

Countries

US 319

Ports targeted

What it requests

GET/310
GET/api/4

User agents claimed

Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36286 IPs338
Source IPCCNetwork Last seenEvents
16.146.29.42AS0 Amazon.com, Inc.2026-09-044
50.18.65.117AS0 Amazon.com, Inc.2026-08-304
35.91.11.215AS0 Amazon.com, Inc.2026-08-263
16.147.186.156AS0 Amazon.com, Inc.2026-09-153
34.222.191.81AS0 Amazon.com, Inc.2026-09-032
52.8.27.221AS0 Amazon.com, Inc.2026-09-152
54.241.58.70AS0 Amazon.com, Inc.2026-08-312
3.101.155.97AS0 Amazon.com, Inc.2026-08-312
54.153.23.203AS0 Amazon.com, Inc.2026-08-312
54.176.47.33AS0 Amazon.com, Inc.2026-08-282
54.176.228.125AS0 Amazon.com, Inc.2026-09-172
35.94.93.81AS0 Amazon.com, Inc.2026-08-282
100.23.160.246AS0 Amazon.com, Inc.2026-08-272
18.237.132.176AS0 Amazon.com, Inc.2026-08-262
184.32.33.234AS0 Amazon.com, Inc.2026-09-172
54.67.44.118AS0 Amazon.com, Inc.2026-09-042
13.52.184.104AS0 Amazon.com, Inc.2026-09-122
13.52.219.202AS0 Amazon.com, Inc.2026-09-122
18.144.28.142AS0 Amazon.com, Inc.2026-09-012
44.244.80.148AS0 Amazon.com, Inc.2026-09-052

About this fingerprint

JA4 is a fingerprint of the TLS Client Hello: the version, cipher suites, extensions and signature algorithms a client offers when it opens an HTTPS connection. Clients built on the same library and version produce the same JA4, which makes it a durable handle on the tool behind the traffic.