JA4 TLS client fingerprint
t13i301000_1d37bd780c83_0d46a1bf4a7c
Seen 2026-07-01 to 2026-09-18 across the retained window.
The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked.
Or watch the top network: AS16509 sends an email when it next hits a sensor.
This fingerprint is concentrated: many addresses on very few networks, which is what a single coordinated operation tends to look like.
User agents claimed
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.36286 IPs338
Source IPCCNetwork
Last seenEvents
16.146.29.42AS0 Amazon.com, Inc.2026-09-044 50.18.65.117AS0 Amazon.com, Inc.2026-08-304 35.91.11.215AS0 Amazon.com, Inc.2026-08-263 16.147.186.156AS0 Amazon.com, Inc.2026-09-153 34.222.191.81AS0 Amazon.com, Inc.2026-09-032 52.8.27.221AS0 Amazon.com, Inc.2026-09-152 54.241.58.70AS0 Amazon.com, Inc.2026-08-312 3.101.155.97AS0 Amazon.com, Inc.2026-08-312 54.153.23.203AS0 Amazon.com, Inc.2026-08-312 54.176.47.33AS0 Amazon.com, Inc.2026-08-282 54.176.228.125AS0 Amazon.com, Inc.2026-09-172 35.94.93.81AS0 Amazon.com, Inc.2026-08-282 100.23.160.246AS0 Amazon.com, Inc.2026-08-272 18.237.132.176AS0 Amazon.com, Inc.2026-08-262 184.32.33.234AS0 Amazon.com, Inc.2026-09-172 54.67.44.118AS0 Amazon.com, Inc.2026-09-042 13.52.184.104AS0 Amazon.com, Inc.2026-09-122 13.52.219.202AS0 Amazon.com, Inc.2026-09-122 18.144.28.142AS0 Amazon.com, Inc.2026-09-012 44.244.80.148AS0 Amazon.com, Inc.2026-09-052
About this fingerprint
JA4 is a fingerprint of the TLS Client Hello: the version, cipher suites, extensions and signature algorithms a client offers when it opens an HTTPS connection. Clients built on the same library and version produce the same JA4, which makes it a durable handle on the tool behind the traffic.