HoneyLabs

JA4 TLS client fingerprint

t13i3012h1_1d37bd780c83_8537cf56674e

Seen 2026-03-04 to 2026-07-24 across the retained window.

9

Source IPs

9

Networks

7

Countries

9

Ports hit

80

Events

1

IPs / network

This fingerprint is spread thinly across many networks, which is the shape of a common, widely-used client.

Top networks

Countries

NL 2DE 2SG 1CA 1RU 1AU 1US 1

Ports targeted

Source IPCCNetworkEvents
91.215.85.104RUAS200593 Prospero Ooo24
209.54.124.33CAAS400724 EZProvider Networks, Inc.22
5.181.177.123NLAS214677 DELUXHOST20
175.41.159.224SGAS16509 Amazon.com, Inc.3
31.220.100.250USAS40021 Contabo Inc.3
45.140.188.18NLAS212477 RoyaleHosting BV2
83.172.138.236DEAS9009 M247 Europe SRL2
109.123.227.33AUAS141995 Contabo Asia Private Limited2
207.154.208.244DEAS14061 DigitalOcean, LLC2

About this fingerprint

JA4 is a fingerprint of the TLS Client Hello: the version, cipher suites, extensions and signature algorithms a client offers when it opens an HTTPS connection. Clients built on the same library and version produce the same JA4, which makes it a durable handle on the tool behind the traffic.