JA4 TLS client fingerprint
t13i311000_e8f1e7e78f70_24695f2957a7
Seen 2026-02-19 to 2026-09-24 across the retained window.
The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS396982 sends an email when it next hits a sensor.
516
Source IPs
4
Networks
5
Countries
21
Ports hit
1.8K
Events
129
IPs / network
Top networks
Countries
US 511NL 2FR 1BR 1TW 1
What it requests
User agents claimed
curl/7.68.0486 IPs1.4K
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.361 IPs161
Mozilla/5.02 IPs35
Source IPCCNetwork
Last seenEvents
About this fingerprint
JA4 is a fingerprint of the TLS Client Hello: the version, cipher suites, extensions and signature algorithms a client offers when it opens an HTTPS connection. Clients built on the same library and version produce the same JA4, which makes it a durable handle on the tool behind the traffic.