HoneyLabs

JA4 TLS client fingerprint

t13i311000_e8f1e7e78f70_24695f2957a7

Seen 2026-02-19 to 2026-09-24 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS396982 sends an email when it next hits a sensor.

516

Source IPs

4

Networks

5

Countries

21

Ports hit

1.8K

Events

129

IPs / network

Top networks

Countries

US 511NL 2FR 1BR 1TW 1

Ports targeted

What it requests

GET/1.6K
GET/i1
GET/info1
GET/.env1

User agents claimed

curl/7.68.0486 IPs1.4K
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.361 IPs161
Mozilla/5.02 IPs35
Source IPCCNetwork Last seenEvents
164.92.211.98AS0 DigitalOcean, LLC2026-09-24161
172.234.162.226AS0 Akamai Connected Cloud2026-09-1634
198.235.24.56AS0 Google LLC2026-09-1710
198.235.24.76AS0 Google LLC2026-09-219
147.185.132.216AS0 Google LLC2026-09-199
198.235.24.175AS0 Google LLC2026-09-249
205.210.31.237AS0 Google LLC2026-09-209
205.210.31.74AS0 Google LLC2026-09-219
205.210.31.64AS0 Google LLC2026-09-198
147.185.132.135AS0 Google LLC2026-09-218
198.235.24.107AS0 Google LLC2026-09-098
205.210.31.66AS0 Google LLC2026-09-238
205.210.31.72AS0 Google LLC2026-09-228
147.185.132.19AS0 Google LLC2026-09-238
147.185.132.76AS0 Google LLC2026-09-248
205.210.31.176AS0 Google LLC2026-09-228
205.210.31.82AS0 Google LLC2026-09-217
205.210.31.54AS0 Google LLC2026-09-247
198.235.24.209AS0 Google LLC2026-09-187
198.235.24.229AS0 Google LLC2026-09-247

About this fingerprint

JA4 is a fingerprint of the TLS Client Hello: the version, cipher suites, extensions and signature algorithms a client offers when it opens an HTTPS connection. Clients built on the same library and version produce the same JA4, which makes it a durable handle on the tool behind the traffic.