JA4 TLS client fingerprint
t13i3111h1_e8f1e7e78f70_8d633dac7124
Seen 2026-03-03 to 2026-09-24 across the retained window.
The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS63949 sends an email when it next hits a sensor.
22
Source IPs
3
Networks
3
Countries
2
Ports hit
389
Events
7
IPs / network
This fingerprint is concentrated: many addresses on very few networks, which is what a single coordinated operation tends to look like.
Top networks
Countries
Ports targeted
What it requests
User agents claimed
About this fingerprint
JA4 is a fingerprint of the TLS Client Hello: the version, cipher suites, extensions and signature algorithms a client offers when it opens an HTTPS connection. Clients built on the same library and version produce the same JA4, which makes it a durable handle on the tool behind the traffic.