HoneyLabs

JA4 TLS client fingerprint

t13i3111h1_e8f1e7e78f70_d41ae481755e

Seen 2026-02-25 to 2026-07-27 across the retained window.

53

Source IPs

17

Networks

14

Countries

45

Ports hit

451

Events

3

IPs / network

Top networks

Countries

US 18DE 16CA 3FR 2NL 2BG 2SG 2UA 2FI 1GB 1

Ports targeted

Source IPCCNetworkEvents
195.128.248.33UAAS6698 Virtual Systems LLC146
77.90.4.192DEAS214243 Marc Fischer66
45.148.10.166NLAS48090 Techoff Srv Limited59
194.110.87.216BGAS203380 DA International Group Ltd.51
176.120.22.113RUAS198953 Proton66 OOO51
93.123.109.214BGAS48090 Techoff Srv Limited10
141.11.107.134NLAS43350 NForce Entertainment B.V.6
34.9.221.106USAS396982 Google LLC6
35.228.236.33FIAS396982 Google LLC4
109.94.96.211DEAS396356 Latitude.sh3
129.213.82.146USAS31898 Oracle Corporation2
161.153.69.163USAS31898 Oracle Corporation2
45.138.16.178PLAS210558 1337 Services GmbH2
104.248.12.133USAS14061 DigitalOcean, LLC2
178.20.210.173DEAS210006 Shereverov Marat Ahmedovich2
212.227.244.14DEAS8560 IONOS SE2
129.213.78.179USAS31898 Oracle Corporation1
104.248.14.237USAS14061 DigitalOcean, LLC1
20.195.169.191BRAS8075 Microsoft Corporation1
148.116.84.248CAAS31898 Oracle Corporation1

About this fingerprint

JA4 is a fingerprint of the TLS Client Hello: the version, cipher suites, extensions and signature algorithms a client offers when it opens an HTTPS connection. Clients built on the same library and version produce the same JA4, which makes it a durable handle on the tool behind the traffic.