HoneyLabs

JA4 TLS client fingerprint

t13i351200_bfa337485184_678a800b2221

Seen 2026-06-21 to 2026-07-23 across the retained window.

3

Source IPs

4

Networks

4

Countries

14

Ports hit

346

Events

1

IPs / network

This fingerprint is spread thinly across many networks, which is the shape of a common, widely-used client.

Top networks

AS0 1 IPs3

Countries

RO 1SG 1US 1ES 1

Ports targeted

Source IPCCNetworkEvents
66.154.119.224USAS7393 CYBERCON, INC.195
80.94.95.7ROAS204428 SS-Net144

About this fingerprint

JA4 is a fingerprint of the TLS Client Hello: the version, cipher suites, extensions and signature algorithms a client offers when it opens an HTTPS connection. Clients built on the same library and version produce the same JA4, which makes it a durable handle on the tool behind the traffic.