HoneyLabs

JA4 TLS client fingerprint

t13i430900_c7886603b240_5ac7197df9d2

Seen 2026-02-19 to 2026-09-28 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS10439 sends an email when it next hits a sensor.

21

Source IPs

5

Networks

4

Countries

56

Ports hit

521

Events

4

IPs / network

Top networks

Countries

US 11NL 5CA 5GB 4

Ports targeted

What it requests

POST/29
GET/crawl12

User agents claimed

Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/102.0.5005.63 Safari/537.3621 IPs480
python-requests/2.23.011 IPs41
Source IPCCNetwork Last seenEvents
93.174.95.106NLAS202425 IP Volume inc2026-09-2752
71.6.199.23USAS10439 CariNet, Inc.2026-09-2851
71.6.135.131USAS10439 CariNet, Inc.2026-09-2850
66.240.192.138USAS10439 CariNet, Inc.2026-09-2841
86.54.31.38CAAS12989 Black HOST Ltd2026-09-2840
86.54.31.34CAAS12989 Black HOST Ltd2026-09-2637
89.248.167.131NLAS202425 IP Volume inc2026-09-2835
80.82.77.139NLAS202425 IP Volume inc2026-09-2835
94.102.49.193NLAS202425 IP Volume inc2026-09-2831
86.54.31.32CAAS12989 Black HOST Ltd2026-09-2630
71.6.158.166USAS10439 CariNet, Inc.2026-09-2824
86.54.31.40CAAS12989 Black HOST Ltd2026-09-2522
80.82.77.33NLAS202425 IP Volume inc2026-09-2821
66.240.236.119USAS10439 CariNet, Inc.2026-09-2719
71.6.165.200USAS10439 CariNet, Inc.2026-09-2619
207.90.244.14USAS174 Cogent Communications, LLC2026-09-276
71.6.167.142USAS10439 CariNet, Inc.2026-09-284
86.54.31.46CAAS12989 Black HOST Ltd2026-09-241
66.240.219.146USAS10439 CariNet, Inc.2026-09-271
71.6.146.186USAS10439 CariNet, Inc.2026-09-281

About this fingerprint

JA4 is a fingerprint of the TLS Client Hello: the version, cipher suites, extensions and signature algorithms a client offers when it opens an HTTPS connection. Clients built on the same library and version produce the same JA4, which makes it a durable handle on the tool behind the traffic.