JA4 TLS client fingerprint
t13i4311h1_c7886603b240_b26ce05bbdd6
Seen 2026-02-19 to 2026-09-24 across the retained window.
The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS400619 sends an email when it next hits a sensor.
21
Source IPs
10
Networks
11
Countries
4
Ports hit
614
Events
2
IPs / network
Top networks
Countries
HK 5CL 4SG 2US 2CN 2ID 1AU 1NL 1SC 1DE 1
Ports targeted
What it requests
User agents claimed
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.361 IPs559
Mozilla/5.011 IPs21
python-requests/2.25.14 IPs15
Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.363 IPs12
Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:52.0) Gecko/20100101 Firefox/52.02 IPs2
Source IPCCNetwork
Last seenEvents
About this fingerprint
JA4 is a fingerprint of the TLS Client Hello: the version, cipher suites, extensions and signature algorithms a client offers when it opens an HTTPS connection. Clients built on the same library and version produce the same JA4, which makes it a durable handle on the tool behind the traffic.