HoneyLabs

JA4 TLS client fingerprint

t13i751000_479067518aa3_d41ae481755e

Seen 2026-02-19 to 2026-09-24 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS14061 sends an email when it next hits a sensor.

602

Source IPs

2

Networks

2

Countries

57

Ports hit

19.6K

Events

301

IPs / network

This fingerprint is concentrated: many addresses on very few networks, which is what a single coordinated operation tends to look like.

Top networks

Countries

US 324DE 278

Ports targeted

What it requests

GET/2.4K
POST/sdk27

User agents claimed

Mozilla/5.0 (compatible; Odin; https://docs.getodin.com/)27 IPs108
Source IPCCNetwork Last seenEvents
167.99.155.56AS0 DigitalOcean, LLC2026-09-19138
161.35.100.4AS0 DigitalOcean, LLC2026-09-15129
104.248.238.227AS0 DigitalOcean, LLC2026-09-15129
167.99.7.109AS0 DigitalOcean, LLC2026-09-10119
137.184.21.203AS0 DigitalOcean, LLC2026-09-02116
146.190.221.246AS0 DigitalOcean, LLC2026-09-07113
143.198.112.72AS0 DigitalOcean, LLC2026-09-02112
142.93.194.151AS0 DigitalOcean, LLC2026-09-09106
208.68.39.247AS0 DigitalOcean, LLC2026-09-02106
157.230.210.76AS0 DigitalOcean, LLC2026-09-13103
161.35.51.30AS0 DigitalOcean, LLC2026-08-27103
157.230.217.232AS0 DigitalOcean, LLC2026-09-02103
204.48.28.61AS0 DigitalOcean, LLC2026-09-0296
69.55.54.245AS0 DigitalOcean, LLC2026-09-1396
67.205.137.162AS0 DigitalOcean, LLC2026-09-1393
161.35.107.178AS0 DigitalOcean, LLC2026-09-1693
159.223.99.168AS0 DigitalOcean, LLC2026-08-3090
206.81.1.169AS0 DigitalOcean, LLC2026-09-0290
147.182.143.217AS0 DigitalOcean, LLC2026-09-0790
67.205.162.17AS0 DigitalOcean, LLC2026-09-0687

About this fingerprint

JA4 is a fingerprint of the TLS Client Hello: the version, cipher suites, extensions and signature algorithms a client offers when it opens an HTTPS connection. Clients built on the same library and version produce the same JA4, which makes it a durable handle on the tool behind the traffic.