HoneyLabs

JA4H HTTP client fingerprint

ge11nn0500_e6b1eaaea03a

Seen 2026-06-20 to 2026-09-18 across the retained window.

3

Source IPs

2

Networks

2

Countries

11

Ports hit

47.8K

Events

2

IPs / network

This fingerprint is spread thinly across many networks, which is the shape of a common, widely-used client.

Top networks

Countries

NL 2DE 1

Ports targeted

What it requests

GET/$%7B%28121
GET/.env100

User agents claimed

Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.363 IPs6.2K
Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:125.0) Gecko/20100101 Firefox/125.03 IPs6.1K
Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.5 Safari/605.1.153 IPs6.0K
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36 Edg/124.0.0.03 IPs5.9K
Mozilla/5.0 (X11; Linux x86_64; rv:126.0) Gecko/20100101 Firefox/126.03 IPs5.9K
Source IPCCNetwork Last seenEvents
192.253.248.173NLAS213790 Limited Network LTD2026-09-1837.1K
213.209.159.148DEAS208137 Feo Prest SRL2026-09-098.8K
192.253.248.163NLAS213790 Limited Network LTD2026-09-121.9K

About this fingerprint

JA4H fingerprints the shape of an HTTP request: method, version, the ordered set of headers and the cookie and language handling. It identifies the HTTP client independently of the URL it asks for.