HoneyLabs

JA4H HTTP client fingerprint

ge11nn06en_c79eadf4d2aa

Seen 2026-06-05 to 2026-09-17 across the retained window.

3

Source IPs

2

Networks

3

Countries

4

Ports hit

69.9K

Events

2

IPs / network

This fingerprint is spread thinly across many networks, which is the shape of a common, widely-used client.

Top networks

AS204428 SS-Net1 IPs40.0K

Countries

TW 2DE 2RO 1

Ports targeted

What it requests

GET/.env428
GET/api/.env428
GET/427
GET/app/.env421

User agents claimed

Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US; rv:1.9.2.2) Gecko/20100316 AskTbSPC2/3.9.1.14019 Firefox/3.6.21 IPs379
Mozilla/5.0 (iPhone; CPU iPhone OS 9_2 like Mac OS X) AppleWebKit/601.1.46 (KHTML, like Gecko) FxiOS/1.2 Mobile/13C75 Safari/601.1.461 IPs332
Opera/9.80 (Macintosh; Intel Mac OS X 10.6.8; U; en) Presto/2.10.289 Version/12.001 IPs332
Mozilla/5.0 (X11; U; Linux i686; fr; rv:1.8.0.1) Gecko/20060124 Firefox/1.5.0.11 IPs329
Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; MathPlayer 2.20; chromeframe/28.0.1500.95; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET4.0C; .NET4.0E; InfoPath.3; IPH 1.1.21.4019)1 IPs329
Source IPCCNetwork Last seenEvents
80.94.95.211ROAS204428 SS-Net2026-09-1740.0K
213.209.159.175DEAS208137 Feo Prest SRL2026-09-1722.6K
213.209.159.154DEAS208137 Feo Prest SRL2026-09-167.4K

About this fingerprint

JA4H fingerprints the shape of an HTTP request: method, version, the ordered set of headers and the cookie and language handling. It identifies the HTTP client independently of the URL it asks for.