HoneyLabs

JA4H HTTP client fingerprint

po11nn0400_fdcc3615ee04

Seen 2026-06-20 to 2026-07-27 across the retained window.

15

Source IPs

9

Networks

7

Countries

24

Ports hit

1.5K

Events

2

IPs / network

This fingerprint is spread thinly across many networks, which is the shape of a common, widely-used client.

Top networks

Countries

NL 7US 3PA 1AU 1AE 1DE 1FI 1

Ports targeted

Source IPCCNetworkEvents
45.153.34.231NLAS197170 TechTies Inc.283
45.153.34.252NLAS197170 TechTies Inc.275
45.156.87.213NLAS197170 TechTies Inc.256
45.153.34.195NLAS197170 TechTies Inc.244
85.11.167.203NLAS197170 TechTies Inc.190
45.153.34.219NLAS197170 TechTies Inc.161
91.92.40.34NLAS197170 TechTies Inc.52
217.60.195.39AEAS209373 Swissnet LLC24
144.126.143.44USAS40021 Contabo Inc.16
23.111.155.222USAS29802 HIVELOCITY, Inc.11
170.64.177.57AUAS14061 DigitalOcean, LLC6
87.120.166.170DEAS215439 Play2go International Limited2
141.11.88.127USAS198364 Banatsync Srl1
5.252.153.10PAAS215826 Partner Hosting LTD1
89.169.98.0FIAS213291 Nebius B.V.1

About this fingerprint

JA4H fingerprints the shape of an HTTP request: method, version, the ordered set of headers and the cookie and language handling. It identifies the HTTP client independently of the URL it asks for.