HoneyLabs

JA4H HTTP client fingerprint

po11nn0700_5a5182d16ecb

Seen 2026-03-07 to 2026-07-25 across the retained window.

25

Source IPs

19

Networks

13

Countries

2

Ports hit

169

Events

1

IPs / network

This fingerprint is spread thinly across many networks, which is the shape of a common, widely-used client.

Top networks

Countries

CN 6US 4SE 3KR 2RU 2IR 1GB 1BR 1AE 1GR 1

Ports targeted

Source IPCCNetworkEvents
81.226.129.67SEAS3301 Telia Company AB44
24.84.30.89CAAS6327 Shaw Communications12
162.198.46.77USAS7018 AT&T Enterprises, LLC12
111.20.172.234CNAS9808 China Mobile Communications Group Co., Ltd.12
175.200.104.40KRAS4766 Korea Telecom12
27.153.157.138CNAS4134 Chinanet8
200.255.205.162BRAS4230 CLARO S.A.8
94.35.140.5ITAS8612 Tiscali SpA4
117.60.24.97CNAS4134 Chinanet4
113.101.246.10CNAS4134 Chinanet4
59.24.34.224KRAS4766 Korea Telecom4
24.185.219.32USAS6128 Cablevision Systems Corp.4
98.172.97.239USAS22773 Cox Communications Inc.4
82.28.80.167GBAS5089 Virgin Media4
120.1.237.12CNAS4837 CHINA UNICOM China169 Backbone4
90.226.146.31SEAS3301 Telia Company AB4
85.133.133.99IRAS39074 Sepanta Communication Development Co. Ltd4
113.101.246.167CNAS4134 Chinanet4
79.129.165.192GRAS6799 OTEnet S.A.4
78.68.234.165SEAS3301 Telia Company AB4

About this fingerprint

JA4H fingerprints the shape of an HTTP request: method, version, the ordered set of headers and the cookie and language handling. It identifies the HTTP client independently of the URL it asks for.