HoneyLabs

JA4H HTTP client fingerprint

po11nn0700_a1f20e5bfd9b

Seen 2026-02-19 to 2026-07-27 across the retained window.

54

Source IPs

32

Networks

19

Countries

2

Ports hit

418

Events

2

IPs / network

This fingerprint is spread thinly across many networks, which is the shape of a common, widely-used client.

Top networks

Countries

CN 18US 8RU 5KR 4BR 2DE 2SG 2SE 2HU 1TR 1

Ports targeted

Source IPCCNetworkEvents
46.191.157.159RUAS60095 JSC Ufanet45
79.76.58.113SEAS31898 Oracle Corporation44
120.236.49.131CNAS9808 China Mobile Communications Group Co., Ltd.36
222.89.169.98CNAS4134 Chinanet32
170.9.16.186USAS31898 Oracle Corporation20
134.65.30.157BRAS31898 Oracle Corporation12
36.132.36.134CNAS56044 China Mobile communications corporation12
168.110.107.79KRAS31898 Oracle Corporation12
138.2.102.66SGAS31898 Oracle Corporation8
138.2.0.137JPAS31898 Oracle Corporation8
119.8.163.124SGAS136907 HUAWEI CLOUDS8
222.187.115.202CNAS4134 Chinanet8
165.1.78.209USAS31898 Oracle Corporation8
185.238.202.151RUAS29076 Citytelecom LLC7
5.20.23.118LTAS21412 UAB Cgates6
101.99.81.76MYAS45839 Shinjiru Technology Sdn Bhd4
221.2.109.198CNAS4837 CHINA UNICOM China169 Backbone4
1.94.17.74CNAS55990 Huawei Cloud Service data center4
36.105.194.19CNAS4134 Chinanet4
89.217.231.108CHAS6730 Sunrise GmbH4

About this fingerprint

JA4H fingerprints the shape of an HTTP request: method, version, the ordered set of headers and the cookie and language handling. It identifies the HTTP client independently of the URL it asks for.