HoneyLabs

JA4H HTTP client fingerprint

po11nn0700_cfe31aff51dc

Seen 2026-07-16 to 2026-07-28 across the retained window.

13

Source IPs

9

Networks

8

Countries

2

Ports hit

95

Events

1

IPs / network

This fingerprint is spread thinly across many networks, which is the shape of a common, widely-used client.

Top networks

Countries

CN 3US 2JP 2FR 2ID 1CH 1SG 1RU 1

Ports targeted

Source IPCCNetworkEvents
103.96.147.148IDAS140456 PT Era Awan Digital24
185.227.134.15USAS141995 Contabo Asia Private Limited20
161.97.173.163FRAS51167 Contabo GmbH8
169.58.25.13FRAS51167 Contabo GmbH8
111.228.42.186CNAS141679 China Telecom Beijing Tianjin Hebei Big Data Industry Park Branch8
208.69.78.36CHAS63023 GTHost4
8.209.236.13JPAS45102 Alibaba (US) Technology Co., Ltd.4
8.209.254.243JPAS45102 Alibaba (US) Technology Co., Ltd.4
209.126.10.42USAS40021 Contabo Inc.4
195.161.62.64RUAS8342 JSC RTComm.RU4
47.82.153.124SGAS45102 Alibaba (US) Technology Co., Ltd.4
117.175.51.134CNAS9808 China Mobile Communications Group Co., Ltd.2
117.172.226.189CNAS9808 China Mobile Communications Group Co., Ltd.1

About this fingerprint

JA4H fingerprints the shape of an HTTP request: method, version, the ordered set of headers and the cookie and language handling. It identifies the HTTP client independently of the URL it asks for.