HoneyLabs
iAnonymous lookups: 10/min, 60/hr per source IP. Sign in (free) to lift the limit, run heavier queries, and get an API key for MCP / HTTP.

Filtered actors

query: ja4:t13i251000_b78ed14e2fd0_ab7e3b40a677

14 unique IPs · 37.5K events · 8 countries · 12 ASNs

Activity · last 7d

2026-06-14: 5 events2026-06-15: 13 events2026-06-16: 10 events2026-06-17: 2.6K events2026-06-18: 9.5K events2026-06-19: 2.5K events2026-06-20: 12.0K events2026-06-21: 10.8K events

peak 12.0K on 2026-06-20

Top source networks · click to refine

Refine
Turn this query into a daily email digest or an IOC feed URL.Save as feed

Sample payloads

top distinct probes matching this query
ProtocolPortProbe / payloadHitsExample
HTTP762GET /sslvpn_logon.shtml
UA: Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_0; en-US) AppleWebKit/532.0 (KHTML, like Gecko) Chrome/4.0.202.0 Safari/5…
5.4K · 5 IPs213.209.159.5 →
HTTP17961GET /auth.html
UA: Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_0; en-US) AppleWebKit/532.0 (KHTML, like Gecko) Chrome/4.0.202.0 Safari/5…
5.3K · 2 IPs213.209.159.5 →
HTTP15329GET /remote/login
UA: Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_0; en-US) AppleWebKit/532.0 (KHTML, like Gecko) Chrome/4.0.202.0 Safari/5…
5.3K · 2 IPs213.209.159.5 →
HTTP11634GET /+CSCOE+/logon.html
UA: Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_0; en-US) AppleWebKit/532.0 (KHTML, like Gecko) Chrome/4.0.202.0 Safari/5…
5.3K · 2 IPs213.209.159.5 →
HTTP2712GET /RDWeb/
UA: Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_0; en-US) AppleWebKit/532.0 (KHTML, like Gecko) Chrome/4.0.202.0 Safari/5…
5.3K · 2 IPs213.209.159.5 →
HTTP2712GET /global-protect/login.esp
UA: Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_0; en-US) AppleWebKit/532.0 (KHTML, like Gecko) Chrome/4.0.202.0 Safari/5…
5.2K · 2 IPs213.209.159.5 →
HTTP11634GET /sslmgr
UA: Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_0; en-US) AppleWebKit/532.0 (KHTML, like Gecko) Chrome/4.0.202.0 Safari/5…
5.2K · 2 IPs213.209.159.5 →
HTTP443/HTTPSGET /
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 11_7_0) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.1 Safari/605.1.15
283 · 9 IPs130.12.180.196 →
HTTP29443GET /login?redir=%2F
UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36
171 · 2 IPs45.74.59.4 →
HTTP443/HTTPSGET /api/auth/validate-sso53151.242.30.224 →
HTTP22/SSHGET /.env
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.1 Safari/605.1.15
1077.90.185.97 →
HTTP993/IMAPSGET /.env.local
UA: Mozilla/5.0 (CentOS; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36
777.90.185.97 →
IPCountryASNTop portsEvents
Showing top 50 by event count. Window is the last 7d. Add or remove filters by clicking any value on a per-IP report.