JA4 is now in VirusTotal!
All the malware using wininet: virustotal.com/gui/search/t12…
Executables using winhttp:
virustotal.com/gui/search/t12…
Remember, it is the combination of JA4+ fingerprints that build high fidelity detection. Rarely is JA4 a silver bullet on its own. For example, if you wanted to find Cobalt Strike, you would look for:
JA4 = t12d190800_d83cc789557e_16bbda4055b2 (wininet)
AND
JA4S = t120300_c030_52d195ce1d92 (Cobalt Strike C2 Response to wininet)
This combination search vastly increases detection fidelity.
Other examples:
HTTP IcedID dropper with JA4H = ge11cn060000_4e59edc1297a_4da5efaf0cb
Pikabot C2 X509 certs with JA4X =
1a59268f55e5_1a59268f55e5_795797892f9c
Right now VirusTotal only supports JA4, if you'd like to see the rest of JA4+ in there so you can have these higher fidelity matches, make sure you let your VirusTotal sales rep know!
If you're ever sad, just remember the world is 4.543 billion years old and you somehow managed to exist at the same time as Texas A&M losing to Appalachian State at home after signing the best recruiting class of all-time. We are truly blessed 🙏🏽
#AggieFactThursday
Announcing the JA4+ Database!
ja4db.com
Under *very* active development but ready for use. Expect orders of magnitude more data and JA4+ combinations over the next few months. I recommend downloading the DB and loading up in your data explorer of choice for now.
Everyone has a different use-case for JA4+ so we're trying to make it easy to find what you're looking for. Below are some examples you can do in a data explorer like Elastic.
JA4 to JA4H
JA4 to User-Agent String
JA4 to Application
JA4 to Library
JA4T to Device
JA4X to Device
JA4X to Application
JA4X to Issuers
JA4X to JA4T
etc. etc. etc.
There are so many combinations and use cases for each.
Please send me any feedback, improvement suggestions.
Sunday: Excessive Heat Warning in effect … HOWEVER! … there are rain chances today in the forecast. 🙂 Mostly sunny AM, partly cloudy PM with a chance of showers and thunderstorms. High 107°. Good luck to all in the rain derby!
Per a letter he posted on Truth Social, Trump's attorneys John Rowley & James Trusty have written to Attorney General Garland requesting a meeting “at your earliest convenience to discuss the ongoing injustice that is being perpetrated by your Special Counsel and his prosecutors."
2/2: The forecast calls for the potential for 3-6" of rain in many areas along and west of I-35, however locally heavier totals up to 10" are possible. It is impossible to pinpoint where this may occur. Please do not ask "what about my location?".