Bingbot

The wire fingerprints traffic claiming to be this crawler presented, split by whether a channel the operator publishes for verification — its IP ranges or forward-confirmed reverse DNS — confirmed the claim.

Claims in window

Same adjudication as the stats page: a claim confirmed by either channel the operator publishes — its IP ranges or forward-confirmed reverse DNS — is legit; one confirmed by neither is spoofed. Operators differ in which channels they offer, and either alone fully identifies. Sources count distinct clients, not traffic. Fingerprint windows below are day-granular, like sources.

observationssourceslegitspoofedspoof rate
148323026.2%

Fingerprints presented by confirmed traffic

The highest-volume fingerprints the operator's own traffic runs, per signal — claims confirmed via operator-published channels. A Match pill marks an exact match against a controlled capture — an association with known stacks, not an identity verdict: unrelated clients built on the same stack can legitimately share a fingerprint.

TLS ClientHello (JA4)

fingerprintobservations
t13d2013h2_2b729b4bf6f3_e24568c0d440 115
t13d2212h2_231e334592e8_36bf25f296df 25

HTTP request (JA4H)

fingerprintobservations
ge20nn060000_0c07ec02b430_000000000000_000000000000 115
ge20nn040000_272467e735d1_000000000000_000000000000 5
ge20nn040000_b293ea6c67e2_000000000000_000000000000 3
ge20nn040000_14e57ecc58b7_000000000000_000000000000 2
ge20nn040000_200b94e8daef_000000000000_000000000000 2
ge20nn040000_31537f9be9e0_000000000000_000000000000 2
ge20nn040000_4fc62b8ba0b7_000000000000_000000000000 2
ge20nn040000_ac162d8a7b0c_000000000000_000000000000 2
ge20nn040000_50ac80afc84f_000000000000_000000000000 1
ge20nn040000_55a9dade9a93_000000000000_000000000000 1

HTTP/2 frames (Akamai)

fingerprintobservations
2:0;4:10485760|10420225|0|m,p,a,s 115
2:0;4:65535|67043329|0|m,s,a,p 25

TCP SYN (JA4T)

fingerprintobservations
64240_2-1-1-4_1440_00 115
64240_2-1-3-1-1-4_1440_8 25

TCP SYN (p0f)

fingerprintobservations
4:114+14:0:1440:mss*44,0:mss,nop,nop,sok:df,id+,ecn:0 54
4:113+15:0:1440:mss*44,0:mss,nop,nop,sok:df,id+,ecn:0 19
4:112+16:0:1440:mss*44,0:mss,nop,nop,sok:df,id+,ecn:0 14
4:114+14:0:1440:mss*44,8:mss,nop,ws,nop,nop,sok:df,id+,ecn:0 13
4:109+19:0:1440:mss*44,0:mss,nop,nop,sok:df,id+,ecn:0 9
4:110+18:0:1440:mss*44,0:mss,nop,nop,sok:df,id+,ecn:0 9
4:112+16:0:1440:mss*44,8:mss,nop,ws,nop,nop,sok:df,id+,ecn:0 7
4:108+20:0:1440:mss*44,0:mss,nop,nop,sok:df,id+,ecn:0 5
4:107+21:0:1440:mss*44,0:mss,nop,nop,sok:df,id+,ecn:0 2
4:111+17:0:1440:mss*44,0:mss,nop,nop,sok:df,id+,ecn:0 2

Fingerprints presented by unconfirmed claims

The impostor inventory: the highest-volume fingerprints wearing this operator's User-Agent that no operator-published channel confirms, per signal. A Match pill here shows known clients measured producing the same fingerprint an impostor presents.

TLS ClientHello (JA4)

fingerprintobservations
t13d1011h1_61a7ad8aa9b6_3a8073edd8ef 9

HTTP request (JA4H)

fingerprintobservations
ge11nn040000_8b1ed2202073_000000000000_000000000000 7
ge11nr040000_8b1ed2202073_000000000000_000000000000 2

TCP SYN (JA4T)

fingerprintobservations
64240_2-4-8-1-3_1460_7 9

TCP SYN (p0f)

fingerprintobservations
4:48+16:0:1460:mss*44,7:mss,sok,ts,nop,ws:df,id+:0 4
4:47+17:0:1460:mss*44,7:mss,sok,ts,nop,ws:df,id+:0 2
4:51+13:0:1460:mss*44,7:mss,sok,ts,nop,ws:df,id+:0 1
4:52+12:0:1460:mss*44,7:mss,sok,ts,nop,ws:df,id+:0 1
4:54+10:0:1460:mss*44,7:mss,sok,ts,nop,ws:df,id+:0 1