HTTP/2 frames (Akamai)

1:65536;2:0;4:6291456;6:262144|15663105|9:1:0:220|m,a,s,p

first seen 2026-06-29 23:13 · last seen 2026-09-09 00:13 · JSON

Distinct clients per day (last 30 days, peak 1/day)

Distinct clients are counted by IP-hash per complete UTC day — unlike observation counts this is insensitive to one chatty client, but NAT merges clients and address rotation splits them.

Decomposed attributes

SETTINGS{"1": 65536, "2": 0, "4": 6291456, "6": 262144}
WINDOW_UPDATE15663105
PRIORITY frames9:1:0:220
Pseudo-header orderm,a,s,p

Co-observed signals

Signals from other families seen in the same observation. A fingerprint spread thinly across many lower-layer signatures is a classic inconsistency signal.

TLS ClientHello (JA4)

fingerprintco-occurrences
t13d1516h2_8daaf6152771_806a8c22fdea Match?Exact match in Thumbprint's published controlled catalog captures: chrome 150.0.7871.187, chrome 151.0.7922.137, chromium 151.0.7922.34, +24 more.The fingerprint page shows the full measured match list. More on the catalog.12
t13d1516h2_8daaf6152771_d8a2da3f94cd Match?Exact match in Thumbprint's published controlled catalog captures: chromium 149.0.7827.102, chrome 149.0.7827.102, chrome 149.0.7827.156, +25 more.The fingerprint page shows the full measured match list. More on the catalog.9
t13d1516h2_8daaf6152771_02713d6af862 Match?Exact match in Thumbprint's published controlled catalog captures: chromium 131.0.6778.33, chromium 134.0.6998.35, chromium 133.0.6943.16.The fingerprint page shows the full measured match list. More on the catalog.3
t13d1517h2_8daaf6152771_cb7bf5808d99 Match?Exact match in Thumbprint's published controlled catalog captures: chrome 152.0.7977.83, chrome 152.0.7977.64, chrome 152.0.7977.65, +5 more.The fingerprint page shows the full measured match list. More on the catalog.1

HTTP request (JA4H)

fingerprintco-occurrences
ge20nr10enus_00ecf112ab34_000000000000_0000000000006
ge20nr12enus_54b4638ab28b_000000000000_000000000000 Match?Exact match in Thumbprint's published controlled catalog captures: chrome 150.0.7871.187, chrome 151.0.7922.137, edge 151.0.4129.93, +36 more.The fingerprint page shows the full measured match list. More on the catalog.5
ge20nr100000_3a59a3b24d6e_000000000000_0000000000003
ge20nr100000_65cf54e683ea_000000000000_0000000000003
ge20nn13enus_0c2c1d640f3e_000000000000_000000000000 Match?Exact match in Thumbprint's published controlled catalog captures: chrome 151.0.7922.137, chrome 151.0.7922.170, chrome 151.0.7922.108, +23 more.The fingerprint page shows the full measured match list. More on the catalog.2
ge20nr11enus_30a8a9dcaa5a_000000000000_0000000000001
ge20nr12zhcn_54b4638ab28b_000000000000_0000000000001
ge20nr13ruru_5907f7c6644a_000000000000_0000000000001
ge20nr12ruru_54b4638ab28b_000000000000_0000000000001
ge20nr12eses_f632767e7b7a_000000000000_0000000000001

TCP SYN (p0f)

fingerprintco-occurrences
4:51+13:0:1410:mss*46,7:mss,sok,ts,nop,ws:df,id+:04
6:44+20:0:1220:mtu*19,7:mss,sok,ts,nop,ws::02
4:115+13:0:1460:mss*44,9:mss,nop,nop,sok,nop,ws:df,id+:02
4:46+18:0:1380:mss*47,9:mss,sok,ts,nop,ws:df,id+:02
4:117+11:0:1412:65535,8:mss,nop,ws,nop,nop,sok:df,id+:02
6:48+16:0:1420:mss*45,8:mss,nop,ws,nop,nop,sok:flow:02
4:47+17:0:1460:mss*44,7:mss,sok,ts,nop,ws:df,id+:01
4:46+18:0:1460:mss*44,7:mss,sok,ts,nop,ws:df,id+:01
4:54+10:0:1460:mss*44,7:mss,sok,ts,nop,ws:df,id+:01
4:43+21:0:1460:mss*44,7:mss,sok,ts,nop,ws:df,id+:01

TCP SYN (JA4T)

fingerprintco-occurrences
64860_2-4-8-1-3_1410_76
64240_2-4-8-1-3_1460_74
24320_2-4-8-1-3_1220_73
64240_2-1-1-4-1-3_1460_93
64860_2-4-8-1-3_1380_92
65535_2-1-3-1-1-4_1412_82
64800_2-1-3-1-1-4_1420_82
42600_2-4-8-1-3_1420_71
65535_2-1-3-1-1-4_1386_81
64800_2-4-8-1-3_1440_61

User-Agent

fingerprintco-occurrences
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.5938.132 Safari/537.366
Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/127.0.6533.0 Safari/537.363
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.363
Mozilla/5.0 (iPhone; CPU iPhone OS 17_5 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/26.0 Mobile/15E148 Safari/604.13
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.363
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.362
Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.361
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36 Edg/150.0.0.01
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.361
Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Mobile Safari/537.361

Country

fingerprintco-occurrences
US · United States10
SG · Singapore3
CN · China3
BR · Brazil2
MD · Moldova2
NL · Netherlands1
FR · France1
EE · Estonia1
MY · Malaysia1
TR · Turkey1

Network (ASN)

fingerprintco-occurrences
AS3356 · Level 3 Parent, LLC6
AS396982 · Google LLC4
AS213476 · Litlink UAB3
AS4134 · CHINANET BACKBONE2
AS7738 · V tal2
AS31252 · StarNet Solutii SRL2
AS16276 · OVH SAS1
AS137266 · CHINATELECOM Hubei province Wuhan 5G network1
AS44620 · Netlen Internet Hizmetleri Ltd. Sti.1
AS50673 · Serverius1

Cross-transport links

TLS ClientHello fingerprints observed from the same client via the beacon's correlation id on the other transport (e.g. this stack over TCP ↔ that stack over QUIC).

fingerprintlinked observations
q13d0311h3_55b375c5d22e_653d80c3fe9d1