HTTP/2 frames (Akamai)

4:2097152;3:100|10485760|0|m,s,p,a

first seen 2026-06-29 23:17 · last seen 2026-09-08 11:32 · JSON

Distinct clients per day (last 30 days, peak 3/day)

Distinct clients are counted by IP-hash per complete UTC day — unlike observation counts this is insensitive to one chatty client, but NAT merges clients and address rotation splits them.

Decomposed attributes

SETTINGS{"3": 100, "4": 2097152}
WINDOW_UPDATE10485760
PRIORITY frames0
Pseudo-header orderm,s,p,a

Co-observed signals

Signals from other families seen in the same observation. A fingerprint spread thinly across many lower-layer signatures is a classic inconsistency signal.

TLS ClientHello (JA4)

fingerprintco-occurrences
t13d2614h2_2802a3db6c62_a5b99884f7f522
t13d2014h2_a09f3c656075_14788d8d241b6
t13d2014h2_a09f3c656075_a5b99884f7f53
t13d2613h2_2802a3db6c62_845d286b0d672

HTTP request (JA4H)

fingerprintco-occurrences
ge20nr010000_c125d0397b60_000000000000_00000000000022
ge20nn05zhcn_eff5d0107a3f_000000000000_0000000000007
ge20nr05engb_f3a6f3dcb3d2_000000000000_0000000000002
ge20nn04enca_39a3ba4480e8_000000000000_0000000000002

TCP SYN (p0f)

fingerprintco-occurrences
4:112+16:0:1300:mss*44,9:mss,nop,nop,sok,nop,ws:df,id+:08
4:113+15:0:1300:mss*44,9:mss,nop,nop,sok,nop,ws:df,id+:08
6:50+14:0:1440:mss*30,11:mss,sok,ts,nop,ws:flow:06
4:48+16:0:1460:65535,6:mss,nop,ws,nop,nop,ts,sok,eol+1:id-:02
6:53+11:0:1440:65535,6:mss,nop,ws,nop,nop,ts,sok,eol+1:flow:02
4:241+14:0:1460:65535,0:mss:df,id+:02
4:47+17:0:1380:65535,6:mss,nop,ws,nop,nop,ts,sok,eol+1:df:02
4:48+16:0:1380:65535,6:mss,nop,ws,nop,nop,ts,sok,eol+1:df:01
4:49+15:0:1380:65535,6:mss,nop,ws,nop,nop,ts,sok,eol+1:df:01
6:49+15:0:1300:65535,6:mss,nop,ws,nop,nop,ts,sok,eol+1:flow:01

TCP SYN (JA4T)

fingerprintco-occurrences
64240_2-1-1-4-1-3_1300_916
43200_2-4-8-1-3_1440_116
65535_2-1-3-1-1-8-4-0-0_1380_64
65535_2-1-3-1-1-8-4-0-0_1460_62
65535_2-1-3-1-1-8-4-0-0_1440_62
65535_2_1460_002
65535_2-1-3-1-1-8-4-0-0_1300_61

User-Agent

fingerprintco-occurrences
Good6
Mozilla/5.0 (iPhone; CPU iPhone OS 15_6 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6 Mobile/15E148 Safari/604.12
HackerNews/1517 CFNetwork/1237 Darwin/20.4.02
BetaNewApp/0 CFNetwork/1390 Darwin/22.0.01

Country

fingerprintco-occurrences
HK · Hong Kong SAR China16
SG · Singapore8
CN · China5
AU · Australia2
CA · Canada2

Network (ASN)

fingerprintco-occurrences
AS39600 · BUNNY TECHNOLOGY LLC16
AS38136 · Akari Networks6
AS4812 · China Telecom (Group)5
AS852 · TELUS Communications Inc.2
AS15830 · Equinix (EMEA) Acquisition Enterprises B.V.2
AS141389 · GOIP Telecom (Asia Pacific) Pte. Ltd.2