HTTP/2 frames (Akamai)

1:139264;2:0;4:121760;5:16384|12517377|5:0:0:42|m,p,a,s

first seen 2026-08-20 23:27 · last seen 2026-08-20 23:39 · JSON

Distinct clients per day (last 30 days, peak 1/day)

Distinct clients are counted by IP-hash per complete UTC day — unlike observation counts this is insensitive to one chatty client, but NAT merges clients and address rotation splits them.

Decomposed attributes

SETTINGS{"1": 139264, "2": 0, "4": 121760, "5": 16384}
WINDOW_UPDATE12517377
PRIORITY frames5:0:0:42
Pseudo-header orderm,p,a,s

Co-observed signals

Signals from other families seen in the same observation. A fingerprint spread thinly across many lower-layer signatures is a classic inconsistency signal.

TLS ClientHello (JA4)

fingerprintco-occurrences
t13d1515h2_1f9c1ec88692_a54fffd0eb614

HTTP request (JA4H)

fingerprintco-occurrences
ge20nr13enus_016d87568c43_000000000000_0000000000004

TCP SYN (p0f)

fingerprintco-occurrences
4:52+12:0:1350:mss*48,10:mss,nop,nop,ts,nop,ws:df,id+:01
4:50+14:0:1430:mss*45,10:mss,sok,ts,nop,ws:df,id+:01
4:52+12:0:1400:mss*46,10:mss,sok,ts,nop,ws:df,id+:01
4:50+14:0:1430:mss*45,0:mss,nop,nop,sok:df,id+:01

TCP SYN (JA4T)

fingerprintco-occurrences
64800_2-1-1-8-1-3_1350_101
64350_2-4-8-1-3_1430_101
64400_2-4-8-1-3_1400_101
64350_2-1-1-4_1430_001

User-Agent

fingerprintco-occurrences
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.364

Country

fingerprintco-occurrences
CA · Canada4

Network (ASN)

fingerprintco-occurrences
AS5645 · TekSavvy Solutions, Inc.4