HTTP/2 frames (Akamai)

1:65536;4:131072;5:16384|12517377|3:0:0:201,5:0:0:101,7:0:0:1,9:0:7:1,11:0:3:1,13:0:0:241,15:0:13:22|m,p,a,s

first seen 2026-08-28 13:55 · last seen 2026-08-28 13:55 · JSON

Distinct clients per day (last 30 days, peak 1/day)

Distinct clients are counted by IP-hash per complete UTC day — unlike observation counts this is insensitive to one chatty client, but NAT merges clients and address rotation splits them.

Decomposed attributes

SETTINGS{"1": 65536, "4": 131072, "5": 16384}
WINDOW_UPDATE12517377
PRIORITY frames3:0:0:201,5:0:0:101,7:0:0:1,9:0:7:1,11:0:3:1,13:0:0:241,15:0:13:22
Pseudo-header orderm,p,a,s

Co-observed signals

Signals from other families seen in the same observation. A fingerprint spread thinly across many lower-layer signatures is a classic inconsistency signal.

TLS ClientHello (JA4)

fingerprintco-occurrences
t13d1715h2_5b57614c22b0_3d5424432f571

HTTP request (JA4H)

fingerprintco-occurrences
ge20nr08enus_ae4d442b3a50_000000000000_0000000000001

TCP SYN (p0f)

fingerprintco-occurrences
4:55+9:0:1460:mss*44,7:mss,sok,ts,nop,ws:df,id+:01

TCP SYN (JA4T)

fingerprintco-occurrences
64240_2-4-8-1-3_1460_71

User-Agent

fingerprintco-occurrences
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_17; rv:109.0) Gecko/20000101 Firefox/109.01

Country

fingerprintco-occurrences
US · United States1

Network (ASN)

fingerprintco-occurrences
AS14061 · DigitalOcean, LLC1