HTTP/2 frames (Akamai)

1:65536;3:1000;4:6291456|15663105|1:1:0:256|m,a,s,p

first seen 2026-06-11 21:04 · last seen 2026-08-29 19:44 · JSON

Distinct clients per day (last 30 days, peak 7/day)

Distinct clients are counted by IP-hash per complete UTC day — unlike observation counts this is insensitive to one chatty client, but NAT merges clients and address rotation splits them.

Decomposed attributes

SETTINGS{"1": 65536, "3": 1000, "4": 6291456}
WINDOW_UPDATE15663105
PRIORITY frames1:1:0:256
Pseudo-header orderm,a,s,p

Co-observed signals

Signals from other families seen in the same observation. A fingerprint spread thinly across many lower-layer signatures is a classic inconsistency signal.

TLS ClientHello (JA4)

fingerprintco-occurrences
t12d1310h2_8b80da21ef18_e69ac49eb88f12
t13d1615h2_46e7e9700bed_45f260be83e28
t12d1311h2_8b80da21ef18_eb7c9aabf8526
t12d1312h2_8b80da21ef18_b00751acaffa1
t13i1614h2_46e7e9700bed_45f260be83e21

HTTP request (JA4H)

fingerprintco-occurrences
ge20nn07zhcn_441d50c9939d_000000000000_00000000000012
ge20nn040000_60e0ac44f2fc_000000000000_0000000000007
ge20nn08enus_e556cc528a46_000000000000_0000000000005
ge20nn07enus_441d50c9939d_000000000000_0000000000001
ge20nn050000_c7428b30b61b_000000000000_0000000000001
ge20nn06enus_426aae43ac51_000000000000_0000000000001
ge20nn070000_f3b3a451f7a9_000000000000_0000000000001

TCP SYN (p0f)

fingerprintco-occurrences
4:42+22:0:1460:mss*44,7:mss,sok,ts,nop,ws:df,id+:012
4:43+21:0:1460:mss*44,7:mss,sok,ts,nop,ws:df,id+:06
4:45+19:0:1460:mss*44,7:mss,sok,ts,nop,ws:df,id+:02
4:246+9:0:1460:mss*20,7:mss,sok,ts,nop,ws:df,id+:02
4:240+15:0:1460:mss*20,7:mss,sok,ts,nop,ws:df,id+:01
4:110+18:0:1460:mss*44,8:mss,nop,ws,nop,nop,sok:df,id+,ecn:01
4:244+11:0:1460:mss*20,7:mss,sok,ts,nop,ws:df,id+:01
4:44+20:0:1460:mss*20,7:mss,sok,ts,nop,ws:df,id+:01
4:241+14:0:1460:mss*20,7:mss,sok,ts,nop,ws:df,id+:01
4:238+17:0:1460:mss*20,7:mss,sok,ts,nop,ws:df,id+:01

TCP SYN (JA4T)

fingerprintco-occurrences
64240_2-4-8-1-3_1460_719
29200_2-4-8-1-3_1460_71
64240_2-1-3-1-1-4_1460_81

User-Agent

fingerprintco-occurrences
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 Edg/122.0.0.08
Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Ubuntu Chromium/61.0.3163.100 Chrome/61.0.3163.100 Safari/537.36 PingdomPageSpeed/1.0 (pingbot/2.0; +http://www.pingdom.com/)6
Mozilla/5.0 (Linux; Android 11; V2055A) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Mobile Safari/537.365
Mozilla/5.0 (Linux; Android 10; HUAWEI P30 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.105 Mobile Safari/537.362
Mozilla/5.0 (Linux; U; Android 8.1.0; zh-cn; MI 8 Build/OPM1.171019.011) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/57.0.2987.108 Mobile Safari/537.362
Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.36 PTST/18.101
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.361
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/73.0.3683.75 Safari/537.361
Mozilla/5.0 (Linux; Android 11; CPH2185) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.101 Mobile Safari/537.361
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/114.0.0.0 Safari/537.36 Edg/114.0.1823.791

Country

fingerprintco-occurrences
CN · China12
DE · Germany7
US · United States3
CA · Canada2
GB · United Kingdom2
FR · France1
SK · Slovakia1

Network (ASN)

fingerprintco-occurrences
AS16276 · OVH SAS8
AS4837 · CHINA UNICOM China169 Backbone6
AS17621 · China Unicom Shanghai network6
AS16509 · Amazon.com, Inc.5
AS24940 · Hetzner Online GmbH1
AS14618 · Amazon.com, Inc.1
AS5578 · SWAN, a.s.1