HTTP/2 frames (Akamai)

1:65536;2:0;3:1000;4:6291456;6:262144|15663105|1:1:0:220|m,a,s,p

first seen 2026-07-02 04:52 · last seen 2026-09-15 05:04 · JSON

Last 7 days (2 observations)

Distinct clients per day (last 30 days, peak 2/day)

Distinct clients are counted by IP-hash per complete UTC day — unlike observation counts this is insensitive to one chatty client, but NAT merges clients and address rotation splits them.

Decomposed attributes

SETTINGS{"1": 65536, "2": 0, "3": 1000, "4": 6291456, "6": 262144}
WINDOW_UPDATE15663105
PRIORITY frames1:1:0:220
Pseudo-header orderm,a,s,p

Co-observed signals

Signals from other families seen in the same observation. A fingerprint spread thinly across many lower-layer signatures is a classic inconsistency signal.

TLS ClientHello (JA4)

fingerprintco-occurrences
t13d1516h2_8daaf6152771_e5627efa2ab120

HTTP request (JA4H)

fingerprintco-occurrences
ge20nr100000_3a9ba06c504b_000000000000_00000000000016
ge20nr11enus_774bc4686a88_000000000000_0000000000004

TCP SYN (p0f)

fingerprintco-occurrences
4:46+18:0:1424:mss*29,9:mss,sok,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,ws:df,id+:03
4:43+21:0:1424:mss*29,7:mss,sok,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,ws:df,id+:03
6:53+11:0:1376:8192,2:mss,nop,ws,nop,nop,sok::02
4:46+18:0:1424:mss*29,7:mss,sok,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,ws:df,id+:02
4:109+19:0:1440:8192,2:mss,nop,ws,nop,nop,sok:df,id+:02
4:44+20:0:1424:mss*29,7:mss,sok,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,ws:df,id+:02
4:42+22:0:1424:mss*29,9:mss,sok,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,ws:df,id+:01
4:42+22:0:1424:mss*29,10:mss,sok,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,ws:df,id+:01
4:46+18:0:1424:mss*29,10:mss,sok,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,ws:df,id+:01
4:44+20:0:1424:mss*29,9:mss,sok,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,ws:df,id+:01

TCP SYN (JA4T)

fingerprintco-occurrences
42340_2-4-1-1-1-1-1-1-1-1-1-1-1-3_1424_78
42340_2-4-1-1-1-1-1-1-1-1-1-1-1-3_1424_96
8192_2-1-3-1-1-4_1376_22
8192_2-1-3-1-1-4_1440_22
42340_2-4-1-1-1-1-1-1-1-1-1-1-1-3_1424_102

User-Agent

fingerprintco-occurrences
Mozilla/5.0 (Linux; Android 11; Redmi Note 8 Pro Build/RP1A.200720.011; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/89.0.4389.72 MQQBrowser/6.2 TBS/045913 Mobile Safari/537.36 V1_AND_SQ_8.8.68_2538_YYB_D A_8086800 QQ/8.8.68.7265 NetType/WIFI WebP/0.3.0 Pixel/1080 StatusBarHeight/76 SimpleUISwitch/1 QQTheme/2971 InMagicWin/0 StudyMode/0 CurrentMode/1 CurrentFontScale/1.0 GlobalDensityScale/0.9818182 AppId/537112567 Edg/98.0.4758.10210
Mozilla/5.0 (Linux; Android 6.0; Nexus 5 Build/MRA58N) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4844.51 Mobile Safari/537.36 MicroMessenger/7.0.16
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.364

Country

fingerprintco-occurrences
CN · China16
US · United States2
VE · Venezuela2

Network (ASN)

fingerprintco-occurrences
AS134763 · CHINANET Guangdong province network6
AS45090 · Shenzhen Tencent Computer Systems Company Limited5
AS134543 · China Unicom Guangdong IP network3
AS21928 · T-Mobile USA, Inc.2
AS56040 · China Mobile communications corporation2
AS271939 · REDES ELIAS, C.A.2

Cross-transport links

TLS ClientHello fingerprints observed from the same client via the beacon's correlation id on the other transport (e.g. this stack over TCP ↔ that stack over QUIC).

fingerprintlinked observations
q13d0310h3_55b375c5d22e_cd85d2d889184