HTTP/2 frames (Akamai)

1:65536;2:0;3:1000;4:6291456;6:262144|15663105|3:1:0:220|m,a,s,p

first seen 2026-07-02 04:52 · last seen 2026-08-22 07:16 · JSON

Distinct clients per day (last 30 days, peak 1/day)

Distinct clients are counted by IP-hash per complete UTC day — unlike observation counts this is insensitive to one chatty client, but NAT merges clients and address rotation splits them.

Decomposed attributes

SETTINGS{"1": 65536, "2": 0, "3": 1000, "4": 6291456, "6": 262144}
WINDOW_UPDATE15663105
PRIORITY frames3:1:0:220
Pseudo-header orderm,a,s,p

Co-observed signals

Signals from other families seen in the same observation. A fingerprint spread thinly across many lower-layer signatures is a classic inconsistency signal.

TLS ClientHello (JA4)

fingerprintco-occurrences
t13d1516h2_8daaf6152771_e5627efa2ab19

HTTP request (JA4H)

fingerprintco-occurrences
ge20nr100000_3a9ba06c504b_000000000000_0000000000007
ge20nr11enus_774bc4686a88_000000000000_0000000000002

TCP SYN (p0f)

fingerprintco-occurrences
6:53+11:0:1376:8192,2:mss,nop,ws,nop,nop,sok::01
4:46+18:0:1424:mss*29,7:mss,sok,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,ws:df,id+:01
4:109+19:0:1440:8192,2:mss,nop,ws,nop,nop,sok:df,id+:01
4:46+18:0:1424:mss*29,9:mss,sok,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,ws:df,id+:01
4:42+22:0:1424:mss*29,9:mss,sok,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,ws:df,id+:01
4:42+22:0:1424:mss*29,10:mss,sok,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,ws:df,id+:01
4:44+20:0:1424:mss*29,7:mss,sok,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,ws:df,id+:01
4:43+21:0:1424:mss*29,7:mss,sok,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,ws:df,id+:01
4:43+21:0:1424:mss*29,9:mss,sok,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,ws:df,id+:01

TCP SYN (JA4T)

fingerprintco-occurrences
42340_2-4-1-1-1-1-1-1-1-1-1-1-1-3_1424_73
42340_2-4-1-1-1-1-1-1-1-1-1-1-1-3_1424_93
8192_2-1-3-1-1-4_1376_21
8192_2-1-3-1-1-4_1440_21
42340_2-4-1-1-1-1-1-1-1-1-1-1-1-3_1424_101

User-Agent

fingerprintco-occurrences
Mozilla/5.0 (Linux; Android 11; Redmi Note 8 Pro Build/RP1A.200720.011; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/89.0.4389.72 MQQBrowser/6.2 TBS/045913 Mobile Safari/537.36 V1_AND_SQ_8.8.68_2538_YYB_D A_8086800 QQ/8.8.68.7265 NetType/WIFI WebP/0.3.0 Pixel/1080 StatusBarHeight/76 SimpleUISwitch/1 QQTheme/2971 InMagicWin/0 StudyMode/0 CurrentMode/1 CurrentFontScale/1.0 GlobalDensityScale/0.9818182 AppId/537112567 Edg/98.0.4758.1024
Mozilla/5.0 (Linux; Android 6.0; Nexus 5 Build/MRA58N) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4844.51 Mobile Safari/537.36 MicroMessenger/7.0.13
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.362

Country

fingerprintco-occurrences
CN · China7
US · United States1
VE · Venezuela1

Network (ASN)

fingerprintco-occurrences
AS45090 · Shenzhen Tencent Computer Systems Company Limited3
AS134543 · China Unicom Guangdong IP network2
AS21928 · T-Mobile USA, Inc.1
AS56040 · China Mobile communications corporation1
AS271939 · REDES ELIAS, C.A.1
AS134763 · CHINANET Guangdong province network1

Cross-transport links

TLS ClientHello fingerprints observed from the same client via the beacon's correlation id on the other transport (e.g. this stack over TCP ↔ that stack over QUIC).

fingerprintlinked observations
q13d0310h3_55b375c5d22e_cd85d2d889182