HTTP/2 frames (Akamai)

1:65536;4:131072;5:16384|12517377|3:0:0:201,5:0:0:101,7:0:0:1,9:0:7:1,11:0:3:1,13:0:0:241,15:0:13:42|m,p,a,s

first seen 2026-07-05 13:24 · last seen 2026-09-16 06:38 · JSON

Last 7 days (4 observations)

Distinct clients per day (last 30 days, peak 2/day)

Distinct clients are counted by IP-hash per complete UTC day — unlike observation counts this is insensitive to one chatty client, but NAT merges clients and address rotation splits them.

Decomposed attributes

SETTINGS{"1": 65536, "4": 131072, "5": 16384}
WINDOW_UPDATE12517377
PRIORITY frames3:0:0:201,5:0:0:101,7:0:0:1,9:0:7:1,11:0:3:1,13:0:0:241,15:0:13:42
Pseudo-header orderm,p,a,s

Co-observed signals

Signals from other families seen in the same observation. A fingerprint spread thinly across many lower-layer signatures is a classic inconsistency signal.

TLS ClientHello (JA4)

fingerprintco-occurrences
t13d1715h2_5b57614c22b0_3d5424432f576
t13d1713h2_5b57614c22b0_f81080dfc5573
t13d1717h2_5b57614c22b0_3cbfd9057e0d Match?Exact match in Thumbprint's published controlled catalog captures: firefox 148.0.2, firefox 144.0.2, firefox 142.0.1, +6 more.The fingerprint page shows the full measured match list. More on the catalog.2
t13d1712h2_6fb0c1f7f59f_b2c23852c9751
t13d1715h2_5b57614c22b0_5c2c66f702b0 Match?Exact match in Thumbprint's published controlled catalog captures: firefox 132.0.The fingerprint page shows the full measured match list. More on the catalog.1

HTTP request (JA4H)

fingerprintco-occurrences
ge20nn10ruru_d63c3be3d9d1_000000000000_0000000000002
ge20nn10enus_3d89cb764348_000000000000_0000000000002
ge20nn12enus_c05a64b9078b_000000000000_0000000000002
ge20nn11engb_3901d4197baf_000000000000_0000000000002
ge20nr11enus_bd1a02c579a6_000000000000_0000000000001
ge20nr10enus_d63c3be3d9d1_000000000000_0000000000001
ge20nn10enus_d63c3be3d9d1_000000000000_0000000000001
ge20nn11enus_bd1a02c579a6_000000000000_0000000000001
ge20nr10jajp_9fcbd3f1e2d6_000000000000_0000000000001

TCP SYN (p0f)

fingerprintco-occurrences
4:53+11:0:1460:mss*29,12:mss,sok,ts,nop,ws:df,id+:01
4:45+19:0:1460:mss*44,7:mss,sok,ts,nop,ws:df,id+:01
4:52+12:0:1460:mss*44,10:mss,sok,ts,nop,ws:df,id+:01
4:51+13:0:1460:mss*44,10:mss,sok,ts,nop,ws:df,id+:01
4:47+17:0:1460:65535,6:mss,nop,ws,nop,nop,ts,sok,eol+1:df,ecn:01
4:55+9:0:1460:mss*44,7:mss,sok,ts,nop,ws:df,id+:01
4:51+13:0:1436:mss*44,7:mss,sok,ts,nop,ws:df,id+:01
4:51+13:0:1380:mss*47,7:mss,sok,ts,nop,ws:df,id+:01
4:48+16:0:1460:65535,6:mss,nop,ws,nop,nop,ts,sok,eol+1:df,ecn:01
4:50+14:0:1460:65535,6:mss,nop,ws,nop,nop,ts,sok,eol+1:df:01

TCP SYN (JA4T)

fingerprintco-occurrences
65535_2-1-3-1-1-8-4-0-0_1460_63
64240_2-4-8-1-3_1460_72
64240_2-4-8-1-3_1460_102
64240_2-4-8-1-3_1436_71
65280_2-4-8-1-3_1360_71
64860_2-4-8-1-3_1380_71
42340_2-4-8-1-3_1460_121
8192_2-1-3-1-1-4_1460_81
65535_2-1-1-4_1460_001

User-Agent

fingerprintco-occurrences
Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:109.0) Gecko/20100101 Firefox/115.03
Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:140.0) Gecko/20100101 Firefox/140.02
Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:153.0) Gecko/20100101 Firefox/153.02
Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:155.0) Gecko/20100101 Firefox/155.02
Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:151.0) Gecko/20100101 Firefox/151.01
Mozilla/5.0 (Macintosh; Intel Mac OS X 10.14; rv:109.0) Gecko/20100101 Firefox/115.01
Mozilla/5.0 (Android 10; Mobile; rv:89.0) Gecko/89.0 Firefox/89.01
Mozilla/5.0 (Windows NT 100.0; rv:100.0) Gecko/20100101 Firefox/100.0 Mypal/74.1.11

Country

fingerprintco-occurrences
NL · Netherlands3
AU · Australia2
DE · Germany2
US · United States1
JP · Japan1
CH · Switzerland1
RU · Russia1
CN · China1
EE · Estonia1

Network (ASN)

fingerprintco-occurrences
AS1221 · Telstra Limited2
AS4134 · CHINANET BACKBONE1
AS396356 · Latitude.sh1
AS49981 · WorldStream B.V.1
AS6730 · Sunrise GmbH1
AS7018 · AT&T Enterprises, LLC1
AS40676 · Psychz Networks1
AS3249 · Telia Eesti AS1
AS8402 · PJSC "Vimpelcom"1
AS208988 · Buchholz Digital GmbH1