HTTP/2 frames (Akamai)

1:65536;4:131072;5:16384|12517377|3:0:0:201,5:0:0:101,7:0:0:1,9:0:7:1,11:0:3:1,13:0:0:241,21:0:11:22|m,p,a,s

first seen 2026-07-05 17:00 · last seen 2026-07-05 17:00 · JSON

Decomposed attributes

SETTINGS{"1": 65536, "4": 131072, "5": 16384}
WINDOW_UPDATE12517377
PRIORITY frames3:0:0:201,5:0:0:101,7:0:0:1,9:0:7:1,11:0:3:1,13:0:0:241,21:0:11:22
Pseudo-header orderm,p,a,s

Co-observed signals

Signals from other families seen in the same observation. A fingerprint spread thinly across many lower-layer signatures is a classic inconsistency signal.

TLS ClientHello (JA4)

fingerprintco-occurrences
t13d1715h2_5b57614c22b0_3d5424432f571

HTTP request (JA4H)

fingerprintco-occurrences
ge20nr08enus_ef40ae3d3783_000000000000_0000000000001

TCP SYN (p0f)

fingerprintco-occurrences
4:45+19:0:1460:mss*44,7:mss,sok,ts,nop,ws:df,id+:01

TCP SYN (JA4T)

fingerprintco-occurrences
64240_2-4-8-1-3_1460_71

User-Agent

fingerprintco-occurrences
Mozilla/5.0 (Android 10; Mobile; rv:89.0) Gecko/89.0 Firefox/89.01

Country

fingerprintco-occurrences
CN · China1

Network (ASN)

fingerprintco-occurrences
AS4134 · CHINANET BACKBONE1