HTTP/2 frames (Akamai)

1:4096;2:0;4:32768;5:16384|12517377|9:0:0:42|m,p,a,s

first seen 2026-07-18 09:07 · last seen 2026-08-30 13:56 · JSON

Distinct clients per day (last 30 days, peak 2/day)

Distinct clients are counted by IP-hash per complete UTC day — unlike observation counts this is insensitive to one chatty client, but NAT merges clients and address rotation splits them.

Decomposed attributes

SETTINGS{"1": 4096, "2": 0, "4": 32768, "5": 16384}
WINDOW_UPDATE12517377
PRIORITY frames9:0:0:42
Pseudo-header orderm,p,a,s

Co-observed signals

Signals from other families seen in the same observation. A fingerprint spread thinly across many lower-layer signatures is a classic inconsistency signal.

TLS ClientHello (JA4)

fingerprintco-occurrences
t13d1615h2_86a278354501_5c2c66f702b01
t13d1516h2_8daaf6152771_eeeea65629601
t13d1515h2_8daaf6152771_5c2c66f702b01

HTTP request (JA4H)

fingerprintco-occurrences
ge20nr13enus_dee81a311bfc_000000000000_0000000000002
ge20nn10enus_d353d425b0bb_000000000000_000000000000 Match?Exact match in Thumbprint's published controlled catalog captures: firefox 152.0.1.The fingerprint page shows the full measured match list. More on the catalog.1

TCP SYN (p0f)

fingerprintco-occurrences
6:57+7:0:1440:mss*45,7:mss,sok,ts,nop,ws:flow:01
4:244+11:0:1400:mss*3,2:mss,nop,ws,sok,eol+1:df,id+:01
4:52+12:0:1460:mss*29,12:mss,nop,nop,sok,nop,ws:df,id+,ecn:01

TCP SYN (JA4T)

fingerprintco-occurrences
64800_2-4-8-1-3_1440_71
42340_2-1-1-4-1-3_1460_121
4200_2-1-3-4-0-0_1400_21

User-Agent

fingerprintco-occurrences
Mozilla/5.0 (Android 16; Mobile; rv:154.0) Gecko/154.0 Firefox/154.02
Mozilla/5.0 (Android 15; Mobile; rv:153.0) Gecko/153.0 Firefox/153.01

Country

fingerprintco-occurrences
NL · Netherlands1
ID · Indonesia1
FI · Finland1

Network (ASN)

fingerprintco-occurrences
AS23693 · PT. Telekomunikasi Selular1
AS50053 · VDSka hosting1
AS56971 · AS56971 Cloud1