HTTP request (JA4H)

ge20nr100000_3a9ba06c504b_000000000000_000000000000

first seen 2026-07-19 14:08 · last seen 2026-09-15 05:04 · JSON

Last 7 days (2 observations)

Distinct clients per day (last 30 days, peak 2/day)

Distinct clients are counted by IP-hash per complete UTC day — unlike observation counts this is insensitive to one chatty client, but NAT merges clients and address rotation splits them.

Decomposed attributes

Methodge
HTTP version20
Cookieno
Refereryes
Header count10
Accept-Language0000
Header ordersec-ch-ua, sec-ch-ua-mobile, user-agent, sec-ch-ua-platform, accept, origin, sec-fetch-site, sec-fetch-mode, sec-fetch-dest, accept-encoding
Header-order hash3a9ba06c504b
Cookie-name hash000000000000
Cookie-value hash000000000000
JA4H_rge20nr100000_sec-ch-ua,sec-ch-ua-mobile,user-agent,sec-ch-ua-platform,accept,origin,sec-fetch-site,sec-fetch-mode,sec-fetch-dest,accept-encoding__

Co-observed signals

Signals from other families seen in the same observation. A fingerprint spread thinly across many lower-layer signatures is a classic inconsistency signal.

TLS ClientHello (JA4)

fingerprintco-occurrences
t13d1516h2_8daaf6152771_e5627efa2ab126

HTTP/2 frames (Akamai)

fingerprintco-occurrences
1:65536;2:0;3:1000;4:6291456;6:262144|15663105|1:1:0:220|m,a,s,p16
1:65536;2:0;3:1000;4:6291456;6:262144|15663105|3:1:0:220|m,a,s,p7
1:65536;2:0;3:1000;4:6291456;6:262144|15663105|5:1:0:220|m,a,s,p3

TCP SYN (p0f)

fingerprintco-occurrences
4:46+18:0:1424:mss*29,9:mss,sok,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,ws:df,id+:05
4:43+21:0:1424:mss*29,7:mss,sok,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,ws:df,id+:05
4:46+18:0:1424:mss*29,7:mss,sok,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,ws:df,id+:03
4:42+22:0:1424:mss*29,9:mss,sok,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,ws:df,id+:03
4:44+20:0:1424:mss*29,7:mss,sok,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,ws:df,id+:03
4:42+22:0:1424:mss*29,10:mss,sok,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,ws:df,id+:02
4:43+21:0:1424:mss*29,9:mss,sok,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,ws:df,id+:02
4:46+18:0:1424:mss*29,10:mss,sok,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,ws:df,id+:01
4:44+20:0:1424:mss*29,9:mss,sok,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,ws:df,id+:01
4:42+22:0:1424:mss*29,7:mss,sok,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,ws:df,id+:01

TCP SYN (JA4T)

fingerprintco-occurrences
42340_2-4-1-1-1-1-1-1-1-1-1-1-1-3_1424_712
42340_2-4-1-1-1-1-1-1-1-1-1-1-1-3_1424_911
42340_2-4-1-1-1-1-1-1-1-1-1-1-1-3_1424_103

User-Agent

fingerprintco-occurrences
Mozilla/5.0 (Linux; Android 11; Redmi Note 8 Pro Build/RP1A.200720.011; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/89.0.4389.72 MQQBrowser/6.2 TBS/045913 Mobile Safari/537.36 V1_AND_SQ_8.8.68_2538_YYB_D A_8086800 QQ/8.8.68.7265 NetType/WIFI WebP/0.3.0 Pixel/1080 StatusBarHeight/76 SimpleUISwitch/1 QQTheme/2971 InMagicWin/0 StudyMode/0 CurrentMode/1 CurrentFontScale/1.0 GlobalDensityScale/0.9818182 AppId/537112567 Edg/98.0.4758.10215
Mozilla/5.0 (Linux; Android 6.0; Nexus 5 Build/MRA58N) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4844.51 Mobile Safari/537.36 MicroMessenger/7.0.111

Country

fingerprintco-occurrences
CN · China26

Network (ASN)

fingerprintco-occurrences
AS45090 · Shenzhen Tencent Computer Systems Company Limited9
AS134763 · CHINANET Guangdong province network8
AS134543 · China Unicom Guangdong IP network6
AS56040 · China Mobile communications corporation3