HTTP request (JA4H)

ge20nn10zh00_06e2da52e592_000000000000_000000000000

first seen 2026-07-23 19:57 · last seen 2026-08-27 06:49 · JSON

Distinct clients per day (last 30 days, peak 14/day)

Distinct clients are counted by IP-hash per complete UTC day — unlike observation counts this is insensitive to one chatty client, but NAT merges clients and address rotation splits them.

Decomposed attributes

Methodge
HTTP version20
Cookieno
Refererno
Header count10
Accept-Languagezh00
Header orderaccept, accept-language, upgrade-insecure-requests, user-agent, sec-fetch-site, sec-fetch-mode, sec-fetch-user, sec-fetch-dest, accept-encoding, priority
Header-order hash06e2da52e592
Cookie-name hash000000000000
Cookie-value hash000000000000
JA4H_rge20nn10zh00_accept,accept-language,upgrade-insecure-requests,user-agent,sec-fetch-site,sec-fetch-mode,sec-fetch-user,sec-fetch-dest,accept-encoding,priority__

Co-observed signals

Signals from other families seen in the same observation. A fingerprint spread thinly across many lower-layer signatures is a classic inconsistency signal.

TLS ClientHello (JA4)

fingerprintco-occurrences
t13d1516h2_8daaf6152771_d8a2da3f94cd Match?Exact match in Thumbprint's published controlled catalog captures: chromium 149.0.7827.102, chrome 149.0.7827.102, chrome 149.0.7827.156, +25 more.The fingerprint page shows the full measured match list. More on the catalog.30

HTTP/2 frames (Akamai)

fingerprintco-occurrences
1:65536;2:0;4:6291456;6:262144|15663105|1:1:0:256|m,a,s,p Match?Exact match in Thumbprint's published controlled catalog captures: chromium 131.0.6778.33, chromium 151.0.7922.34, chrome 151.0.7922.137, +43 more.The fingerprint page shows the full measured match list. More on the catalog.30

TCP SYN (p0f)

fingerprintco-occurrences
4:46+18:0:1460:mss*29,10:mss,sok,ts,nop,ws:df,id+:017
4:40+24:0:1460:mss*20,10:mss,sok,ts,nop,ws:df,id+:06
4:40+24:0:1460:26883,10:mss,sok,ts,nop,ws:df,id+:03
4:48+16:0:1460:mss*29,10:mss,sok,ts,nop,ws:df,id+:01
4:45+19:0:1460:mss*29,10:mss,sok,ts,nop,ws:df,id+:01
4:42+22:0:1460:26883,10:mss,sok,ts,nop,ws:df,id+:01
4:43+21:0:1460:mss*20,10:mss,sok,ts,nop,ws:df,id+:01

TCP SYN (JA4T)

fingerprintco-occurrences
42340_2-4-8-1-3_1460_1019
29200_2-4-8-1-3_1460_107
26883_2-4-8-1-3_1460_104

User-Agent

fingerprintco-occurrences
Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; https://zhanzhang.toutiao.com/)19
Mozilla/5.0 (Linux; Android 14; 23127PN0CC) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Mobile Safari/537.362
Mozilla/5.0 (Linux; Android 5.0; SM-G900P Build/LRX21T) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.8899.1875 Mobile Safari/537.361
Mozilla/5.0 (Linux; Android 5.0; SM-G900P Build/LRX21T) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.4677.1262 Mobile Safari/537.361
Mozilla/5.0 (Linux; Android 8.0; Pixel 2 Build/OPD3.170816.012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/40.0.2142.1309 Mobile Safari/537.361
Mozilla/5.0 (iPhone; CPU iPhone OS 11_0 like Mac OS X) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/46.0.4570.1217 Mobile Safari/537.361
Mozilla/5.0 (Linux; Android 8.0; Pixel 2 Build/OPD3.170816.012) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/53.0.2052.1520 Mobile Safari/537.361
Mozilla/5.0 (Linux; Android 6.0; Nexus 5 Build/MRA58N) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.2300.1520 Mobile Safari/537.361
Mozilla/5.0 (Linux; Android 14; Pixel 8 Pro) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Mobile Safari/537.361
Mozilla/5.0 (Linux; Android 15; Pixel 9) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Mobile Safari/537.361

Country

fingerprintco-occurrences
CN · China30

Network (ASN)

fingerprintco-occurrences
AS4837 · CHINA UNICOM China169 Backbone13
AS55960 · Beijing Guanghuan Xinwang Digital11
AS4134 · CHINANET BACKBONE6