TCP SYN (JA4T)
65535_2-4-8-1-3_1392_6
first seen 2026-07-24 20:45 · last seen 2026-09-08 12:07 · JSON
Distinct clients per day (last 30 days, peak 6/day)
Distinct clients are counted by IP-hash per complete UTC day — unlike observation counts this is insensitive to one chatty client, but NAT merges clients and address rotation splits them.
Decomposed attributes
| TCP window | 65535 |
|---|---|
| Option kinds | 2-4-8-1-3 |
| MSS | 1392 |
| Window scale | 6 |
Co-observed signals
Signals from other families seen in the same observation. A fingerprint spread thinly across many lower-layer signatures is a classic inconsistency signal.
TLS ClientHello (JA4)
| fingerprint | co-occurrences |
|---|---|
t13d1516h2_8daaf6152771_02713d6af862 Match?Exact match in Thumbprint's published controlled catalog captures: chromium 131.0.6778.33, chromium 134.0.6998.35, chromium 133.0.6943.16.The fingerprint page shows the full measured match list. More on the catalog. | 6 |
t13d4412h1_fd39b124ee10_58ed7828516f | 4 |
t13d1515h1_8daaf6152771_0a20fe35d3a5 | 2 |
t13d1515h1_8daaf6152771_de4a06bb82e3 | 1 |
t13d1516h2_8daaf6152771_d8a2da3f94cd Match?Exact match in Thumbprint's published controlled catalog captures: chromium 149.0.7827.102, chrome 149.0.7827.102, chrome 149.0.7827.156, +25 more.The fingerprint page shows the full measured match list. More on the catalog. | 1 |
t13d1516h1_8daaf6152771_1a63afa7c478 | 1 |
HTTP request (JA4H)
| fingerprint | co-occurrences |
|---|---|
ge20nr13zhcn_e2ac93ffb364_000000000000_000000000000 | 6 |
ge11nn050000_b223a0ebb0b5_000000000000_000000000000 Match?Exact match in Thumbprint's published controlled catalog captures: python-requests 2.34.2, python-requests 2.33.1, python-requests 2.32.3.The fingerprint page shows the full measured match list. More on the catalog. | 4 |
ge11nn13enus_9db22d02e17a_000000000000_000000000000 | 2 |
ge11nn14enus_4a2973d235de_000000000000_000000000000 | 2 |
ge20nn13enus_0c2c1d640f3e_000000000000_000000000000 Match?Exact match in Thumbprint's published controlled catalog captures: chrome 151.0.7922.137, chrome 151.0.7922.170, chrome 151.0.7922.108, +23 more.The fingerprint page shows the full measured match list. More on the catalog. | 1 |
HTTP/2 frames (Akamai)
| fingerprint | co-occurrences |
|---|---|
1:65536;2:0;4:6291456;6:262144|15663105|1:1:0:256|m,a,s,p Match?Exact match in Thumbprint's published controlled catalog captures: chromium 131.0.6778.33, chromium 151.0.7922.34, chrome 151.0.7922.137, +43 more.The fingerprint page shows the full measured match list. More on the catalog. | 7 |
TCP SYN (p0f)
User-Agent
Country
| fingerprint | co-occurrences |
|---|---|
BR · Brazil | 6 |
SA · Saudi Arabia | 2 |
IR · Iran | 1 |
ID · Indonesia | 1 |
PT · Portugal | 1 |
TT · Trinidad & Tobago | 1 |
BD · Bangladesh | 1 |
GY · Guyana | 1 |
MD · Moldova | 1 |
Network (ASN)
| fingerprint | co-occurrences |
|---|---|
AS27800 · Digicel Trinidad and Tobago Ltd. | 1 |
AS25019 · Saudi Telecom Company JSC | 1 |
AS35819 · Etihad Etisalat, a joint stock company | 1 |
AS8167 · V tal | 1 |
AS12353 · Vodafone Portugal | 1 |
AS58224 · Iran Telecommunication Company PJS | 1 |
AS262459 · Osirnet Info Telecom Ltda. | 1 |
AS45245 · Banglalink Digital Communications Ltd | 1 |
AS63859 · PT. Eka Mas Republik | 1 |
AS1547 · INTERDNESTRKOM, Sovmestnoe Zakrytoe Aktsionernoe Obshchestvo | 1 |