TCP SYN (JA4T)

59080_2-4-8-1-3_8440_7

first seen 2026-07-06 19:57 · last seen 2026-09-11 08:25 · JSON

Last 7 days (2 observations)

Distinct clients per day (last 30 days, peak 2/day)

Distinct clients are counted by IP-hash per complete UTC day — unlike observation counts this is insensitive to one chatty client, but NAT merges clients and address rotation splits them.

Decomposed attributes

TCP window59080
Option kinds2-4-8-1-3
MSS8440
Window scale7

Co-observed signals

Signals from other families seen in the same observation. A fingerprint spread thinly across many lower-layer signatures is a classic inconsistency signal.

TLS ClientHello (JA4)

fingerprintco-occurrences
t13d1516h2_8daaf6152771_806a8c22fdea Match?Exact match in Thumbprint's published controlled catalog captures: chrome 150.0.7871.187, chrome 151.0.7922.137, chromium 151.0.7922.34, +24 more.The fingerprint page shows the full measured match list. More on the catalog.5
t13d191000_9dc949149365_e7c2852226513
t13d131100_f57a46bbacb6_e5728521abd42
t12d1515h2_8daaf6152771_4d8a99c1bc012
t13d251100_b78ed14e2fd0_ab7e3b40a6771

HTTP request (JA4H)

fingerprintco-occurrences
ge20nr09enus_d05bf764aa1e_000000000000_0000000000004
he11nn020000_818f42cc3fd7_000000000000_0000000000002
ge11nr030000_cd680697de12_000000000000_0000000000002
ge20nn05enus_f649ff7cdbc1_000000000000_0000000000002
ge20nn10enus_f7ad313dcc59_000000000000_0000000000001
ge11nn05enus_f3bb7aa45ec4_000000000000_0000000000001
ge11nr070000_ae5913c5f5ca_000000000000_0000000000001

HTTP/2 frames (Akamai)

fingerprintco-occurrences
1:65536;2:0;4:6291456;6:262144|15663105|1:1:0:220|m,a,s,p Match?Exact match in Thumbprint's published controlled catalog captures: chrome 150.0.7871.187, chromium 149.0.7827.102, chrome 149.0.7827.102, +59 more.The fingerprint page shows the full measured match list. More on the catalog.4
1:65536;3:1000;4:6291456;5:16384;6:262144|15663105|0|m,a,s,p2
1:65536;2:0;4:6291456;6:262144|15663105|1:1:0:256|m,a,s,p Match?Exact match in Thumbprint's published controlled catalog captures: chromium 131.0.6778.33, chromium 151.0.7922.34, chrome 151.0.7922.137, +43 more.The fingerprint page shows the full measured match list. More on the catalog.1

TCP SYN (p0f)

fingerprintco-occurrences
6:48+16:0:8440:mss*7,7:mss,sok,ts,nop,ws:flow:07
6:52+12:0:8440:mss*7,7:mss,sok,ts,nop,ws:flow:02
6:54+10:0:8440:mss*7,7:mss,sok,ts,nop,ws:flow:02
6:53+11:0:8440:mss*7,7:mss,sok,ts,nop,ws:flow:01
6:51+13:0:8440:mss*7,7:mss,sok,ts,nop,ws:flow:01

User-Agent

fingerprintco-occurrences
RootEvidence/1.06
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/105.0.0.0 Safari/537.362
Mozilla/5.0 CMS-Detector/1.02
Adnet-Proxy-Verification/1.02
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.361

Country

fingerprintco-occurrences
US · United States12
BR · Brazil1

Network (ASN)

fingerprintco-occurrences
AS63949 · Akamai Connected Cloud11
AS45102 · Alibaba (US) Technology Co., Ltd.2

Cross-transport links

TLS ClientHello fingerprints observed from the same client via the beacon's correlation id on the other transport (e.g. this stack over TCP ↔ that stack over QUIC).

fingerprintlinked observations
q13d0311h3_55b375c5d22e_653d80c3fe9d4