TCP SYN (p0f)

6:49+15:0:1300:65535,6:mss,nop,ws,nop,nop,ts,sok,eol+1:flow:0

first seen 2026-09-01 06:46 · last seen 2026-09-01 06:46 · JSON

Distinct clients per day (last 30 days, peak 1/day)

Distinct clients are counted by IP-hash per complete UTC day — unlike observation counts this is insensitive to one chatty client, but NAT merges clients and address rotation splits them.

Decomposed attributes

IP version6
Initial TTL49+15
Options length0
MSS1300
Window size65535
Window scale6
Options layoutmss,nop,ws,nop,nop,ts,sok,eol+1
Quirksflow
Payload class0

Co-observed signals

Signals from other families seen in the same observation. A fingerprint spread thinly across many lower-layer signatures is a classic inconsistency signal.

TLS ClientHello (JA4)

fingerprintco-occurrences
t13d2014h2_a09f3c656075_14788d8d241b1

HTTP request (JA4H)

fingerprintco-occurrences
ge20nn05zhcn_eff5d0107a3f_000000000000_0000000000001

HTTP/2 frames (Akamai)

fingerprintco-occurrences
4:2097152;3:100|10485760|0|m,s,p,a1

TCP SYN (JA4T)

fingerprintco-occurrences
65535_2-1-3-1-1-8-4-0-0_1300_61

User-Agent

fingerprintco-occurrences
Good1

Country

fingerprintco-occurrences
CN · China1

Network (ASN)

fingerprintco-occurrences
AS4812 · China Telecom (Group)1