TCP SYN (p0f)

4:47+17:0:1380:65535,6:mss,nop,ws,nop,nop,ts,sok,eol+1:df:0

first seen 2026-09-01 06:47 · last seen 2026-09-01 07:14 · JSON

Distinct clients per day (last 30 days, peak 1/day)

Distinct clients are counted by IP-hash per complete UTC day — unlike observation counts this is insensitive to one chatty client, but NAT merges clients and address rotation splits them.

Decomposed attributes

IP version4
Initial TTL47+17
Options length0
MSS1380
Window size65535
Window scale6
Options layoutmss,nop,ws,nop,nop,ts,sok,eol+1
Quirksdf
Payload class0

Co-observed signals

Signals from other families seen in the same observation. A fingerprint spread thinly across many lower-layer signatures is a classic inconsistency signal.

TLS ClientHello (JA4)

fingerprintco-occurrences
t13d2014h2_a09f3c656075_14788d8d241b2

HTTP request (JA4H)

fingerprintco-occurrences
ge20nn05zhcn_eff5d0107a3f_000000000000_0000000000002

HTTP/2 frames (Akamai)

fingerprintco-occurrences
4:2097152;3:100|10485760|0|m,s,p,a2

TCP SYN (JA4T)

fingerprintco-occurrences
65535_2-1-3-1-1-8-4-0-0_1380_62

User-Agent

fingerprintco-occurrences
Good2

Country

fingerprintco-occurrences
CN · China2

Network (ASN)

fingerprintco-occurrences
AS4812 · China Telecom (Group)2