TCP SYN (p0f)

4:46+18:0:1412:65535,8:mss,sok,ts,nop,ws:df,id+:0

first seen 2026-07-06 07:18 · last seen 2026-09-15 02:03 · JSON

Last 7 days (3 observations)

Distinct clients per day (last 30 days, peak 6/day)

Distinct clients are counted by IP-hash per complete UTC day — unlike observation counts this is insensitive to one chatty client, but NAT merges clients and address rotation splits them.

Decomposed attributes

IP version4
Initial TTL46+18
Options length0
MSS1412
Window size65535
Window scale8
Options layoutmss,sok,ts,nop,ws
Quirksdf,id+
Payload class0

Co-observed signals

Signals from other families seen in the same observation. A fingerprint spread thinly across many lower-layer signatures is a classic inconsistency signal.

TLS ClientHello (JA4)

fingerprintco-occurrences
t13d4412h1_fd39b124ee10_58ed7828516f36
t13d1515h1_8daaf6152771_0a20fe35d3a518
t13d1515h1_8daaf6152771_de4a06bb82e310
t13d1516h1_8daaf6152771_1a63afa7c4783
t13d1613h2_86a278354501_748f4c70de1c1
t13d4312h1_c7886603b240_b26ce05bbdd61

HTTP request (JA4H)

fingerprintco-occurrences
ge11nn050000_b223a0ebb0b5_000000000000_000000000000 Match?Exact match in Thumbprint's published controlled catalog captures: python-requests 2.34.2, python-requests 2.33.1, python-requests 2.32.3.The fingerprint page shows the full measured match list. More on the catalog.37
ge11nn13enus_9db22d02e17a_000000000000_00000000000016
ge11nn14enus_4a2973d235de_000000000000_00000000000015
ge20nr11enit_187a9385d229_000000000000_0000000000001

HTTP/2 frames (Akamai)

fingerprintco-occurrences
1:4096;2:0;4:32768;5:16384|12517377|3:0:0:22|m,p,a,s1

TCP SYN (JA4T)

fingerprintco-occurrences
65535_2-4-8-1-3_1412_869

User-Agent

fingerprintco-occurrences
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.365
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.365
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.364
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.363
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/110.0.0.0 Safari/537.363
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4844.51 Safari/537.363
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.363
Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.93 Safari/537.363
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/101.0.4951.67 Safari/537.362
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.75 Safari/537.362

Country

fingerprintco-occurrences
BR · Brazil13
MX · Mexico7
ZA · South Africa7
EG · Egypt7
PE · Peru4
JO · Jordan4
JM · Jamaica4
VN · Vietnam3
BD · Bangladesh2
BN · Brunei2

Network (ASN)

fingerprintco-occurrences
AS8452 · TE-AS6
AS328961 · NET99 (PTY) LTD6
AS7738 · V tal6
AS48832 · Jordanian mobile phone services Ltd4
AS7552 · Viettel Group3
AS13999 · Mega Cable, S.A. de C.V.3
AS265691 · WI-NET TELECOM S.A.C.3
AS10094 · Unified National Networks2
AS33576 · Digicel Jamaica2
AS9198 · JSC Kazakhtelecom1

Cross-transport links

TLS ClientHello fingerprints observed from the same client via the beacon's correlation id on the other transport (e.g. this stack over TCP ↔ that stack over QUIC).

fingerprintlinked observations
q13d0315h3_55b375c5d22e_dc5437974b471