TCP SYN (p0f)

4:52+12:0:1460:mss*44,1:mss,sok,ts,nop,ws:df,id+:0

first seen 2026-09-04 02:30 · last seen 2026-09-09 07:36 · JSON

Distinct clients per day (last 30 days, peak 2/day)

Distinct clients are counted by IP-hash per complete UTC day — unlike observation counts this is insensitive to one chatty client, but NAT merges clients and address rotation splits them.

Decomposed attributes

IP version4
Initial TTL52+12
Options length0
MSS1460
Window sizemss*44
Window scale1
Options layoutmss,sok,ts,nop,ws
Quirksdf,id+
Payload class0

Co-observed signals

Signals from other families seen in the same observation. A fingerprint spread thinly across many lower-layer signatures is a classic inconsistency signal.

TLS ClientHello (JA4)

fingerprintco-occurrences
t13d1515h1_8daaf6152771_de4a06bb82e32
t13d1515h1_8daaf6152771_0a20fe35d3a52

HTTP request (JA4H)

fingerprintco-occurrences
ge11nn13enus_9db22d02e17a_000000000000_0000000000002
ge11nn14enus_4a2973d235de_000000000000_0000000000002

TCP SYN (JA4T)

fingerprintco-occurrences
64240_2-4-8-1-3_1460_14

User-Agent

fingerprintco-occurrences
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.361
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.361
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.361
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.75 Safari/537.361

Country

fingerprintco-occurrences
US · United States2
PH · Philippines1
PE · Peru1

Network (ASN)

fingerprintco-occurrences
AS7018 · AT&T Enterprises, LLC1
AS9299 · Philippine Long Distance Telephone Company1
AS7922 · Comcast Cable Communications, LLC1
AS274275 · BEST SPEEDYN S.A.C.1