TCP SYN (p0f)

4:116+12:0:1412:65535,8:mss,sok,ts,nop,ws::0

first seen 2026-06-11 07:17 · last seen 2026-06-23 03:32 · JSON

Decomposed attributes

IP version4
Initial TTL116+12
Options length0
MSS1412
Window size65535
Window scale8
Options layoutmss,sok,ts,nop,ws
Payload class0

Co-observed signals

Signals from other families seen in the same observation. A fingerprint spread thinly across many lower-layer signatures is a classic inconsistency signal.

TLS ClientHello (JA4)

fingerprintco-occurrences
t13d181300_e8a523a41297_43ade6aba3df293
t13d1712h2_5b57614c22b0_ef7df7f74e4812
t13d1516h2_8daaf6152771_d8a2da3f94cd Match?Exact match in Thumbprint's published controlled catalog captures: chromium 149.0.7827.102, chrome 149.0.7827.102, chrome 149.0.7827.156, +25 more.The fingerprint page shows the full measured match list. More on the catalog.6
t13d1516h2_8daaf6152771_02713d6af862 Match?Exact match in Thumbprint's published controlled catalog captures: chromium 131.0.6778.33, chromium 134.0.6998.35, chromium 133.0.6943.16.The fingerprint page shows the full measured match list. More on the catalog.1

HTTP request (JA4H)

fingerprintco-occurrences
ge11nn060000_cc5ecf4edfc7_000000000000_00000000000083
ge11nn050000_1e015d7f8561_000000000000_00000000000078
ge11nn070000_26feb861b49b_000000000000_00000000000076
ge11nn040000_be74ea4f9dce_000000000000_00000000000042
ge11nr09enus_42b20cf94b41_000000000000_0000000000004
he11nr08enus_4fe1a7c7b320_000000000000_0000000000004
ge20nn080000_a05a20c662b8_000000000000_0000000000004
ge20nr090000_65d4d215624f_000000000000_0000000000003
ge11nn030000_0db47b7d240d_000000000000_0000000000003
ge11nn050000_304165ead156_000000000000_0000000000003

HTTP/2 frames (Akamai)

fingerprintco-occurrences
2:0;1:4096;8:0;3:1024;4:33554432|25100289|0|m,s,p,a12
1:65536;2:0;4:6291456;6:262144|15663105|1:1:0:110|m,a,s,p4
1:65536;2:0;4:6291456;6:262144|15663105|1:1:0:183|m,a,s,p2
1:65536;2:0;4:6291456;6:262144|15663105|1:1:0:256|m,a,s,p Match?Exact match in Thumbprint's published controlled catalog captures: chromium 131.0.6778.33, chromium 151.0.7922.34, chrome 151.0.7922.137, +43 more.The fingerprint page shows the full measured match list. More on the catalog.1

User-Agent

fingerprintco-occurrences
Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.7778.96 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)163
Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.7778.96 Mobile Safari/537.36 (compatible; GoogleOther)55
Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)52
Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4844.84 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)9
Mozilla/5.0 (Linux; Android 11; moto g power (2022)) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Mobile Safari/537.36 Chrome-Lighthouse9
Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Safari/537.36 AppEngine-Google; (+http://code.google.com/appengine; appid: s~virustotalcloud)4
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36 Chrome-Lighthouse3
Chrome Privacy Preserving Prefetch Proxy3
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.363
GoogleOther3

Country

fingerprintco-occurrences
US · United States280
BE · Belgium30
BR · Brazil1
SE · Sweden1

Network (ASN)

fingerprintco-occurrences
AS15169 · Google LLC303
AS396982 · Google LLC8
AS701 · Verizon Business1