TCP SYN (p0f)
4:46+18:0:1398:mss*44,7:mss,sok,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,ws:df,id+:0
first seen 2026-07-15 08:44 · last seen 2026-07-29 11:47 · JSON
Decomposed attributes
| IP version | 4 |
| Initial TTL | 46+18 |
| Options length | 0 |
| MSS | 1398 |
| Window size | mss*44 |
| Window scale | 7 |
| Options layout | mss,sok,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,ws |
| Quirks | df,id+ |
| Payload class | 0 |
Co-observed signals
Signals from other families seen in the same observation. A fingerprint spread thinly across many lower-layer signatures is a classic inconsistency signal.
TLS ClientHello (JA4)
| fingerprint | co-occurrences |
t13d1516h2_8daaf6152771_02713d6af862 Match?Exact match in Thumbprint's published controlled catalog captures: chromium 131.0.6778.33, chromium 134.0.6998.35, chromium 133.0.6943.16.The fingerprint page shows the full measured match list. More on the catalog. | 8 |
HTTP request (JA4H)
HTTP/2 frames (Akamai)
TCP SYN (JA4T)
User-Agent
Country
| fingerprint | co-occurrences |
CN · China | 8 |
Network (ASN)
| fingerprint | co-occurrences |
AS4134 · CHINANET BACKBONE | 8 |