TCP SYN (p0f)
4:54+10:0:1460:mss*44,12:mss,sok,ts,nop,ws:df,id+:0
first seen 2026-06-22 04:14 · last seen 2026-09-08 16:33 · JSON
Distinct clients per day (last 30 days, peak 1/day)
Distinct clients are counted by IP-hash per complete UTC day — unlike observation counts this is insensitive to one chatty client, but NAT merges clients and address rotation splits them.
Decomposed attributes
| IP version | 4 |
|---|---|
| Initial TTL | 54+10 |
| Options length | 0 |
| MSS | 1460 |
| Window size | mss*44 |
| Window scale | 12 |
| Options layout | mss,sok,ts,nop,ws |
| Quirks | df,id+ |
| Payload class | 0 |
Co-observed signals
Signals from other families seen in the same observation. A fingerprint spread thinly across many lower-layer signatures is a classic inconsistency signal.
TLS ClientHello (JA4)
| fingerprint | co-occurrences |
|---|---|
t13d521100_b262b3658495_8e6e362c5eac | 1 |
t13d1516h2_8daaf6152771_d8a2da3f94cd Match?Exact match in Thumbprint's published controlled catalog captures: chromium 149.0.7827.102, chrome 149.0.7827.102, chrome 149.0.7827.156, +25 more.The fingerprint page shows the full measured match list. More on the catalog. | 1 |
HTTP request (JA4H)
| fingerprint | co-occurrences |
|---|---|
ge11nr15enus_e571cdacc238_000000000000_000000000000 | 1 |
ge20nn11zhcn_33778c32ea55_000000000000_000000000000 | 1 |
HTTP/2 frames (Akamai)
| fingerprint | co-occurrences |
|---|---|
1:65536;2:0;4:6291456;6:262144|15663105|1:1:0:220|m,a,s,p Match?Exact match in Thumbprint's published controlled catalog captures: chrome 150.0.7871.187, chromium 149.0.7827.102, chrome 149.0.7827.102, +59 more.The fingerprint page shows the full measured match list. More on the catalog. | 1 |
TCP SYN (JA4T)
| fingerprint | co-occurrences |
|---|---|
64240_2-4-8-1-3_1460_12 | 1 |
User-Agent
Country
| fingerprint | co-occurrences |
|---|---|
US · United States | 1 |
SG · Singapore | 1 |
Network (ASN)
| fingerprint | co-occurrences |
|---|---|
AS49683 · MASSIVEGRID LTD | 1 |
AS154602 · BACK WAVES LIMITED | 1 |