TCP SYN (p0f)

4:48+16:0:1412:mss*20,4:mss,sok,ts,nop,ws:df,id+:0

first seen 2026-07-24 00:24 · last seen 2026-07-26 11:11 · JSON

Decomposed attributes

IP version4
Initial TTL48+16
Options length0
MSS1412
Window sizemss*20
Window scale4
Options layoutmss,sok,ts,nop,ws
Quirksdf,id+
Payload class0

Co-observed signals

Signals from other families seen in the same observation. A fingerprint spread thinly across many lower-layer signatures is a classic inconsistency signal.

TLS ClientHello (JA4)

fingerprintco-occurrences
t13d4412h1_fd39b124ee10_58ed7828516f5

HTTP request (JA4H)

fingerprintco-occurrences
ge11nn050000_b223a0ebb0b5_000000000000_000000000000 Match?Exact match in Thumbprint's published controlled catalog captures: python-requests 2.34.2, python-requests 2.33.1, python-requests 2.32.3.The fingerprint page shows the full measured match list. More on the catalog.5

TCP SYN (JA4T)

fingerprintco-occurrences
29200_2-4-8-1-3_1412_45

User-Agent

fingerprintco-occurrences
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.163 Safari/537.361
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/37.0.2062.124 Safari/537.361
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3790.0 Safari/537.361
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/106.0.0.0 Safari/537.36 Agency/97.8.8247.481
Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.361

Country

fingerprintco-occurrences
VE · Venezuela2
PE · Peru1
MU · Mauritius1
PR · Puerto Rico1

Network (ASN)

fingerprintco-occurrences
AS272836 · CALA SERVICIOS INTEGRALES E.I.R.L.1
AS23889 · Mauritius Telecom Ltd1
AS11562 · Net Uno, C.A.1
AS263806 · GALAXY ENTERTAINMENT DE VENEZUELA, S.C.A.1
AS30526 · Neptuno Media, Inc.1