TCP SYN (p0f)
4:44+20:0:1424:mss*29,7:mss,sok,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,ws:df,id+:0
first seen 2026-08-07 18:53 · last seen 2026-08-07 18:53 · JSON
Decomposed attributes
| IP version | 4 |
| Initial TTL | 44+20 |
| Options length | 0 |
| MSS | 1424 |
| Window size | mss*29 |
| Window scale | 7 |
| Options layout | mss,sok,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,ws |
| Quirks | df,id+ |
| Payload class | 0 |
Co-observed signals
Signals from other families seen in the same observation. A fingerprint spread thinly across many lower-layer signatures is a classic inconsistency signal.
TLS ClientHello (JA4)
HTTP request (JA4H)
HTTP/2 frames (Akamai)
TCP SYN (JA4T)
User-Agent
Country
| fingerprint | co-occurrences |
CN · China | 3 |
Network (ASN)
| fingerprint | co-occurrences |
AS56040 · China Mobile communications corporation | 3 |