TCP SYN (p0f)
4:43+21:0:1424:mss*29,7:mss,sok,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,ws:df,id+:0
first seen 2026-08-13 04:37 · last seen 2026-09-15 05:04 · JSON
Last 7 days (2 observations)
Distinct clients per day (last 30 days, peak 1/day)
Distinct clients are counted by IP-hash per complete UTC day — unlike observation counts this is insensitive to one chatty client, but NAT merges clients and address rotation splits them.
Decomposed attributes
| IP version | 4 |
|---|---|
| Initial TTL | 43+21 |
| Options length | 0 |
| MSS | 1424 |
| Window size | mss*29 |
| Window scale | 7 |
| Options layout | mss,sok,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,nop,ws |
| Quirks | df,id+ |
| Payload class | 0 |
Co-observed signals
Signals from other families seen in the same observation. A fingerprint spread thinly across many lower-layer signatures is a classic inconsistency signal.
TLS ClientHello (JA4)
| fingerprint | co-occurrences |
|---|---|
t13d1516h2_8daaf6152771_e5627efa2ab1 | 8 |
HTTP request (JA4H)
| fingerprint | co-occurrences |
|---|---|
ge20nr100000_3a9ba06c504b_000000000000_000000000000 | 5 |
ge20nn110000_5a0617034b33_000000000000_000000000000 | 2 |
ge20nn110000_f553327a6567_000000000000_000000000000 | 1 |
HTTP/2 frames (Akamai)
TCP SYN (JA4T)
| fingerprint | co-occurrences |
|---|---|
42340_2-4-1-1-1-1-1-1-1-1-1-1-1-3_1424_7 | 8 |
User-Agent
Country
| fingerprint | co-occurrences |
|---|---|
CN · China | 8 |
Network (ASN)
| fingerprint | co-occurrences |
|---|---|
AS134763 · CHINANET Guangdong province network | 6 |
AS45090 · Shenzhen Tencent Computer Systems Company Limited | 2 |