TLS ClientHello (JA4)

t12d610700_8a10cb45a794_4446390ac224

first seen 2026-06-22 11:08 · last seen 2026-09-15 01:09 · JSON

Last 7 days (2 observations)

Distinct clients per day (last 30 days, peak 6/day)

Distinct clients are counted by IP-hash per complete UTC day — unlike observation counts this is insensitive to one chatty client, but NAT merges clients and address rotation splits them.

Decomposed attributes

Protocolt (TLS over TCP)
TLS version12
SNId (domain)
Cipher count61
Extension count7
ALPN00
Ciphers0005, 000a, 0013, 0016, 002f, 0032, 0033, 0035, 0038, 0039, 003c, 003d, 0040, 0041, 0044, 0045, 0067, 006a, 006b, 0084, 0087, 0088, 009c, 009d, 009e, 009f, 00a2, 00a3, 00ff, c002, c003, c004, c005, c007, c008, c009, c00a, c00c, c00d, c00e, c00f, c011, c012, c013, c014, c023, c024, c025, c026, c027, c028, c029, c02a, c02b, c02c, c02d, c02e, c02f, c030, c031, c032
Extensions000a, 000b, 000d, 000f, 0015, 0023
Signature algorithms0601, 0602, 0603, 0501, 0502, 0503, 0401, 0402, 0403, 0301, 0302, 0303, 0201, 0202, 0203
JA4_rt12d610700_0005,000a,0013,0016,002f,0032,0033,0035,0038,0039,003c,003d,0040,0041,0044,0045,0067,006a,006b,0084,0087,0088,009c,009d,009e,009f,00a2,00a3,00ff,c002,c003,c004,c005,c007,c008,c009,c00a,c00c,c00d,c00e,c00f,c011,c012,c013,c014,c023,c024,c025,c026,c027,c028,c029,c02a,c02b,c02c,c02d,c02e,c02f,c030,c031,c032_000a,000b,000d,000f,0015,0023_0601,0602,0603,0501,0502,0503,0401,0402,0403,0301,0302,0303,0201,0202,0203
JA4_o (sample)t12d610700_6da83dda9e2f_dbabfdc6ab47
JA4_ro (sample)t12d610700_c030,c02c,c032,c02e,c02f,c02b,c031,c02d,00a3,009f,00a2,009e,c028,c024,c014,c00a,c02a,c026,c00f,c005,006b,006a,0039,0038,c027,c023,c013,c009,c029,c025,c00e,c004,0067,0040,0033,0032,c012,c008,c00d,c003,0088,0087,0045,0044,0016,0013,009d,009c,003d,0035,003c,002f,0084,0041,000a,c011,c007,c00c,c002,0005,00ff_0000,000b,000a,0023,000d,000f,0015_0601,0602,0603,0501,0502,0503,0401,0402,0403,0301,0302,0303,0201,0202,0203

Co-observed signals

Signals from other families seen in the same observation. A fingerprint spread thinly across many lower-layer signatures is a classic inconsistency signal.

HTTP request (JA4H)

fingerprintco-occurrences
ge11nn040000_4f6f4aad0c1e_000000000000_000000000000163
ge11nn030000_e6b8afd94bfa_000000000000_0000000000007
ge11nn040000_8653dc51bec2_000000000000_0000000000001

TCP SYN (p0f)

fingerprintco-occurrences
4:43+21:0:1460:mss*29,10:mss,sok,ts,nop,ws:df,id+:031
4:43+21:0:1460:35844,10:mss,sok,ts,nop,ws:df,id+:024
4:44+20:0:1460:35844,10:mss,sok,ts,nop,ws:df,id+:023
4:44+20:0:1460:mss*29,10:mss,sok,ts,nop,ws:df,id+:022
4:42+22:0:1460:mss*29,10:mss,sok,ts,nop,ws:df,id+:020
4:46+18:0:1460:mss*29,10:mss,sok,ts,nop,ws:df,id+:010
4:42+22:0:1460:35844,10:mss,sok,ts,nop,ws:df,id+:010
4:45+19:0:1460:mss*29,10:mss,sok,ts,nop,ws:df,id+:07
4:49+15:0:1460:35844,10:mss,sok,ts,nop,ws:df,id+:06
4:49+15:0:1460:mss*29,10:mss,sok,ts,nop,ws:df,id+:04

TCP SYN (JA4T)

fingerprintco-occurrences
42340_2-4-8-1-3_1460_1097
35844_2-4-8-1-3_1460_1063
42300_2-4-8-1-3_1410_103

User-Agent

fingerprintco-occurrences
Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; https://bytedance.sg.larkoffice.com/docx/K5bxdypulop3IIxrJb0lOjLVgFe)86
Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; spider-feedback@bytedance.com)62
Mozilla/5.0 (Linux; Android 5.0) AppleWebKit/537.36 (KHTML, like Gecko) Mobile Safari/537.36 (compatible; Bytespider; https://zhanzhang.toutiao.com/)23

Country

fingerprintco-occurrences
SG · Singapore148
CN · China23

Network (ASN)

fingerprintco-occurrences
AS16509 · Amazon.com, Inc.148
AS4837 · CHINA UNICOM China169 Backbone16
AS4134 · CHINANET BACKBONE6
AS23724 · IDC, China Telecommunications Corporation1