TLS ClientHello (JA4)

t13d191000_9dc949149365_e7c285222651

first seen 2026-06-11 21:11 · last seen 2026-09-15 19:07 · JSON

Identified as ngrok ?Identity labels come from the community JA4+ database by FoxIO — applications observed with a JA4 fingerprint, not something this site measured. A JA4 identifies a TLS stack, so unrelated applications built on the same stack (notably the many Chromium-based browsers) legitimately share one: labels are a ranked distribution, never a verdict.Labels are loaded from a snapshot and cover only the JA4 family. Where a fingerprint page shows matches controlled captures, that is Thumbprint's own measured truth instead. More on methodology. — per the JA4+ database; JA4 is a TLS-stack fingerprint, so unrelated clients can share one.

Last 7 days (26 observations)

Distinct clients per day (last 30 days, peak 5/day)

Distinct clients are counted by IP-hash per complete UTC day — unlike observation counts this is insensitive to one chatty client, but NAT merges clients and address rotation splits them.

Decomposed attributes

Protocolt (TLS over TCP)
TLS version13
SNId (domain)
Cipher count19
Extension count10
ALPN00
Ciphers000a, 002f, 0035, 009c, 009d, 1301, 1302, 1303, c009, c00a, c012, c013, c014, c02b, c02c, c02f, c030, cca8, cca9
Extensions0005, 000a, 000b, 000d, 0012, 0017, 002b, 0033, ff01
Signature algorithms0804, 0403, 0807, 0805, 0806, 0401, 0501, 0601, 0503, 0603, 0201, 0203
JA4_rt13d191000_000a,002f,0035,009c,009d,1301,1302,1303,c009,c00a,c012,c013,c014,c02b,c02c,c02f,c030,cca8,cca9_0005,000a,000b,000d,0012,0017,002b,0033,ff01_0804,0403,0807,0805,0806,0401,0501,0601,0503,0603,0201,0203
JA4_o (sample)t13d191000_b565e0f3de94_e7abbb9eee14
JA4_ro (sample)t13d191000_c02b,c02f,c02c,c030,cca9,cca8,c009,c013,c00a,c014,009c,009d,002f,0035,c012,000a,1301,1302,1303_0000,0005,000a,000b,000d,ff01,0017,0012,002b,0033_0804,0403,0807,0805,0806,0401,0501,0601,0503,0603,0201,0203

Co-observed signals

Signals from other families seen in the same observation. A fingerprint spread thinly across many lower-layer signatures is a classic inconsistency signal.

HTTP request (JA4H)

fingerprintco-occurrences
ge11nn020000_3ed38b250d3d_000000000000_00000000000081
ge11nn05zh00_4ee89fec50ea_000000000000_00000000000080
ge11nn040000_8391bea91fb6_000000000000_00000000000077
ge11nr050000_a1c329e38462_000000000000_00000000000070
ge11nr040000_e1d2031bdfea_000000000000_00000000000042
ge11nn05zh00_ddc401472a00_000000000000_00000000000029
ge11nn030000_0db47b7d240d_000000000000_00000000000018
ge11nr040000_8391bea91fb6_000000000000_0000000000009
ge11nn06zh00_d81147f3cea4_000000000000_0000000000008
he11nn020000_818f42cc3fd7_000000000000_0000000000007

TCP SYN (p0f)

fingerprintco-occurrences
4:49+15:0:1460:mss*29,9:mss,sok,ts,nop,ws:df,id+:064
4:50+14:0:1460:mss*29,9:mss,sok,ts,nop,ws:df,id+:050
4:46+18:0:1400:mss*20,7:mss,sok,ts,nop,ws:df,id+:036
4:47+17:0:1360:mss*48,7:mss,sok,ts,nop,ws:df,id+:031
4:44+20:0:1412:mss*46,7:mss,sok,ts,nop,ws:df,id+:028
4:46+18:0:1360:mss*48,7:mss,sok,ts,nop,ws:df,id+:026
4:43+21:0:1460:mss*20,7:mss,sok,ts,nop,ws:df,id+:020
4:42+22:0:1400:mss*20,7:mss,sok,ts,nop,ws:df,id+:019
4:43+21:0:1412:mss*46,7:mss,sok,ts,nop,ws:df,id+:019
4:47+17:0:1460:mss*29,9:mss,sok,ts,nop,ws:df,id+:017

TCP SYN (JA4T)

fingerprintco-occurrences
42340_2-4-8-1-3_1460_9136
65280_2-4-8-1-3_1360_773
64952_2-4-8-1-3_1412_761
29200_2-4-8-1-3_1460_747
64240_2-4-8-1-3_1460_720
42340_2-4-8-1-3_1460_1216
64240_2-1-3-1-1-4_1460_811
64800_2-4-8-1-3_1440_77
64240_2-4-8-1-3_1460_83
64952_2-4-8-1-3_1412_83

User-Agent

fingerprintco-occurrences
Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.3681
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.3676
Mozilla/5.0 (Linux; Android 11; vivo 1906; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/87.0.4280.141 Mobile Safari/537.36 VivoBrowser/8.9.0.065
Go-http-client/1.163
Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/63.0.3239.132 Safari/537.36 QIHU 360SE47
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.121 Safari/537.3634
curl/7.4.031
okhttp/3.14.910
Mozilla/5.0 CMS-Detector/1.07
curl/7.29.06

Country

fingerprintco-occurrences
CN · China283
NL · Netherlands90
HK · Hong Kong SAR China47
TH · Thailand21
US · United States19
DE · Germany16
RO · Romania6
FR · France4
IN · India3
SI · Slovenia3

Network (ASN)

fingerprintco-occurrences
AS4134 · CHINANET BACKBONE183
AS135377 · UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED75
AS213790 · Limited Network LTD67
AS58461 · CT HangZhou IDC47
AS4837 · CHINA UNICOM China169 Backbone39
AS48090 · TECHOFF SRV LIMITED19
AS63949 · Akamai Connected Cloud11
AS23724 · IDC, China Telecommunications Corporation8
AS47890 · UNMANAGED LTD6
AS401626 · Netiface America, Inc.5