t12i570500_2a2bed94251f_a1e935682795
Probe (no SNI, no ALPN) — inferred from the JA4 handshake shape.
What this fingerprint encodes
t12i570500
handshake shape, human-readable
2a2bed94251f
truncated hash of the cipher list
a1e935682795
truncated hash of extensions + signature algorithms
- Transport
- TCP
- TLS version
- TLS 1.2
- Server name
- no server name (IP literal)
- Cipher suites offered
- 57
- Extensions offered
- 5
- ALPN
- none offered
The hello it was computed from
Recovered because the proxy now stores the pre-hash JA3 string alongside the digest. Every number below came out of this client's ClientHello; anything we cannot name in the IANA registry is shown as its raw value rather than guessed at.
- Version
- TLS 1.2
Cipher suites 57
-
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 -
TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 -
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 -
TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384 -
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA -
TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA -
49177 (0xc019) -
49202 (0xc032) -
49198 (0xc02e) -
49194 (0xc02a) -
49190 (0xc026) -
49167 (0xc00f) -
49157 (0xc005) -
TLS_RSA_WITH_AES_256_GCM_SHA384 -
TLS_RSA_WITH_AES_256_CBC_SHA256 -
TLS_RSA_WITH_AES_256_CBC_SHA -
TLS_RSA_WITH_CAMELLIA_256_CBC_SHA -
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 -
TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 -
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 -
TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256 -
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA -
TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA -
49176 (0xc018) -
49201 (0xc031) -
49197 (0xc02d) -
49193 (0xc029) -
49189 (0xc025) -
49166 (0xc00e) -
49156 (0xc004) -
TLS_RSA_WITH_AES_128_GCM_SHA256 -
TLS_RSA_WITH_AES_128_CBC_SHA256 -
TLS_RSA_WITH_AES_128_CBC_SHA -
TLS_RSA_WITH_SEED_CBC_SHA -
TLS_RSA_WITH_CAMELLIA_128_CBC_SHA -
TLS_ECDHE_RSA_WITH_RC4_128_SHA -
TLS_ECDHE_ECDSA_WITH_RC4_128_SHA -
49174 (0xc016) -
49164 (0xc00c) -
49154 (0xc002) -
TLS_RSA_WITH_RC4_128_SHA -
TLS_RSA_WITH_RC4_128_MD5 -
TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA -
TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA -
49175 (0xc017) -
49165 (0xc00d) -
49155 (0xc003) -
TLS_RSA_WITH_3DES_EDE_CBC_SHA -
49168 (0xc010) -
49158 (0xc006) -
49173 (0xc015) -
49163 (0xc00b) -
49153 (0xc001) -
59 (0x003b) -
2 (0x0002) -
1 (0x0001) -
TLS_EMPTY_RENEGOTIATION_INFO_SCSV
Extensions 5
-
ec_point_formats -
supported_groups -
session_ticket -
signature_algorithms -
heartbeat
Named groups 13
-
secp256r1 -
secp521r1 -
28 (0x001c) -
27 (0x001b) -
secp384r1 -
26 (0x001a) -
22 (0x0016) -
14 (0x000e) -
13 (0x000d) -
11 (0x000b) -
12 (0x000c) -
9 (0x0009) -
10 (0x000a)
Point formats 3
-
uncompressed -
ansiX962_compressed_prime -
ansiX962_compressed_char2
Raw JA3 string
771,49200-49196-49192-49188-49172-49162-49177-49202-49198-49194-49190-49167-49157-157-61-53-132-49199-49195-49191-49187-49171-49161-49176-49201-49197-49193-49189-49166-49156-156-60-47-150-65-49169-49159-49174-49164-49154-5-4-49170-49160-49175-49165-49155-10-49168-49158-49173-49163-49153-59-2-1-255,11-10-35-13-15,23-25-28-27-24-26-22-14-13-11-12-9-10,0-1-2
Seen in live traffic
- Connections
- 2
- First seen
- 2026-08-25 22:42 UTC
- Last seen
- 2026-08-25 23:43 UTC
- Transport
- TCP
This entry is an observation, not a policy decision. It is here because the edge saw it, not because anyone reviewed it, and it blocks nothing on its own. Only the curated tier drives classification and banning.