t13d640700_70d83611e2fb_829ed713d377
Presented a User-Agent we cannot attribute to a known client.
What this fingerprint encodes
t13d640700
handshake shape, human-readable
70d83611e2fb
truncated hash of the cipher list
829ed713d377
truncated hash of extensions + signature algorithms
- Transport
- TCP
- TLS version
- TLS 1.3
- Server name
- server name sent
- Cipher suites offered
- 64
- Extensions offered
- 7
- ALPN
- none offered
The hello it was computed from
Recovered because the proxy now stores the pre-hash JA3 string alongside the digest. Every number below came out of this client's ClientHello; anything we cannot name in the IANA registry is shown as its raw value rather than guessed at.
- Version
- TLS 1.2
Cipher suites 64
-
TLS_EMPTY_RENEGOTIATION_INFO_SCSV -
TLS_AES_256_GCM_SHA384 -
TLS_AES_128_GCM_SHA256 -
TLS_CHACHA20_POLY1305_SHA256 -
TLS_AES_128_CCM_SHA256 -
TLS_AES_128_CCM_8_SHA256 -
TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 -
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 -
TLS_RSA_WITH_AES_256_CCM -
TLS_DHE_RSA_WITH_AES_256_CCM -
TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256 -
TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 -
TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 -
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 -
TLS_RSA_WITH_AES_128_CCM -
TLS_DHE_RSA_WITH_AES_128_CCM -
TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 -
163 (0x00a3) -
TLS_DHE_RSA_WITH_AES_128_GCM_SHA256 -
162 (0x00a2) -
TLS_DHE_RSA_WITH_CHACHA20_POLY1305_SHA256 -
TLS_DHE_RSA_WITH_AES_256_CBC_SHA256 -
106 (0x006a) -
TLS_DHE_RSA_WITH_AES_128_CBC_SHA256 -
64 (0x0040) -
182 (0x00b6) -
149 (0x0095) -
148 (0x0094) -
146 (0x0092) -
49185 (0xc021) -
49186 (0xc022) -
49182 (0xc01e) -
49183 (0xc01f) -
TLS_RSA_WITH_AES_256_CBC_SHA256 -
TLS_RSA_WITH_AES_128_CBC_SHA256 -
TLS_RSA_WITH_AES_256_CBC_SHA -
TLS_RSA_WITH_AES_128_CBC_SHA -
TLS_RSA_WITH_3DES_EDE_CBC_SHA -
TLS_ECDHE_ECDSA_WITH_3DES_EDE_CBC_SHA -
TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA -
TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA -
19 (0x0013) -
49155 (0xc003) -
49165 (0xc00d) -
21 (0x0015) -
9 (0x0009) -
TLS_ECDHE_ECDSA_WITH_RC4_128_SHA -
TLS_ECDHE_RSA_WITH_RC4_128_SHA -
49154 (0xc002) -
49164 (0xc00c) -
TLS_RSA_WITH_RC4_128_SHA -
TLS_RSA_WITH_RC4_128_MD5 -
TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA -
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA -
49157 (0xc005) -
49167 (0xc00f) -
TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA -
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA -
49156 (0xc004) -
49166 (0xc00e) -
TLS_DHE_RSA_WITH_AES_256_CBC_SHA -
56 (0x0038) -
TLS_DHE_RSA_WITH_AES_128_CBC_SHA -
50 (0x0032)
Extensions 7
-
key_share -
ec_point_formats -
supported_versions -
server_name -
signature_algorithms_cert -
supported_groups -
signature_algorithms
Named groups 8
-
x25519 -
x448 -
secp521r1 -
secp384r1 -
secp256r1 -
33 (0x0021) -
32 (0x0020) -
31 (0x001f)
Point formats 1
-
uncompressed
Raw JA3 string
771,255-4866-4865-4867-4868-4869-49196-49200-49325-49327-52393-52392-49195-49199-49324-49326-159-163-158-162-52394-107-106-103-64-182-149-148-146-49185-49186-49182-49183-61-60-53-47-10-49160-49170-22-19-49155-49165-21-9-49159-49169-49154-49164-5-4-49162-49172-49157-49167-49161-49171-49156-49166-57-56-51-50,51-11-43-0-50-10-13,29-30-25-24-23-33-32-31,0
Seen in live traffic
- Connections
- 2
- First seen
- 2026-08-25 10:15 UTC
- Last seen
- 2026-08-25 10:17 UTC
- Transport
- TCP
User-Agents seen on this fingerprint
req/0.5.152×
A User-Agent is self-declared and trivially forged, so this names an observation rather than proving an identity. It is still the strongest signal available: the fingerprint comes off the TLS handshake and the User-Agent off the request that followed, and one client build keeping a stable JA4 while changing what it calls itself is a finding in its own right.
This entry is an observation, not a policy decision. It is here because the edge saw it, not because anyone reviewed it, and it blocks nothing on its own. Only the curated tier drives classification and banning.