q13d0311h3_55b375c5d22e_00d49a47e7d1
Chrome — inferred from the User-Agent on its requests.
What this fingerprint encodes
q13d0311h3
handshake shape, human-readable
55b375c5d22e
truncated hash of the cipher list
00d49a47e7d1
truncated hash of extensions + signature algorithms
- Transport
- QUIC
- TLS version
- TLS 1.3
- Server name
- server name sent
- Cipher suites offered
- 3
- Extensions offered
- 11
- ALPN
- h3
The hello it was computed from
Recovered because the proxy now stores the pre-hash JA3 string alongside the digest. Every number below came out of this client's ClientHello; anything we cannot name in the IANA registry is shown as its raw value rather than guessed at.
- Version
- TLS 1.2
Cipher suites 3
-
TLS_AES_128_GCM_SHA256 -
TLS_AES_256_GCM_SHA384 -
TLS_CHACHA20_POLY1305_SHA256
Extensions 11
-
signature_algorithms -
quic_transport_parameters -
encrypted_client_hello -
application_settings -
supported_groups -
key_share -
server_name -
psk_key_exchange_modes -
compress_certificate -
application_layer_protocol_negotiation -
supported_versions
Named groups 4
-
X25519Kyber768Draft00 -
x25519 -
secp256r1 -
secp384r1
Raw JA3 string
771,4865-4866-4867,13-57-65037-17513-10-51-0-45-27-16-43,25497-29-23-24,
Seen in live traffic
- Connections
- 20
- First seen
- 2026-09-03 18:37 UTC
- Last seen
- 2026-10-09 13:18 UTC
- Transport
- QUIC
- JA3 hashes absorbed
- 20
The same client, 20 different JA3s
This one JA4 covers 20 distinct JA3 hashes. A JA3 hashes the cipher and extension lists in the order they arrived, so a client that shuffles them — which Chrome and its derivatives do on purpose — produces a new JA3 almost every connection and fragments into what looks like 20 unrelated clients. JA4 sorts those lists before hashing, which is why all of it lands here instead.
1dcc8b4c3961a8e86f03597e05026184e08fa6acc0acfa3f200632fe5fa3b6e6918062656dddf6a99ed3057c367cd752709a5ae39ca584ec6c31ff71ae4244b671f87b2c83f60c7c9183e872fdf6460f6ca6f6a7aa5df2210d97469f937a49d05322e78ad093486676f724f053a67ffb517a0accc488aaeb9724326e5fc9bb94545ec20959a7f012cfd66dfbd7d67ff09ec7ba075891820056ce730571cfa18043d56a1330872c15cd59a003ea511df64c23198d1a564f0a46db1fa9503da8a8- … and 8 more
User-Agents seen on this fingerprint
Mozilla/5.0 (Linux; arm_64; Android 15; 2505DRP06G) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.6998.94 YaBrowser/25.4.5.94.01 Safari/537.3618×Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.6312.86 Safari/537.36 BitSightBot/1.06×Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.363×Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.6367.78 Safari/537.361×Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 UnveilPhishingML/1.0 (+https://sitereview.unveiltech.com/)1×Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.361×
A User-Agent is self-declared and trivially forged, so this names an observation rather than proving an identity. It is still the strongest signal available: the fingerprint comes off the TLS handshake and the User-Agent off the request that followed, and one client build keeping a stable JA4 while changing what it calls itself is a finding in its own right.
This entry is an observation, not a policy decision. It is here because the edge saw it, not because anyone reviewed it, and it blocks nothing on its own. Only the curated tier drives classification and banning.