PQ CRYPTA PLATFORM

🏠 Main

🧪 Interactive Apps

📰 News

🛡️ PQ Crypta Proxy

👤 Account

⟨ QUANTUM ERROR PORTAL ⟩

Navigate the Error Dimensions

PQ Crypta Logo

JA4 t11i990200_0df3f6915705_357e3bc58f3d

Scanner — observed in live traffic

Scanner

t11i990200_0df3f6915705_357e3bc58f3d

Probe (legacy TLS, no SNI, no ALPN) — inferred from the JA4 handshake shape.

What this fingerprint encodes

JA4_a t11i990200 handshake shape, human-readable
JA4_b 0df3f6915705 truncated hash of the cipher list
JA4_c 357e3bc58f3d truncated hash of extensions + signature algorithms
Transport
TCP
TLS version
TLS 1.1
Server name
no server name (IP literal)
Cipher suites offered
99
Extensions offered
2
ALPN
none offered

Same tool, different options

These 1 other fingerprints share this one's JA4_c — the extension and signature-algorithm hash. A client that keeps its extension set constant while varying its cipher list produces exactly this pattern, which is what a scanner iterating cipher suites looks like. A JA3 cannot show you this: its single MD5 collapses ciphers and extensions together, so every variation looks like an unrelated client.

The hello it was computed from

Recovered because the proxy now stores the pre-hash JA3 string alongside the digest. Every number below came out of this client's ClientHello; anything we cannot name in the IANA registry is shown as its raw value rather than guessed at.

Version
TLS 1.1

Cipher suites 399

Extensions 2

Named groups 6

Raw JA3 string
770,49273-49176-151-149-120-150-49227-49165-165-49413-189-49323-91-194-49193-49247-29-187-195-179-68-17-178-49299-92-175-166-49248-49319-49235-13-65279-20-1-81-174-177-142-49261-49289-49190-45-4-64-124-10-27-97-159-23-147-98-49166-49270-49153-50-49224-137-49257-42-49237-8-49249-49230-80-160-115-49191-49207-49246-49282-145-198-49168-49228-49252-104-180-49159-49163-182-33-192-114-49211-43-49177-75-116-47-66-49221-49308-79-36-87-60-4866-49196-89-167-49173-49321-126-49305-14-188-153-51-25-52398-49201-49250-168-49266-172-121-105-49225-176-49295-49192-49242-49331-49304-7-73-55-49285-49271-49326-49206-49197-5-19-135-133-49276-199-99-44-49288-49169-4869-49236-49290-162-49179-49170-9-31-4867-4865-49174-49297-30-49263-48-2-49267-49408-53253-53251-61-49180-67-53249-49189-49199-52396-49217-82-52394-49307-128-52393-49157-49291-49277-53-52245-52244-72-57-52243-49414-49412-49200-49167-190-49410-49409-49258-40-49333-49332-49330-100-49328-86-49327-49184-49324-49322-6-49301-197-49186-49219-49209-129-170-16-49320-156-49318-49317-49316-49315-49187-49313-157-152-49311-143-49158-49309-49265-49306-131-49294-49181-49302-49188-148-49300-185-49298-134-49205-49216-65278-84-49278-49283-49203-49293-49254-108-52392-4868-34-90-4870-63-15-37-49286-109-49296-28-49281-49280-49279-49238-49275-49274-69-49272-49234-161-49268-107-49264-49262-49245-49260-49259-125-21-52-26-62-49256-70-49292-49253-32-49269-144-49244-56-49243-49241-49303-49239-49251-49233-49232-49208-49171-3-38-35-49194-49240-49226-49223-136-22-49222-49220-49172-11-83-49218-24-52395-49175-49-140-186-46-52397-49202-49210-49204-49213-41-49212-49198-96-184-49156-49185-164-49214-39-49314-49325-49183-49182-49178-49231-49164-18-102-130-49161-49160-49310-58-155-53250-132-193-191-49411-49215-183-181-4871-85-139-171-101-49195-103-106-49287-77-78-158-54-49312-154-146-141-138-196-12-49229-119-88-49284-169-49329-173-76-74-71-0-49255-49154-65-59-49155-163-49162,10-15,23-24-25-29-256-4588,

Seen in live traffic

Connections
4
First seen
2026-09-06 23:30 UTC
Last seen
2026-09-07 11:57 UTC
Transport
TCP
JA3 hashes absorbed
4

The same client, 4 different JA3s

This one JA4 covers 4 distinct JA3 hashes. A JA3 hashes the cipher and extension lists in the order they arrived, so a client that shuffles them — which Chrome and its derivatives do on purpose — produces a new JA3 almost every connection and fragments into what looks like 4 unrelated clients. JA4 sorts those lists before hashing, which is why all of it lands here instead.

This entry is an observation, not a policy decision. It is here because the edge saw it, not because anyone reviewed it, and it blocks nothing on its own. Only the curated tier drives classification and banning.