t12d020500_a7802ed2ba9f_fb388e60c1a9
Completed a TLS handshake but never an HTTP request, so no User-Agent was ever presented.
What this fingerprint encodes
t12d020500
handshake shape, human-readable
a7802ed2ba9f
truncated hash of the cipher list
fb388e60c1a9
truncated hash of extensions + signature algorithms
- Transport
- TCP
- TLS version
- TLS 1.2
- Server name
- server name sent
- Cipher suites offered
- 2
- Extensions offered
- 5
- ALPN
- none offered
Same tool, different options
These 21 other fingerprints share this one's JA4_c — the extension and signature-algorithm hash. A client that keeps its extension set constant while varying its cipher list produces exactly this pattern, which is what a scanner iterating cipher suites looks like. A JA3 cannot show you this: its single MD5 collapses ciphers and extensions together, so every variation looks like an unrelated client.
- t12d020500_017f96aa3752_fb388e60c1a9
- t12d020500_1846c2936b89_fb388e60c1a9
- t12d020500_20953c10fd1e_fb388e60c1a9
- t12d020500_257973278e6d_fb388e60c1a9
- t12d020500_2901e63b1132_fb388e60c1a9
- t12d020500_311fb8e5b694_fb388e60c1a9
- t12d020500_3d40e48a2282_fb388e60c1a9
- t12d020500_3f35d2254949_fb388e60c1a9
- t12d020500_40046a45f286_fb388e60c1a9
- t12d020500_532f5318fa2e_fb388e60c1a9
- t12d020500_5550d68fda30_fb388e60c1a9
- t12d020500_5e7453b33de5_fb388e60c1a9
- t12d020500_69403f293a54_fb388e60c1a9
- t12d020500_8c8995b733ef_fb388e60c1a9
- t12d020500_9757046a497d_fb388e60c1a9
- t12d020500_aaba3a77cce3_fb388e60c1a9
- t12d020500_c38774e7e0a0_fb388e60c1a9
- t12d020500_c94d2e240461_fb388e60c1a9
- t12d020500_dab6fbdff9f8_fb388e60c1a9
- t12d020500_efbfc930fd96_fb388e60c1a9
- t12d020500_f290bf0ab7b3_fb388e60c1a9
The hello it was computed from
Recovered because the proxy now stores the pre-hash JA3 string alongside the digest. Every number below came out of this client's ClientHello; anything we cannot name in the IANA registry is shown as its raw value rather than guessed at.
- Version
- TLS 1.2
Cipher suites 2
-
TLS_RSA_WITH_ARIA_128_GCM_SHA256 -
TLS_EMPTY_RENEGOTIATION_INFO_SCSV
Extensions 5
-
server_name -
session_ticket -
encrypt_then_mac -
extended_master_secret -
signature_algorithms
Raw JA3 string
771,49310-255,0-35-22-23-13,,
Seen in live traffic
- Connections
- 1
- First seen
- 2026-08-27 10:11 UTC
- Last seen
- 2026-08-27 10:11 UTC
- Transport
- TCP
This entry is an observation, not a policy decision. It is here because the edge saw it, not because anyone reviewed it, and it blocks nothing on its own. Only the curated tier drives classification and banning.