t12d630400_305e7cc661dc_3549fbaf615c
Shares its JA4_c (3549fbaf615c) with 6 fingerprints classified as scanner, and nothing else in that family disagrees — the same tool under different cipher options. Inferred from the family, not observed directly.
What this fingerprint encodes
t12d630400
handshake shape, human-readable
305e7cc661dc
truncated hash of the cipher list
3549fbaf615c
truncated hash of extensions + signature algorithms
- Transport
- TCP
- TLS version
- TLS 1.2
- Server name
- server name sent
- Cipher suites offered
- 63
- Extensions offered
- 4
- ALPN
- none offered
Same tool, different options
These 12 other fingerprints share this one's JA4_c — the extension and signature-algorithm hash. A client that keeps its extension set constant while varying its cipher list produces exactly this pattern, which is what a scanner iterating cipher suites looks like. A JA3 cannot show you this: its single MD5 collapses ciphers and extensions together, so every variation looks like an unrelated client.
- t12d640400_13a2a23d501b_3549fbaf615c
- t12d640400_67f0ca237a44_3549fbaf615c
- t12d640400_a3acda31d846_3549fbaf615c
- t12d640400_e31a90cd0803_3549fbaf615c
- t12d640400_e7b476f9520b_3549fbaf615c
- t12d640400_f559eb9565fd_3549fbaf615c
- t12d060400_272d6f91cd02_3549fbaf615c
- t12d630400_4607ee80f03a_3549fbaf615c
- t12d630400_6ea97102b799_3549fbaf615c
- t12d630400_a819cc8c6927_3549fbaf615c
- t12d630400_c47ce3b2bf1f_3549fbaf615c
- t12d630400_f4a33ce78bd4_3549fbaf615c
The hello it was computed from
Recovered because the proxy now stores the pre-hash JA3 string alongside the digest. Every number below came out of this client's ClientHello; anything we cannot name in the IANA registry is shown as its raw value rather than guessed at.
- Version
- TLS 1.2
Cipher suites 63
-
49175 (0xc017) -
90 (0x005a) -
49176 (0xc018) -
49177 (0xc019) -
89 (0x0059) -
49173 (0xc015) -
49174 (0xc016) -
88 (0x0058) -
79 (0x004f) -
82 (0x0052) -
81 (0x0051) -
80 (0x0050) -
83 (0x0053) -
86 (0x0056) -
85 (0x0055) -
84 (0x0054) -
129 (0x0081) -
131 (0x0083) -
128 (0x0080) -
130 (0x0082) -
49410 (0xc102) -
49408 (0xc100) -
49409 (0xc101) -
41 (0x0029) -
38 (0x0026) -
42 (0x002a) -
39 (0x0027) -
43 (0x002b) -
40 (0x0028) -
35 (0x0023) -
31 (0x001f) -
34 (0x0022) -
30 (0x001e) -
37 (0x0025) -
33 (0x0021) -
36 (0x0024) -
32 (0x0020) -
0 (0x0000) -
49322 (0xc0aa) -
49323 (0xc0ab) -
139 (0x008b) -
140 (0x008c) -
174 (0x00ae) -
49316 (0xc0a4) -
49320 (0xc0a8) -
168 (0x00a8) -
141 (0x008d) -
175 (0x00af) -
49317 (0xc0a5) -
49321 (0xc0a9) -
169 (0x00a9) -
49252 (0xc064) -
49258 (0xc06a) -
49253 (0xc065) -
49259 (0xc06b) -
49300 (0xc094) -
49294 (0xc08e) -
49301 (0xc095) -
49295 (0xc08f) -
52395 (0xccab) -
44 (0x002c) -
176 (0x00b0) -
177 (0x00b1)
Extensions 4
-
supported_groups -
ec_point_formats -
server_name -
signature_algorithms
Named groups 6
-
secp256r1 -
secp384r1 -
secp521r1 -
x25519 -
ffdhe2048 -
SecP256r1MLKEM768
Point formats 1
-
uncompressed
Raw JA3 string
771,49175-90-49176-49177-89-49173-49174-88-79-82-81-80-83-86-85-84-129-131-128-130-49410-49408-49409-41-38-42-39-43-40-35-31-34-30-37-33-36-32-0-49322-49323-139-140-174-49316-49320-168-141-175-49317-49321-169-49252-49258-49253-49259-49300-49294-49301-49295-52395-44-176-177,10-11-0-13,23-24-25-29-256-4588,0
Seen in live traffic
- Connections
- 1
- First seen
- 2026-08-27 08:59 UTC
- Last seen
- 2026-08-27 08:59 UTC
- Transport
- TCP
This entry is an observation, not a policy decision. It is here because the edge saw it, not because anyone reviewed it, and it blocks nothing on its own. Only the curated tier drives classification and banning.