t12d630400_4607ee80f03a_3549fbaf615c
Shares its JA4_c (3549fbaf615c) with 6 fingerprints classified as scanner, and nothing else in that family disagrees — the same tool under different cipher options. Inferred from the family, not observed directly.
What this fingerprint encodes
t12d630400
handshake shape, human-readable
4607ee80f03a
truncated hash of the cipher list
3549fbaf615c
truncated hash of extensions + signature algorithms
- Transport
- TCP
- TLS version
- TLS 1.2
- Server name
- server name sent
- Cipher suites offered
- 63
- Extensions offered
- 4
- ALPN
- none offered
Same tool, different options
These 12 other fingerprints share this one's JA4_c — the extension and signature-algorithm hash. A client that keeps its extension set constant while varying its cipher list produces exactly this pattern, which is what a scanner iterating cipher suites looks like. A JA3 cannot show you this: its single MD5 collapses ciphers and extensions together, so every variation looks like an unrelated client.
- t12d640400_13a2a23d501b_3549fbaf615c
- t12d640400_67f0ca237a44_3549fbaf615c
- t12d640400_a3acda31d846_3549fbaf615c
- t12d640400_e31a90cd0803_3549fbaf615c
- t12d640400_e7b476f9520b_3549fbaf615c
- t12d640400_f559eb9565fd_3549fbaf615c
- t12d060400_272d6f91cd02_3549fbaf615c
- t12d630400_305e7cc661dc_3549fbaf615c
- t12d630400_6ea97102b799_3549fbaf615c
- t12d630400_a819cc8c6927_3549fbaf615c
- t12d630400_c47ce3b2bf1f_3549fbaf615c
- t12d630400_f4a33ce78bd4_3549fbaf615c
The hello it was computed from
Recovered because the proxy now stores the pre-hash JA3 string alongside the digest. Every number below came out of this client's ClientHello; anything we cannot name in the IANA registry is shown as its raw value rather than guessed at.
- Version
- TLS 1.2
Cipher suites 63
-
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA -
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 -
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 -
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA -
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384 -
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 -
49228 (0xc04c) -
TLS_ECDHE_ECDSA_WITH_CAMELLIA_128_CBC_SHA256 -
49229 (0xc04d) -
TLS_ECDHE_ECDSA_WITH_CAMELLIA_256_CBC_SHA384 -
TLS_RSA_WITH_CAMELLIA_128_GCM_SHA256 -
49290 (0xc08a) -
TLS_RSA_WITH_CAMELLIA_256_GCM_SHA384 -
49291 (0xc08b) -
TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 -
TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 (draft) -
49168 (0xc010) -
TLS_ECDHE_RSA_WITH_RC4_128_SHA -
49155 (0xc003) -
74 (0x004a) -
49156 (0xc004) -
75 (0x004b) -
49189 (0xc025) -
49197 (0xc02d) -
49157 (0xc005) -
76 (0x004c) -
49190 (0xc026) -
49198 (0xc02e) -
49226 (0xc04a) -
49246 (0xc05e) -
49227 (0xc04b) -
49247 (0xc05f) -
49268 (0xc074) -
49288 (0xc088) -
49269 (0xc075) -
49289 (0xc089) -
73 (0x0049) -
49153 (0xc001) -
71 (0x0047) -
49154 (0xc002) -
72 (0x0048) -
78 (0x004e) -
77 (0x004d) -
49165 (0xc00d) -
49166 (0xc00e) -
49193 (0xc029) -
49201 (0xc031) -
49167 (0xc00f) -
49194 (0xc02a) -
49202 (0xc032) -
49230 (0xc04e) -
49250 (0xc062) -
49231 (0xc04f) -
49251 (0xc063) -
49272 (0xc078) -
49292 (0xc08c) -
49273 (0xc079) -
49293 (0xc08d) -
49163 (0xc00b) -
49164 (0xc00c) -
91 (0x005b) -
92 (0x005c) -
87 (0x0057)
Extensions 4
-
supported_groups -
ec_point_formats -
server_name -
signature_algorithms
Named groups 6
-
secp256r1 -
secp384r1 -
secp521r1 -
x25519 -
ffdhe2048 -
SecP256r1MLKEM768
Point formats 1
-
uncompressed
Raw JA3 string
771,49171-49191-49199-49172-49192-49200-49228-49248-49229-49249-49270-49290-49271-49291-52392-52243-49168-49169-49155-74-49156-75-49189-49197-49157-76-49190-49198-49226-49246-49227-49247-49268-49288-49269-49289-73-49153-71-49154-72-78-77-49165-49166-49193-49201-49167-49194-49202-49230-49250-49231-49251-49272-49292-49273-49293-49163-49164-91-92-87,10-11-0-13,23-24-25-29-256-4588,0
Seen in live traffic
- Connections
- 1
- First seen
- 2026-08-27 08:59 UTC
- Last seen
- 2026-08-27 08:59 UTC
- Transport
- TCP
This entry is an observation, not a policy decision. It is here because the edge saw it, not because anyone reviewed it, and it blocks nothing on its own. Only the curated tier drives classification and banning.