t12d630400_c47ce3b2bf1f_3549fbaf615c
Shares its JA4_c (3549fbaf615c) with 6 fingerprints classified as scanner, and nothing else in that family disagrees — the same tool under different cipher options. Inferred from the family, not observed directly.
What this fingerprint encodes
t12d630400
handshake shape, human-readable
c47ce3b2bf1f
truncated hash of the cipher list
3549fbaf615c
truncated hash of extensions + signature algorithms
- Transport
- TCP
- TLS version
- TLS 1.2
- Server name
- server name sent
- Cipher suites offered
- 63
- Extensions offered
- 4
- ALPN
- none offered
Same tool, different options
These 12 other fingerprints share this one's JA4_c — the extension and signature-algorithm hash. A client that keeps its extension set constant while varying its cipher list produces exactly this pattern, which is what a scanner iterating cipher suites looks like. A JA3 cannot show you this: its single MD5 collapses ciphers and extensions together, so every variation looks like an unrelated client.
- t12d640400_13a2a23d501b_3549fbaf615c
- t12d640400_67f0ca237a44_3549fbaf615c
- t12d640400_a3acda31d846_3549fbaf615c
- t12d640400_e31a90cd0803_3549fbaf615c
- t12d640400_e7b476f9520b_3549fbaf615c
- t12d640400_f559eb9565fd_3549fbaf615c
- t12d060400_272d6f91cd02_3549fbaf615c
- t12d630400_305e7cc661dc_3549fbaf615c
- t12d630400_4607ee80f03a_3549fbaf615c
- t12d630400_6ea97102b799_3549fbaf615c
- t12d630400_a819cc8c6927_3549fbaf615c
- t12d630400_f4a33ce78bd4_3549fbaf615c
The hello it was computed from
Recovered because the proxy now stores the pre-hash JA3 string alongside the digest. Every number below came out of this client's ClientHello; anything we cannot name in the IANA registry is shown as its raw value rather than guessed at.
- Version
- TLS 1.2
Cipher suites 63
-
138 (0x008a) -
98 (0x0062) -
97 (0x0061) -
96 (0x0060) -
100 (0x0064) -
8 (0x0008) -
6 (0x0006) -
3 (0x0003) -
147 (0x0093) -
148 (0x0094) -
182 (0x00b6) -
172 (0x00ac) -
149 (0x0095) -
183 (0x00b7) -
173 (0x00ad) -
49256 (0xc068) -
49262 (0xc06e) -
49257 (0xc069) -
49263 (0xc06f) -
49304 (0xc098) -
49298 (0xc092) -
49305 (0xc099) -
49299 (0xc093) -
52398 (0xccae) -
46 (0x002e) -
184 (0x00b8) -
185 (0x00b9) -
146 (0x0092) -
124 (0x007c) -
TLS_RSA_WITH_3DES_EDE_CBC_SHA -
125 (0x007d) -
TLS_RSA_WITH_AES_128_CBC_SHA -
TLS_RSA_WITH_AES_128_CBC_SHA256 -
TLS_DHE_RSA_WITH_ARIA_128_GCM_SHA256 -
TLS_ECDHE_ECDSA_WITH_ARIA_128_GCM_SHA256 -
TLS_RSA_WITH_AES_128_GCM_SHA256 -
126 (0x007e) -
TLS_RSA_WITH_AES_256_CBC_SHA -
TLS_RSA_WITH_AES_256_CBC_SHA256 -
TLS_DHE_RSA_WITH_ARIA_256_GCM_SHA384 -
TLS_ECDHE_ECDSA_WITH_ARIA_256_GCM_SHA384 -
TLS_RSA_WITH_AES_256_GCM_SHA384 -
49212 (0xc03c) -
49232 (0xc050) -
49213 (0xc03d) -
49233 (0xc051) -
TLS_RSA_WITH_CAMELLIA_128_CBC_SHA -
TLS_RSA_WITH_CAMELLIA_128_CBC_SHA256 -
49274 (0xc07a) -
TLS_RSA_WITH_CAMELLIA_256_CBC_SHA -
TLS_RSA_WITH_CAMELLIA_256_CBC_SHA256 -
49275 (0xc07b) -
9 (0x0009) -
7 (0x0007) -
1 (0x0001) -
2 (0x0002) -
59 (0x003b) -
TLS_RSA_WITH_RC4_128_MD5 -
TLS_RSA_WITH_RC4_128_SHA -
TLS_RSA_WITH_SEED_CBC_SHA -
49180 (0xc01c) -
49183 (0xc01f) -
49186 (0xc022)
Extensions 4
-
supported_groups -
ec_point_formats -
server_name -
signature_algorithms
Named groups 6
-
secp256r1 -
secp384r1 -
secp521r1 -
x25519 -
ffdhe2048 -
SecP256r1MLKEM768
Point formats 1
-
uncompressed
Raw JA3 string
771,138-98-97-96-100-8-6-3-147-148-182-172-149-183-173-49256-49262-49257-49263-49304-49298-49305-49299-52398-46-184-185-146-124-10-125-47-60-49308-49312-156-126-53-61-49309-49313-157-49212-49232-49213-49233-65-186-49274-132-192-49275-9-7-1-2-59-4-5-150-49180-49183-49186,10-11-0-13,23-24-25-29-256-4588,0
Seen in live traffic
- Connections
- 1
- First seen
- 2026-08-27 08:59 UTC
- Last seen
- 2026-08-27 08:59 UTC
- Transport
- TCP
This entry is an observation, not a policy decision. It is here because the edge saw it, not because anyone reviewed it, and it blocks nothing on its own. Only the curated tier drives classification and banning.