t13d0911h1_f91f431d341e_fe5d0254026e
Completed a TLS handshake but never an HTTP request, so no User-Agent was ever presented.
What this fingerprint encodes
t13d0911h1
handshake shape, human-readable
f91f431d341e
truncated hash of the cipher list
fe5d0254026e
truncated hash of extensions + signature algorithms
- Transport
- TCP
- TLS version
- TLS 1.3
- Server name
- server name sent
- Cipher suites offered
- 9
- Extensions offered
- 11
- ALPN
- h1
The hello it was computed from
Recovered because the proxy now stores the pre-hash JA3 string alongside the digest. Every number below came out of this client's ClientHello; anything we cannot name in the IANA registry is shown as its raw value rather than guessed at.
- Version
- TLS 1.2
Cipher suites 9
-
TLS_AES_256_GCM_SHA384 -
TLS_AES_128_GCM_SHA256 -
TLS_CHACHA20_POLY1305_SHA256 -
TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 -
TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 -
TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256 -
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 -
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 -
TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256
Extensions 11
-
status_request -
server_name -
application_layer_protocol_negotiation -
supported_groups -
key_share -
ec_point_formats -
supported_versions -
signature_algorithms -
extended_master_secret -
psk_key_exchange_modes -
encrypted_client_hello
Named groups 4
-
SecP256r1MLKEM768 -
x25519 -
secp256r1 -
secp384r1
Point formats 1
-
uncompressed
Raw JA3 string
771,4866-4865-4867-49196-49195-52393-49200-49199-52392,5-0-16-10-51-11-43-13-23-45-65037,4588-29-23-24,0
Seen in live traffic
- Connections
- 15
- First seen
- 2026-10-06 19:58 UTC
- Last seen
- 2026-10-06 21:28 UTC
- Transport
- TCP
- JA3 hashes absorbed
- 15
The same client, 15 different JA3s
This one JA4 covers 15 distinct JA3 hashes. A JA3 hashes the cipher and extension lists in the order they arrived, so a client that shuffles them — which Chrome and its derivatives do on purpose — produces a new JA3 almost every connection and fragments into what looks like 15 unrelated clients. JA4 sorts those lists before hashing, which is why all of it lands here instead.
78ab0b1f2087b8b9fb559e92f14f94c0a76bdc3818cc66858db5ac1d431c92e1c9de3d7a7f73052c4fef231aa03e6d49ed9bc941e01cc3b67fac8758936adf9c76bc09ccf1eeb9ce480d84d522ed36800e5ce4a174274c88b4388fc2a24f66f89c35a9ed78de9c7101216b225ca4216927b4b2f0aa9aeef4daf82c96cc5cdea6a0cfaa5b41ebade4212c74ea09fd08c6a64c911df3c203b5f108aa98c9568bd0ee9acc9411518a5eff76da9e02fce51dd7acc681755c33d6630bac49cb84618e- … and 3 more
This entry is an observation, not a policy decision. It is here because the edge saw it, not because anyone reviewed it, and it blocks nothing on its own. Only the curated tier drives classification and banning.