t13d1012ht_61a7ad8aa9b6_b38bd6d0bc9a
Completed a TLS handshake but never an HTTP request, so no User-Agent was ever presented.
What this fingerprint encodes
t13d1012ht
handshake shape, human-readable
61a7ad8aa9b6
truncated hash of the cipher list
b38bd6d0bc9a
truncated hash of extensions + signature algorithms
- Transport
- TCP
- TLS version
- TLS 1.3
- Server name
- server name sent
- Cipher suites offered
- 10
- Extensions offered
- 12
- ALPN
- ht
The hello it was computed from
Recovered because the proxy now stores the pre-hash JA3 string alongside the digest. Every number below came out of this client's ClientHello; anything we cannot name in the IANA registry is shown as its raw value rather than guessed at.
- Version
- TLS 1.2
Cipher suites 10
-
TLS_AES_256_GCM_SHA384 -
TLS_AES_128_GCM_SHA256 -
TLS_CHACHA20_POLY1305_SHA256 -
TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 -
TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 -
TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256 -
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 -
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 -
TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 -
TLS_EMPTY_RENEGOTIATION_INFO_SCSV
Extensions 12
-
ec_point_formats -
supported_groups -
extended_master_secret -
psk_key_exchange_modes -
server_name -
session_ticket -
key_share -
application_layer_protocol_negotiation -
compress_certificate -
supported_versions -
signature_algorithms -
status_request
Named groups 3
-
x25519 -
secp256r1 -
secp384r1
Point formats 1
-
uncompressed
Raw JA3 string
771,4866-4865-4867-49196-49195-52393-49200-49199-52392-255,11-10-23-45-0-35-51-16-27-43-13-5,29-23-24,0
Seen in live traffic
- Connections
- 141
- First seen
- 2026-09-17 19:52 UTC
- Last seen
- 2026-09-19 00:12 UTC
- Transport
- TCP
- JA3 hashes absorbed
- 141
The same client, 141 different JA3s
This one JA4 covers 141 distinct JA3 hashes. A JA3 hashes the cipher and extension lists in the order they arrived, so a client that shuffles them — which Chrome and its derivatives do on purpose — produces a new JA3 almost every connection and fragments into what looks like 141 unrelated clients. JA4 sorts those lists before hashing, which is why all of it lands here instead.
1e06010c5624499f85bbf9e4b6b2da49985c77d63bd5f1080c465cb0a989862dab8251da63178b87a77af8f64ef217aede7ea55d95ec4a4bddb8bc061e0f26ee7e385732d8d1914a00be140f1a1e49c8555cc1d294fa5a170c5bb7c7ed2b24eeeed01c5e57c9bc44a02ca1992d094fd5b762f8db58dd9e8a123f16ead0231dd71834d249636abbe8245fc25cea0e903df285fac01ff7cfd25bf064b759fa92294097179df8105a317d28dd510b98aa3d222e99e3ded4ef4121ac088df422a93c- … and 129 more
This entry is an observation, not a policy decision. It is here because the edge saw it, not because anyone reviewed it, and it blocks nothing on its own. Only the curated tier drives classification and banning.