t13d1516h1_8daaf6152771_038aa86713e7
Chrome — inferred from the User-Agent on its requests.
What this fingerprint encodes
t13d1516h1
handshake shape, human-readable
8daaf6152771
truncated hash of the cipher list
038aa86713e7
truncated hash of extensions + signature algorithms
- Transport
- TCP
- TLS version
- TLS 1.3
- Server name
- server name sent
- Cipher suites offered
- 15
- Extensions offered
- 16
- ALPN
- h1
The hello it was computed from
Recovered because the proxy now stores the pre-hash JA3 string alongside the digest. Every number below came out of this client's ClientHello; anything we cannot name in the IANA registry is shown as its raw value rather than guessed at.
- Version
- TLS 1.2
Cipher suites 15
-
TLS_AES_128_GCM_SHA256 -
TLS_AES_256_GCM_SHA384 -
TLS_CHACHA20_POLY1305_SHA256 -
TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256 -
TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 -
TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 -
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 -
TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256 -
TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256 -
TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA -
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA -
TLS_RSA_WITH_AES_128_GCM_SHA256 -
TLS_RSA_WITH_AES_256_GCM_SHA384 -
TLS_RSA_WITH_AES_128_CBC_SHA -
TLS_RSA_WITH_AES_256_CBC_SHA
Extensions 16
-
psk_key_exchange_modes -
signature_algorithms -
extended_master_secret -
encrypted_client_hello -
supported_groups -
server_name -
supported_versions -
compress_certificate -
51764 (0xca34) -
signed_certificate_timestamp -
session_ticket -
ec_point_formats -
application_layer_protocol_negotiation -
renegotiation_info -
status_request -
key_share
Named groups 4
-
SecP256r1MLKEM768 -
x25519 -
secp256r1 -
secp384r1
Point formats 1
-
uncompressed
Raw JA3 string
771,4865-4866-4867-49195-49199-49196-49200-52393-52392-49171-49172-156-157-47-53,45-13-23-65037-10-0-43-27-51764-18-35-11-16-65281-5-51,4588-29-23-24,0
Seen in live traffic
- Connections
- 15
- First seen
- 2026-10-06 23:41 UTC
- Last seen
- 2026-10-06 23:56 UTC
- Transport
- TCP
- JA3 hashes absorbed
- 15
The same client, 15 different JA3s
This one JA4 covers 15 distinct JA3 hashes. A JA3 hashes the cipher and extension lists in the order they arrived, so a client that shuffles them — which Chrome and its derivatives do on purpose — produces a new JA3 almost every connection and fragments into what looks like 15 unrelated clients. JA4 sorts those lists before hashing, which is why all of it lands here instead.
48a37905be20b45ff3455d562629eb010eb07294425ab9335b4507693425f433f60262e76f7b2f6d9a6c138aca58ba8aad13343afd3ee6ab2e7da50a04a99d0d089347c45af8d0720fff2626233dfa6c2e8a8f982b87ffbb888d31e971bb848d30919058660240481e30b28f7d85d815b5ebd05e45380629cf5c40234f668795cc18da8a7b8fde58e9b20db6e03e128359a74e49dd0f9db65c8d785c6465320244c524905575f329d6ae939e72605478a15c3873f64a960c645ee20753d8d0d5- … and 3 more
User-Agents seen on this fingerprint
Mozilla/5.0 (Linux; Android 11; CPH2065; Build/RQ2A.200114.34) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.362×Mozilla/5.0 (Linux; Android 11; 12T; Build/RD2A.200221.192) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.362×Mozilla/5.0 (Linux; Android 10; 14 Ultra; Build/QQ1B.200910.48) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.362×Mozilla/5.0 (Linux; Android 14; Pixel 4 XL; Build/UD2A.230413.239) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.361×Mozilla/5.0 (Linux; Android 10; Pixel 8a; Build/QQ1C.201007.248) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.361×Mozilla/5.0 (Linux; Android 13; 13 Pro; Build/TQ2A.221201.78) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.361×Mozilla/5.0 (Linux; Android 10; Pixel 7 Pro; Build/QQ1B.201125.178) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.361×Mozilla/5.0 (Linux; Android 14; Pixel 9; Build/UQ1A.230702.231) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.361×Mozilla/5.0 (Linux; Android 12; Pixel 7 Pro; Build/SD2A.211024.130) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.361×Mozilla/5.0 (Linux; Android 14; SM-G986B; Build/AP2A.241211.128) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.361×Mozilla/5.0 (Linux; Android 11; Pixel 7 Pro; Build/RQ3A.200808.123) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.361×Mozilla/5.0 (Linux; Android 13; SM-G975U; Build/TQ2B.220605.81) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.361×
A User-Agent is self-declared and trivially forged, so this names an observation rather than proving an identity. It is still the strongest signal available: the fingerprint comes off the TLS handshake and the User-Agent off the request that followed, and one client build keeping a stable JA4 while changing what it calls itself is a finding in its own right.
This entry is an observation, not a policy decision. It is here because the edge saw it, not because anyone reviewed it, and it blocks nothing on its own. Only the curated tier drives classification and banning.