tls-reputation.comTLS fingerprint reputation

unrecognised fingerprint

t13d2309h2_bc6434d430c8_79fd8a4b704b

Unclassified

Too few observations to classify this stack — a handful of connections can't tell a permuting client from coincidence.

TLS 1.3ALPN h2 · http/1.12026-07-22 → 2026-07-23
JA4
JA4_r
JA3
no single JA3 is stored for this fingerprint.
JA3_raw

explore in graph →

Read

catalog identity
No ground-truth build has reproduced this hello yet — absence is not a verdict.
self-randomisation
unclassified · 2 JA3 — only 8 observation(s) — too few to tell a permuting client from a coincidence.
reach
0.980 roams across 7 domains — spread is how evenly, not how many.

Spread measures reach, not intent: it can’t tell one scraper visiting 500 domains from 500 people visiting one each. Stability is a claim about software — whether the stack is deterministic — nothing about who runs it.

Footprint

8
observations
7
domains reached
2026-07-22
first seen
2026-07-23
last seen

ClientHello anatomy

The underscore groups of JA4_r are the raw cipher suites · extensions · signature algorithms behind the hash.

TLS version
TLS 1.3
ALPN (wire order)
h2, http/1.1
EC point formats
0x0000
Post-quantum key share
absent

The post-quantum key share is a structural fact about the hello, not a verdict — GREASE values are flagged the same neutral way.

cipher suites(23)
  1. 00x1301TLS_AES_128_GCM_SHA256
  2. 10x1302TLS_AES_256_GCM_SHA384
  3. 20x1303TLS_CHACHA20_POLY1305_SHA256
  4. 30x1304unknown (0x1304)
  5. 40x1305unknown (0x1305)
  6. 50xc02bTLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256
  7. 60xc02fTLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
  8. 70xc02cTLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384
  9. 80xc030TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
  10. 90xcca9TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305
  11. 100xcca8TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305
  12. 110xc009TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA
  13. 120xc013TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA
  14. 130xc00aTLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA
  15. 140xc014TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA
  16. 150x009eTLS_DHE_RSA_WITH_AES_128_GCM_SHA256
  17. 160x009fTLS_DHE_RSA_WITH_AES_256_GCM_SHA384
  18. 170x009cTLS_RSA_WITH_AES_128_GCM_SHA256
  19. 180x009dTLS_RSA_WITH_AES_256_GCM_SHA384
  20. 190x002fTLS_RSA_WITH_AES_128_CBC_SHA
  21. 200x0035TLS_RSA_WITH_AES_256_CBC_SHA
  22. 210x000aunknown (0x000a)
  23. 220x00ffTLS_EMPTY_RENEGOTIATION_INFO
extensions(9)sorted
  1. 00x0000server_name (SNI)
  2. 10x000asupported_groups
  3. 20x000bec_point_formats
  4. 30x000dsignature_algorithms
  5. 40x0010application_layer_protocol_negotiation (ALPN)
  6. 50x0017extended_master_secret
  7. 60x002bsupported_versions
  8. 70x002dpsk_key_exchange_modes
  9. 80x0033key_share

Stored sorted — under one JA4 the wire order varies by construction, so no single order is “the” order.

curves / groups(5)
  1. 00x001dx25519
  2. 10x0017secp256r1 (P-256)
  3. 20x0018secp384r1 (P-384)
  4. 30x0019secp521r1 (P-521)
  5. 40x0100ffdhe2048
signature algorithms(13)
  1. 00x0403ecdsa_secp256r1_sha256
  2. 10x0804rsa_pss_rsae_sha256
  3. 20x0809rsa_pss_pss_sha256
  4. 30x0401rsa_pkcs1_sha256
  5. 40x0503ecdsa_secp384r1_sha384
  6. 50x0805rsa_pss_rsae_sha384
  7. 60x080arsa_pss_pss_sha384
  8. 70x0501rsa_pkcs1_sha384
  9. 80x0603ecdsa_secp521r1_sha512
  10. 90x0806rsa_pss_rsae_sha512
  11. 100x080brsa_pss_pss_sha512
  12. 110x0601rsa_pkcs1_sha512
  13. 120x0201rsa_pkcs1_sha1

JA3 variants

2 distinct JA3 hashes collapse into this one JA4.

#JA3JA3_rawobsshare
0771,4865-4866-4867-486…256-4588,0675%
1771,4865-4866-4867-486…4-25-256,0225%

JA3 hashes preserve wire order, so a permuting client mints a new one per connection; JA4 sorts the same set, which is why they share one JA4. Every hash here belongs to this fingerprint — there is no per-JA3 page.

Reach — domains contacted

Top 7 of 7. Share is the fraction of this fingerprint’s observations reaching each name.