auth surface
auth.wb.ru
Credential-stuffing shape
Many unrelated client stacks reach this auth endpoint in near-equal proportion — the credential-stuffing shape. The corpus records no per-connection identity and cannot confirm intent.
- domain
Read
client diversity
8 distinct client stacks reach this name.
concentration
0.911 traffic splits near-evenly across many unrelated stacks.
category
Looks like an auth endpoint — a hostname heuristic, high-precision / low-recall, not a verdict.
synthesis
Many unrelated stacks reaching an auth endpoint in near-equal proportion is the credential-stuffing shape. The corpus records no per-connection identity and cannot confirm intent.
Spread is entropy over the fingerprints reaching this domain, not over the domains a fingerprint reaches. It can’t distinguish one scraper from many people — it measures the mix of software, not who runs it.
Footprint
20
observations
8
distinct clients
2026-07-23
first seen
2026-07-23
last seen
Client stacks reaching this name
- Google Chrome / Chromiummulti-build30%
- Android (Conscrypt) / Flutter (BoringSSL)randomising15%
- Google Chrome / Chromiummulti-build15%
- Android (Conscrypt) / Flutter (BoringSSL)randomising15%
- Apple Safari / WebKitmulti-build10%
- t13d1314h2_f57…8d8d241brandomising5.0%
- t12d0508h1_be4…66c06c35randomising5.0%
- Dart dart:io HttpClient (package:http / dio)multi-build5.0%
Busiest 8 client stacks on this page. Share is the fraction of this name’s observations. Many distinct fingerprints on a low-traffic name is itself worth a look; a blank JA3 is a permuting client — open the fingerprint for its variants.
| client | JA3 | stability | count | share | first seen | last seen |
|---|---|---|---|---|---|---|
| Google Chrome / Chromium Chromium cipher-suite signature — Chrome, Edge, Brave, Opera; any extension permutation or version | — | multi-build | 6 | 30% | 2026-07-23 | 2026-07-23 |
| Android (Conscrypt) / Flutter (BoringSSL) mobile-BoringSSL cipher-suite signature — Android system TLS (Play Services, Firebase, OkHttp apps) and Flutter/Dart; any ALPN | — | randomising | 3 | 15% | 2026-07-23 | 2026-07-23 |
| Google Chrome / Chromium Chromium cipher-suite signature — Chrome, Edge, Brave, Opera; any extension permutation or version | — | multi-build | 3 | 15% | 2026-07-23 | 2026-07-23 |
| Android (Conscrypt) / Flutter (BoringSSL) mobile-BoringSSL cipher-suite signature — Android system TLS (Play Services, Firebase, OkHttp apps) and Flutter/Dart; any ALPN | — | randomising | 3 | 15% | 2026-07-23 | 2026-07-23 |
| Apple Safari / WebKit Apple SecureTransport cipher-suite signature — Safari (macOS/iOS), WKWebView, and native URLSession apps; the 3DES legacy tail (0xC008/0xC012/0x000A) is Apple's tell, no other modern stack carries it. Platform entry like Android's Conscrypt: Apple system TLS legitimately offers any ALPN (h2, http/1.1, dot, none), so the cipher list alone is the signature — not ALPN-gated | — | multi-build | 2 | 10% | 2026-07-23 | 2026-07-23 |
| t13d1314h2_f57a4…8d8d241b | — | randomising | 1 | 5.0% | 2026-07-23 | 2026-07-23 |
| t12d0508h1_be416…66c06c35 | — | randomising | 1 | 5.0% | 2026-07-23 | 2026-07-23 |
| Dart dart:io HttpClient (package:http / dio) Dart 3.3, BoringSSL (bundled) — older cipher set; no ALPN | — | multi-build | 1 | 5.0% | 2026-07-23 | 2026-07-23 |