tls-reputation.comTLS fingerprint reputation

unrecognised fingerprint

t13d2913h1_723694b0fccc_5671b5df5029

Randomising client

Reshuffles its own ClientHello per connection — browser-shaped behaviour, but no catalogue build has reproduced this exact hello.

TLS 1.3ALPN http/1.1 · http/1.02026-07-19 → 2026-07-22
JA4
JA4_r
JA3
permutes its ClientHello, so every connection emits a fresh JA3 — none represents it.
JA3_raw

explore in graph →

Read

catalog identity
No ground-truth build has reproduced this hello yet — absence is not a verdict.
self-randomisation
randomising · 128+ JA3 — 99% of connections presented a JA3 never seen before for this client — it reshuffles its own ClientHello. Chrome has permuted extension order since version 110.
real-browser tell
Browser-shaped cipher list but no post-quantum key share — the tell that separates curl-impersonate / uTLS from a real Chrome.
reach
0.756 roams across 23 domains — spread is how evenly, not how many.

Spread measures reach, not intent: it can’t tell one scraper visiting 500 domains from 500 people visiting one each. Stability is a claim about software — whether the stack is deterministic — nothing about who runs it.

Footprint

137
observations
23
domains reached
2026-07-19
first seen
2026-07-22
last seen

ClientHello anatomy

The underscore groups of JA4_r are the raw cipher suites · extensions · signature algorithms behind the hash.

TLS version
TLS 1.3
ALPN (wire order)
http/1.1, http/1.0
EC point formats
0x0000
Post-quantum key share
absent

The post-quantum key share is a structural fact about the hello, not a verdict — GREASE values are flagged the same neutral way.

cipher suites(29)
  1. 00x1302TLS_AES_256_GCM_SHA384
  2. 10x1303TLS_CHACHA20_POLY1305_SHA256
  3. 20x1301TLS_AES_128_GCM_SHA256
  4. 30x1304unknown (0x1304)
  5. 40xc02cTLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384
  6. 50xcca9TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305
  7. 60xc0adTLS_ECDHE_ECDSA_WITH_AES_256_CCM
  8. 70xc00aTLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA
  9. 80xc02bTLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256
  10. 90xc0acTLS_ECDHE_ECDSA_WITH_AES_128_CCM
  11. 100xc009TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA
  12. 110xc030TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384
  13. 120xcca8TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305
  14. 130xc014TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA
  15. 140xc02fTLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256
  16. 150xc013TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA
  17. 160x009dTLS_RSA_WITH_AES_256_GCM_SHA384
  18. 170xc09dTLS_RSA_WITH_AES_256_CCM
  19. 180x0035TLS_RSA_WITH_AES_256_CBC_SHA
  20. 190x009cTLS_RSA_WITH_AES_128_GCM_SHA256
  21. 200xc09cTLS_RSA_WITH_AES_128_CCM
  22. 210x002fTLS_RSA_WITH_AES_128_CBC_SHA
  23. 220x009fTLS_DHE_RSA_WITH_AES_256_GCM_SHA384
  24. 230xccaaTLS_DHE_RSA_WITH_CHACHA20_POLY1305
  25. 240xc09fTLS_DHE_RSA_WITH_AES_256_CCM
  26. 250x0039TLS_DHE_RSA_WITH_AES_256_CBC_SHA
  27. 260x009eTLS_DHE_RSA_WITH_AES_128_GCM_SHA256
  28. 270xc09eTLS_DHE_RSA_WITH_AES_128_CCM
  29. 280x0033TLS_DHE_RSA_WITH_AES_128_CBC_SHA
extensions(13)sorted
  1. 00x0000server_name (SNI)
  2. 10x0005status_request (OCSP)
  3. 20x000asupported_groups
  4. 30x000bec_point_formats
  5. 40x000dsignature_algorithms
  6. 50x0010application_layer_protocol_negotiation (ALPN)
  7. 60x0015padding
  8. 70x001crecord_size_limit
  9. 80x0023session_ticket
  10. 90x002bsupported_versions
  11. 100x002dpsk_key_exchange_modes
  12. 110x0033key_share
  13. 120xff01renegotiation_info

Stored sorted — under one JA4 the wire order varies by construction, so no single order is “the” order.

curves / groups(10)
  1. 00x0017secp256r1 (P-256)
  2. 10x0018secp384r1 (P-384)
  3. 20x0019secp521r1 (P-521)
  4. 30x001dx25519
  5. 40x001ex448
  6. 50x0100ffdhe2048
  7. 60x0101ffdhe3072
  8. 70x0102ffdhe4096
  9. 80x0103ffdhe6144
  10. 90x0104ffdhe8192
signature algorithms(16)
  1. 00x0401rsa_pkcs1_sha256
  2. 10x0809rsa_pss_pss_sha256
  3. 20x0804rsa_pss_rsae_sha256
  4. 30x0403ecdsa_secp256r1_sha256
  5. 40x0807ed25519
  6. 50x0501rsa_pkcs1_sha384
  7. 60x080arsa_pss_pss_sha384
  8. 70x0805rsa_pss_rsae_sha384
  9. 80x0503ecdsa_secp384r1_sha384
  10. 90x0808ed448
  11. 100x0601rsa_pkcs1_sha512
  12. 110x080brsa_pss_pss_sha512
  13. 120x0806rsa_pss_rsae_sha512
  14. 130x0603ecdsa_secp521r1_sha512
  15. 140x0201rsa_pkcs1_sha1
  16. 150x0203ecdsa_sha1

JA3 variants

128+ distinct JA3 hashes collapse into this one JA4.

#JA3JA3_rawobsshare
0771,4866-4867-4865-486…-259-260,021.5%
1771,4866-4867-4865-486…-259-260,010.7%
2771,4866-4867-4865-486…-259-260,010.7%
3771,4866-4867-4865-486…-259-260,010.7%
4771,4866-4867-4865-486…-259-260,010.7%
5771,4866-4867-4865-486…-259-260,010.7%
6771,4866-4867-4865-486…-259-260,010.7%
7771,4866-4867-4865-486…-259-260,010.7%
8771,4866-4867-4865-486…-259-260,010.7%
9771,4866-4867-4865-486…-259-260,010.7%
10771,4866-4867-4865-486…-259-260,010.7%
11771,4866-4867-4865-486…-259-260,010.7%
12771,4866-4867-4865-486…-259-260,010.7%
13771,4866-4867-4865-486…-259-260,010.7%
14771,4866-4867-4865-486…-259-260,010.7%
15771,4866-4867-4865-486…-259-260,010.7%
16771,4866-4867-4865-486…-259-260,010.7%
17771,4866-4867-4865-486…-259-260,010.7%
18771,4866-4867-4865-486…-259-260,010.7%
19771,4866-4867-4865-486…-259-260,010.7%

JA3 hashes preserve wire order, so a permuting client mints a new one per connection; JA4 sorts the same set, which is why they share one JA4. Every hash here belongs to this fingerprint — there is no per-JA3 page. Showing the busiest 20.

Reach — domains contacted

Top 15 of 23. Share is the fraction of this fingerprint’s observations reaching each name.