Traffic Fingerprint Analysis

🤔
Uncertain
2 anomalies detected • Record #873
40%

Connection Info

IP Address 216.73.216.138
Country US
City Columbus
Coordinates 39.9612, -82.9988

TCP/IP Fingerprint

OS Guess Chromium OS
Confidence 59%
TTL 110
Window Size 62727
MSS 1460
Window Scaling 7
TCP Options MSTNW

Latency Analysis (JA4L)

Round Trip Time 110.52 ms
JA4L_a (one-way) 55,260 µs
TTL / Hop Count 110 / 18 hops
Propagation Factor ×1.7
Estimated Distance 6,696 km
Expected (GeoIP) 6,829 km
Distance Ratio 0.98x

HTTP Fingerprint

JA4H geth210_65330eb47d01_27ac6ee77f0b
User Agent Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.c
Accept-Language N/A
Accept-Encoding gzip, br, zstd, deflate

TLS Fingerprint

JA4 t12d1211_9ed2ebe69434_907de04407fa

Proxy Detection

Status ✓ Direct Connection
Proxy Score 0%
RTT Variance Ratio 0.113
Connection Reuse Yes (#2)

Detection Flags

  • header_anomaly low
    Missing ACCEPT-LANGUAGE header for browser User-Agent
  • ttl_anomaly medium
    TTL 110 higher than expected 64 for - possible TTL manipulation

HTTP Header Order

1. ACCEPT-ENCODING
2. USER-AGENT
3. ACCEPT
4. HOST
5. X-FORWARDED-FOR
6. X-REAL-IP
7. X-CONNECTION-REQUESTS
8. X-REQUEST-START
9. X-TCP-RTTVAR
10. X-TCP-RTT

Raw Data

View as JSON

{ "avg_score_os_class": { "Android": 8.98, "Chromium OS": 12.14, "Linux": 7.08, "Mac OS": 1.55, "Windows": 3.86, "iOS": 0.81 }, "details": { "client_ip": "::ffff:172.18.0.5", "highest_os_avg": 12.14, "lookup_ip": "216.73.216.138", "num_fingerprints": 1, "os_highest_class": "Chromium OS", "os_mismatch": null, "perfect_score": 20.5 }, "fp": { "cap_len": 74, "dst_ip": "134.209.234.103", "dst_port": 443, "header_len": 74, "ip_checksum": 29615, "ip_df": 1, "ip_hdr_length": 5, "ip_id": 30423, "ip_mf": 0, "ip_nxt": null, "ip_off": 16384, "ip_plen": null, "ip_protocol": 6, "ip_rf": 0, "ip_tos": 40, "ip_total_length": 60, "ip_ttl": 110, "ip_version": 4, "src_ip": "216.73.216.138", "src_port": 19805, "tcp_ack": 0, "tcp_checksum": 64488, "tcp_flags": 2, "tcp_header_length": 20, "tcp_mss": 1460, "tcp_off": 10, "tcp_options": "M1460,S,T,N,W7,", "tcp_options_ordered": "MSTNW", "tcp_seq": 3937456604, "tcp_timestamp": 1166795728, "tcp_timestamp_echo_reply": 0, "tcp_urp": 0, "tcp_window_scaling": 7, "tcp_window_size": 62727, "ts": [ 1766078133, 5577 ] } }