HoneyLabs

Akin HTTP request fingerprint

a10cun010_00000008_c4b2c4aa

Seen 2026-09-23 to 2026-09-23 across the retained window.

18

Source IPs

4

Networks

3

Countries

21

Ports hit

31

Events

4

IPs / network

Top networks

Countries

SG 15US 2BG 1

Ports targeted

What it requests

GET/31
Source IPCCNetwork Last seenEvents
195.178.110.204BGAS48090 Techoff Srv Limited2026-09-2312
43.98.168.156SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-232
43.106.52.37SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-232
43.106.55.86SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-231
43.106.52.96SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-231
199.45.155.30USAS398722 Censys, Inc.2026-09-231
43.106.56.236SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-231
43.106.53.84SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-231
43.106.49.28SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-231
47.84.97.110SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-231
47.236.189.186SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-231
43.106.48.162SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-231
43.98.192.248SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-231
47.84.98.202SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-231
43.98.200.1SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-231
43.106.53.135SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-231
43.106.57.45SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-231
66.132.186.193USAS398324 Censys, Inc.2026-09-231

Fingerprint family: 2 shapes, 100 IPs, 483 events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.0, 2 headers, no body: connection, host

asks for/ (GET)
ports8000 · 4000 · 9090 · 11434
fromSG · CN · US · ES · Alibaba (US) Technology Co., Ltd. · Chinanet · Performive LLC
a10cun020_0000000a_78f1f19c/100 IPs452a10cun010_00000008_c4b2c4aa this one+/- connection · /18 IPs31

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

a11cun010_00000008_c4b2c4aasame header set332 IPs1.5Ka11cun020_00000048_724c10fb1 header apart96 IPs532a10lun000_00000000_334359b91 header apart126 IPs512a10cun020_0000000a_78f1f19c1 header apart100 IPs452a11cun020_00000009_0a8d7f111 header apart155 IPs217a11cun064_00000048_f2f3ae251 header apart2 IPs95a11cun031_00000048_e62b6d851 header apart2 IPs95a11cun020_0000000a_78f1f19c1 header apart4 IPs33

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.