HoneyLabs

Akin HTTP request fingerprint

a10cun020_0000000a_78f1f19c

Seen 2026-09-22 to 2026-09-24 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS45102 sends an email when it next hits a sensor.

173

Source IPs

19

Networks

10

Countries

501

Ports hit

618

Events

9

IPs / network

Top networks

Countries

SG 90US 61CN 12KR 3FR 2ES 1HK 1NL 1BR 1IR 1

Ports targeted

What it requests

GET/618
Source IPCCNetwork Last seenEvents
43.106.58.188SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-2317
47.85.104.213USAS45102 Alibaba (US) Technology Co., Ltd.2026-09-2314
43.106.48.6SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-2313
43.106.52.96SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-2311
43.106.58.146SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-2310
47.84.111.144SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-2310
43.98.200.1SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-2310
47.84.97.178SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-2310
43.106.56.76SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-2310
47.84.96.224SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-2310
43.98.176.103SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-239
43.98.166.144SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-239
43.106.52.37SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-239
43.106.53.188SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-239
47.236.224.95SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-239
47.236.38.116SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-238
47.84.97.110SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-238
43.106.54.116SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-238
43.106.60.112SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-237
47.84.112.13SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-237

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

a11cun020_0000000a_78f1f19csame header set7 IPs100a11cun020_0000000a_4e1a3733same header set1 IPs15a11cun010_00000008_c4b2c4aa1 header apart390 IPs4.1Ka11cun030_0000004a_c91eaf541 header apart110 IPs635a10cun010_00000008_c4b2c4aa1 header apart36 IPs233a11cun030_0000000e_21fe282e1 header apart4 IPs47a11cun030_0000000b_4c75231d1 header apart2 IPs3a10cun030_0000004a_c91eaf541 header apart3 IPs3

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.