HoneyLabs

Akin HTTP request fingerprint

a10cun050_0040004e_844abc4b

Seen 2026-09-23 to 2026-09-28 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS210006 sends an email when it next hits a sensor.

36

Source IPs

8

Networks

8

Countries

109

Ports hit

4.9K

Events

4

IPs / network

Top networks

Countries

TR 17DE 7SC 5KZ 2RU 2GB 1US 1IR 1

Ports targeted

What it requests

GET/1.4K
GET/RDWeb21

User agents claimed

Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.3636 IPs4.9K
Source IPCCNetwork Last seenEvents
138.226.239.79GBAS44589 Digital Network S.r.l.2026-09-28287
185.136.15.55KZAS210328 AO ALMAZ2026-09-28217
185.136.15.19KZAS210328 AO ALMAZ2026-09-28216
45.154.244.145SCAS210006 Shereverov Marat Ahmedovich2026-09-28208
178.20.210.194DEAS210006 Shereverov Marat Ahmedovich2026-09-28205
178.20.210.183DEAS210006 Shereverov Marat Ahmedovich2026-09-28204
46.29.26.138TRAS132359 M/S ROBI TRADERS2026-09-28202
193.32.204.146TRAS153622 Madina IT2026-09-28202
178.20.210.145DEAS210006 Shereverov Marat Ahmedovich2026-09-28198
193.187.110.132TRAS153947 FAST ZONE IT2026-09-28194
77.91.71.78RUAS211486 Alferov Aleksey Aleksandrovich2026-09-28187
46.29.26.171TRAS132359 M/S ROBI TRADERS2026-09-28182
46.29.26.150TRAS132359 M/S ROBI TRADERS2026-09-28161
193.32.204.131TRAS153622 Madina IT2026-09-28159
46.29.26.140TRAS132359 M/S ROBI TRADERS2026-09-28158
193.187.110.153TRAS153947 FAST ZONE IT2026-09-28153
193.187.110.147TRAS153947 FAST ZONE IT2026-09-28152
178.20.210.173DEAS210006 Shereverov Marat Ahmedovich2026-09-28132
45.154.244.174SCAS210006 Shereverov Marat Ahmedovich2026-09-28130
46.29.26.149TRAS132359 M/S ROBI TRADERS2026-09-28128

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

a11cun050_0040004e_80f24ccesame header set1 IPs10a11cun061_0040004e_be5a5cc7same header set1 IPs3a11cun050_0040004e_dae12bdfsame header set1 IPs2a11cuk061_0040004e_be5a5cc7same header set1 IPs2a11cun127_0040004e_ebc59d08same header set1 IPs1a11cun127_0040004e_16fd481bsame header set1 IPs1a11cun040_0000004e_608dab681 header apart759 IPs47.1Ka11cun040_0000004e_36fbce141 header apart1.8K IPs4.0K

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.