HoneyLabs

Akin HTTP request fingerprint

a11cuk105_0000044d_5ccac048

Seen 2026-09-23 to 2026-09-23 across the retained window.

2

Source IPs

1

Networks

1

Countries

2

Ports hit

2

Events

2

IPs / network

Top networks

Countries

US 2

Ports targeted

What it requests

POST/2

User agents claimed

Mozilla/5.0 (X11; Linux x86_64; rv:143.0) Gecko/20100101 Firefox/143.01 IPs1
Mozilla/5.0 (Windows NT 10.0; rv:110.0) Gecko/20100101 Firefox/110.01 IPs1
Source IPCCNetwork Last seenEvents
65.49.1.94AS0 Hurricane Electric LLC2026-09-231
64.62.156.94AS0 Hurricane Electric LLC2026-09-231

Fingerprint family: 4 shapes, 1.5K IPs, 15.5K events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 4 headers, no body: accept, accept-encoding, host, user-agent

asks for/ · /favicon.ico · /ai/site-profile.json · /sitemap.xml (GET / POST)
asMozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/) · Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/14 · visionheight.com/scan Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) Chrome/126 and 211 more
ports80 · 443 · 8080 · 8081
fromUS · CA · PT · FR · Censys, Inc. · Modat B.V. · Hurricane Electric LLC
a11cun040_0000004d_aa48e2c8Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/) · /1.5K IPs15.5Ka11cun030_00000045_6396c54d+/- host · NTRIP · /4 IPs4a11cun040_0000004d_50f90888Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) · /3 IPs3a11cuk105_0000044d_5ccac048 this one+/- content-type · Mozilla/5.0 (Windows NT 10.0; rv:110.0) Gecko/20100101 Firefox/110.0 · /2 IPs2

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

a11cun050_0000044d_a7cb51b4same header set1 IPs2a11cun040_0000004d_aa48e2c81 header apart1.5K IPs15.6Ka11cun040_0000004d_4110f1561 header apart10 IPs3.7Ka11cun040_0000004d_c2bd490f1 header apart32 IPs296a11cun040_0000004d_f36dd82e1 header apart6 IPs175a11cun040_0000004d_c5bb04c51 header apart4 IPs97a11cun051_0000004d_a7cb51b41 header apart1 IPs12a11cuq060_0000064d_84d4cebf1 header apart11 IPs11

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.