HoneyLabs

Akin HTTP request fingerprint

a11cun020_0000000c_5ff1c0a9

Seen 2026-09-22 to 2026-09-24 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS202412 sends an email when it next hits a sensor.

11

Source IPs

6

Networks

4

Countries

17

Ports hit

66

Events

2

IPs / network

This fingerprint is spread thinly across many networks, which is the shape of a common, widely-used client.

Top networks

Countries

NL 5US 4RU 1CN 1

Ports targeted

What it requests

GET/17
Source IPCCNetwork Last seenEvents
176.120.22.240RUAS198953 Proton66 OOO2026-09-2421
207.90.244.14USAS174 Cogent Communications, LLC2026-09-239
158.94.210.5NLAS202412 Omegatech LTD2026-09-247
178.16.53.3NLAS202412 Omegatech LTD2026-09-247
139.159.219.161CNAS55990 Huawei Cloud Service data center2026-09-244
80.82.77.33NLAS202425 IP Volume inc2026-09-233
94.154.35.25NLAS202412 Omegatech LTD2026-09-233
80.82.77.139NLAS202425 IP Volume inc2026-09-233
71.6.158.166USAS10439 CariNet, Inc.2026-09-223
66.240.192.138USAS10439 CariNet, Inc.2026-09-233
71.6.199.23USAS10439 CariNet, Inc.2026-09-223

Fingerprint family: 2 shapes, 11 IPs, 118 events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 2 headers, no body: accept-encoding, host

asks for/remote/login?lang=en · / · /.well-known/security.txt · /robots.txt (GET)
ports4443 · 80 · 6333 · 11434
fromNL · RU · US · CN · Proton66 OOO · Omegatech LTD · Cogent Communications, LLC
a11cun020_0000000c_5ff1c0a9 this one/remote/login?lang=en11 IPs66a11cun030_0000000e_21fe282e+/- connection · /4 IPs52

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

a11cun030_0000004c_13ee3d341 header apart2.2K IPs11.3Ka11cun010_00000008_c4b2c4aa1 header apart400 IPs4.5Ka10cun010_00000008_c4b2c4aa1 header apart36 IPs282a11cun030_0000000e_21fe282e1 header apart4 IPs52a11cun030_0000004c_f6d8d7971 header apart4 IPs4a11cun030_0000000d_6396c54d1 header apart1 IPs1a11cun030_0000000e_57ba74d41 header apart1 IPs1a11cun107_0000000e_9784fa1b1 header apart1 IPs1

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.