HoneyLabs

Akin HTTP request fingerprint

a11cun020_00000041_0a8d7f11

Seen 2026-09-22 to 2026-09-23 across the retained window.

6

Source IPs

3

Networks

2

Countries

3

Ports hit

6

Events

2

IPs / network

Top networks

Countries

HK 3US 3

Ports targeted

What it requests

GET/3

User agents claimed

NTRIP GNSSInternetRadio3 IPs3
Hello from Palo Alto Networks, find out more about our scans in https://docs-cortex.paloaltonetworks.com/r/1/Cortex-Xpanse/Scanning-activity3 IPs3
Source IPCCNetwork Last seenEvents
156.225.1.103HKAS9465 AGOTOZ PTE. LTD.2026-09-231
152.32.216.159HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-231
152.32.133.206HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-231
147.185.132.109USAS396982 Google LLC2026-09-221
198.235.24.69USAS396982 Google LLC2026-09-221
198.235.24.230USAS396982 Google LLC2026-09-221

Related fingerprints

No other fingerprint seen in the last 30 days is within two headers of this one.

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.