HoneyLabs

Akin HTTP request fingerprint

a11cun020_00000048_724c10fb

Seen 2026-09-22 to 2026-09-23 across the retained window.

83

Source IPs

12

Networks

8

Countries

136

Ports hit

473

Events

7

IPs / network

Top networks

Countries

US 70NL 4DE 3RU 2GB 1MX 1PL 1SG 1

Ports targeted

What it requests

GET/136
HEAD/_ping2

User agents claimed

what-vpn-go/0.12 IPs340
fasthttp6 IPs37
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.361 IPs5
Hello from Palo Alto Networks, find out more about our scans in https://docs-cortex.paloaltonetworks.com/r/1/Cortex-Xpanse/Scanning-activity5 IPs5
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36 Edg/123.0.0.04 IPs4
Source IPCCNetwork Last seenEvents
94.26.83.79DEAS207043 Dedik Services Limited2026-09-23176
91.92.43.222DEAS207043 Dedik Services Limited2026-09-23164
45.91.64.6RUAS214664 JSC F62026-09-2318
89.248.171.24NLAS202425 IP Volume inc2026-09-239
23.95.132.49USAS36352 HostPapa2026-09-235
2.59.163.159PLAS215540 Global Connectivity Solutions Llp2026-09-224
86.54.31.32GBAS12989 Black HOST Ltd2026-09-234
45.91.64.10RUAS214664 JSC F62026-09-234
80.82.77.202NLAS202425 IP Volume inc2026-09-233
65.49.20.67USAS6939 Hurricane Electric LLC2026-09-233
65.49.20.68USAS6939 Hurricane Electric LLC2026-09-232
74.82.47.3USAS6939 Hurricane Electric LLC2026-09-232
148.216.108.65MXAS11172 Alestra, S. de R.L. de C.V.2026-09-222
216.218.206.66USAS6939 Hurricane Electric LLC2026-09-232
89.248.172.33NLAS202425 IP Volume inc2026-09-232
65.49.20.66USAS6939 Hurricane Electric LLC2026-09-232
184.105.139.69USAS6939 Hurricane Electric LLC2026-09-232
184.105.139.70USAS6939 Hurricane Electric LLC2026-09-232
64.62.156.72USAS6939 Hurricane Electric LLC2026-09-232
184.105.247.195USAS6939 Hurricane Electric LLC2026-09-232

Fingerprint family: 4 shapes, 83 IPs, 728 events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

a11cun020_00000048_724c10fb this one83 IPs472a11cuq030_00000248_e62b6d853 IPs86a11cun031_00000048_e62b6d852 IPs85a11cun064_00000048_f2f3ae252 IPs85

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

a11cun064_00000048_f2f3ae25same header set2 IPs85a11cun031_00000048_e62b6d85same header set2 IPs85a10cun020_00000048_724c10fbsame header set2 IPs16a11cun030_00000049_03330a181 header apart2 IPs14.6Ka11cun030_0000004c_13ee3d341 header apart1.7K IPs4.0Ka11cun010_00000008_c4b2c4aa1 header apart324 IPs1.4Ka11cun030_00000049_54d07b6d1 header apart564 IPs1.1Ka11cun030_0000004a_c91eaf541 header apart56 IPs150

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.