HoneyLabs

Akin HTTP request fingerprint

a11cun030_0000004a_c91eaf54

Seen 2026-09-22 to 2026-09-23 across the retained window.

58

Source IPs

20

Networks

21

Countries

34

Ports hit

165

Events

3

IPs / network

Top networks

Unattributed1 IPs2

Countries

DE 19SG 8US 8CN 3NL 3BR 2EC 1BA 1AE 1SE 1

Ports targeted

What it requests

GET/51

User agents claimed

Go-http-client/1.131 IPs104
Mozilla/5.02 IPs16
WanScannerBot/1.013 IPs16
Mozilla/5.0 (X11; Linux x86_64) HighPerfScanner/10G1 IPs7
proxy-prefilter/12 IPs5
Source IPCCNetwork Last seenEvents
137.184.74.141USAS14061 DigitalOcean, LLC2026-09-2317
162.243.166.118USAS14061 DigitalOcean, LLC2026-09-2315
94.154.43.7NLAS219502 Storm Industries LLC2026-09-2215
165.22.6.104USAS14061 DigitalOcean, LLC2026-09-2315
204.76.203.31NLAS51396 Pfcloud UG (haftungsbeschrankt)2026-09-237
165.245.220.93DEAS14061 DigitalOcean, LLC2026-09-236
164.92.247.156DEAS14061 DigitalOcean, LLC2026-09-234
77.91.71.90RUAS211486 Alferov Aleksey Aleksandrovich2026-09-234
164.92.207.74DEAS14061 DigitalOcean, LLC2026-09-234
45.198.224.188USAS215925 Vpsvault.host Ltd2026-09-233
165.245.242.232DEAS14061 DigitalOcean, LLC2026-09-233
159.223.26.113DEAS14061 DigitalOcean, LLC2026-09-233
161.35.72.179DEAS14061 DigitalOcean, LLC2026-09-233
201.79.6.182DEAS14061 DigitalOcean, LLC2026-09-233
209.38.204.16DEAS14061 DigitalOcean, LLC2026-09-233
177.188.141.75BRAS27699 TELEFONICA BRASIL S.A2026-09-233
201.79.0.176DEAS14061 DigitalOcean, LLC2026-09-232
209.38.206.89DEAS14061 DigitalOcean, LLC2026-09-232
46.101.193.182DEAS14061 DigitalOcean, LLC2026-09-232
147.90.171.26MOAS137409 GSL Networks Pty LTD2026-09-222

Fingerprint family: 2 shapes, 58 IPs, 175 events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 3 headers, no body: connection, host, user-agent

asks for/ · /solr/admin/cores?action=STATUS&wt=json · /cgi-bin/authLogin.cgi · /solr/admin/info/system (GET)
asGo-http-client/1.1 · WanScannerBot/1.0 · Mozilla/5.0 and 12 more
ports5060 · 27017 · 8087 · 9202
fromUS · DE · NL · SG · DigitalOcean, LLC · Storm Industries LLC · GSL Networks Pty LTD
a11cun030_0000004a_c91eaf54 this oneGo-http-client/1.1 · /58 IPs165a11cun040_0000004b_a4cdfabf+/- accept · Mozilla/5.0 (Windows NT 10.0; Win64; x64) · /2 IPs10

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

a10cun030_0000004a_c91eaf54same header set1 IPs1a11cun040_0000004e_608dab681 header apart449 IPs5.8Ka11cun020_00000048_724c10fb1 header apart96 IPs532a11cun040_0000004b_4c87b06e1 header apart113 IPs509a10cun020_0000000a_78f1f19c1 header apart100 IPs452a11cun040_0000004e_36fbce141 header apart307 IPs348a11cun040_0000004b_00b09b791 header apart1 IPs173a11cun031_00000048_e62b6d851 header apart2 IPs95

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.