HoneyLabs

Akin HTTP request fingerprint

a11cun030_0000004c_f6d8d797

Seen 2026-09-24 to 2026-09-24 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS63949 sends an email when it next hits a sensor.

3

Source IPs

1

Networks

1

Countries

1

Ports hit

3

Events

3

IPs / network

Top networks

Countries

US 3

Ports targeted

What it requests

User agents claimed

Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.363 IPs3
Source IPCCNetwork Last seenEvents
172.104.17.51AS0 Akamai Connected Cloud2026-09-241
173.230.131.27AS0 Akamai Connected Cloud2026-09-241
45.79.192.162AS0 Akamai Connected Cloud2026-09-241

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

a11cun030_0000004c_13ee3d34same header set2.2K IPs10.3Ka11cun040_0000004d_aa48e2c81 header apart2.1K IPs36.9Ka11cun040_0000004e_608dab681 header apart525 IPs14.5Ka11cun040_0000004d_4110f1561 header apart13 IPs7.6Ka11cun040_0000004e_36fbce141 header apart738 IPs900a11cun020_00000048_724c10fb1 header apart173 IPs801a11cun040_0000004d_c2bd490f1 header apart33 IPs582a11cun062_0000004d_84d4cebf1 header apart2 IPs493

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.