HoneyLabs

Akin HTTP request fingerprint

a11cun040_0000004b_4c87b06e

Seen 2026-09-22 to 2026-09-23 across the retained window.

113

Source IPs

6

Networks

6

Countries

439

Ports hit

493

Events

19

IPs / network

Top networks

Countries

US 103GB 4DE 3NO 1NL 1PH 1

Ports targeted

What it requests

GET/317
GET/Dr0v1

User agents claimed

curl/7.61.1102 IPs380
Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:146.0) Gecko/20100101 Firefox/146.01 IPs91
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.361 IPs13
Mozilla/5.0 (compatible; Infrawatch/1.0; +https://infrawat.ch/)7 IPs7
-1 IPs1
Source IPCCNetwork Last seenEvents
192.161.49.2USAS23273 HostPapa2026-09-2391
185.19.40.147NLAS210558 1337 Services GmbH2026-09-2313
104.152.52.123USAS14987 Rethem Hosting LLC2026-09-238
104.152.52.116USAS14987 Rethem Hosting LLC2026-09-238
104.152.52.128USAS14987 Rethem Hosting LLC2026-09-238
104.152.52.148USAS14987 Rethem Hosting LLC2026-09-238
104.152.52.244USAS14987 Rethem Hosting LLC2026-09-237
104.152.52.146USAS14987 Rethem Hosting LLC2026-09-237
104.152.52.132USAS14987 Rethem Hosting LLC2026-09-237
104.152.52.130USAS14987 Rethem Hosting LLC2026-09-237
104.152.52.122USAS14987 Rethem Hosting LLC2026-09-237
104.152.52.222USAS14987 Rethem Hosting LLC2026-09-237
104.152.52.243USAS14987 Rethem Hosting LLC2026-09-237
104.152.52.107USAS14987 Rethem Hosting LLC2026-09-237
104.152.52.200USAS14987 Rethem Hosting LLC2026-09-236
104.152.52.125USAS14987 Rethem Hosting LLC2026-09-236
104.152.52.227USAS14987 Rethem Hosting LLC2026-09-236
104.152.52.103USAS14987 Rethem Hosting LLC2026-09-236
104.152.52.233USAS14987 Rethem Hosting LLC2026-09-236
104.152.52.101USAS14987 Rethem Hosting LLC2026-09-236

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

a11cun040_0000004b_00b09b79same header set1 IPs163a11cun040_0000004b_ba182931same header set3 IPs24a10cun040_0000004b_4c87b06esame header set1 IPs13a11cun040_0000004b_a4cdfabfsame header set2 IPs10a11cun040_0000004b_469eb43fsame header set1 IPs1a11cun051_0000004b_df66fe0fsame header set1 IPs1a11cun030_00000049_03330a181 header apart2 IPs14.6Ka11cun050_0000005b_09001b3e1 header apart963 IPs4.4K

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.