HoneyLabs

Akin HTTP request fingerprint

a11cun040_0000004d_4110f156

Seen 2026-09-22 to 2026-09-24 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS202425 sends an email when it next hits a sensor.

13

Source IPs

7

Networks

4

Countries

213

Ports hit

7.2K

Events

2

IPs / network

This fingerprint is spread thinly across many networks, which is the shape of a common, widely-used client.

Top networks

Countries

NL 4US 4JP 4FR 1

Ports targeted

What it requests

GET/7.2K
GET/.env2

User agents claimed

Python/3.10 aiohttp/3.8.44 IPs7.2K
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.361 IPs21
Mozilla/5.01 IPs4
Python/3.11 aiohttp/3.8.41 IPs4
Docker-Client/24.0.7 (linux)1 IPs3
Source IPCCNetwork Last seenEvents
89.248.171.24AS0 IP Volume inc2026-09-243.5K
93.174.93.12AS0 IP Volume inc2026-09-243.3K
80.82.77.202AS0 IP Volume inc2026-09-22330
89.248.172.33AS0 IP Volume inc2026-09-2223
198.144.189.91AS0 HostPapa2026-09-2321
81.161.239.10AS0 GravHosting LLC2026-09-224
34.123.115.73AS0 Google LLC2026-09-234
107.167.18.99AS0 Sharktech2026-09-233
8.209.206.203AS0 Alibaba (US) Technology Co., Ltd.2026-09-232
178.238.224.34AS0 Contabo GmbH2026-09-241
47.74.9.19AS0 Alibaba (US) Technology Co., Ltd.2026-09-231
47.91.14.43AS0 Alibaba (US) Technology Co., Ltd.2026-09-241
8.211.145.158AS0 Alibaba (US) Technology Co., Ltd.2026-09-231

Fingerprint family: 2 shapes, 13 IPs, 7.1K events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 4 headers, no body: accept, accept-encoding, host, user-agent

asks for/ · /favicon.ico · /version · /server/.env (GET)
asPython/3.10 aiohttp/3.8.4 · Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) · Python/3.11 aiohttp/3.8.4 and 13 more
ports2087 · 11211 · 4786 · 300
fromNL · US · JP · FR · IP Volume inc · HostPapa · Alibaba (US) Technology Co., Ltd.
a11cun040_0000004d_4110f156 this onePython/3.10 aiohttp/3.8.4 · /13 IPs7.1Ka11cun050_0000005d_fecf3944+/- accept-language · Mozilla/5.0 (Windows NT 6.1; WOW64; rv:53.0) Gecko/20100101 Firefox/53.0 · /4 IPs5

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

a11cun040_0000004d_aa48e2c8same header set2.1K IPs36.4Ka11cun040_0000004d_c2bd490fsame header set33 IPs572a11cun062_0000004d_84d4cebfsame header set2 IPs493a11cun040_0000004d_50f90888same header set6 IPs452a11cun040_0000004d_f36dd82esame header set8 IPs355a11cun040_0000004d_c5bb04c5same header set12 IPs313a11cun051_0000004d_a7cb51b4same header set1 IPs12a11cun062_0000004d_9898e8b5same header set5 IPs9

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.