HoneyLabs

Akin HTTP request fingerprint

a11cun040_0000004d_aa48e2c8

Seen 2026-09-22 to 2026-09-23 across the retained window.

1.3K

Source IPs

37

Networks

21

Countries

1.6K

Ports hit

9.1K

Events

36

IPs / network

Top networks

Countries

US 1.1KPT 167DE 10CN 9NL 3CA 3AU 2FR 2JP 2MA 1

Ports targeted

What it requests

GET/4.1K
GET/login152
GET/ads.txt141
GET/wiki119

User agents claimed

Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)322 IPs4.2K
visionheight.com/scan Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) Chrome/126.0.0.0 Safari/537.364 IPs1.0K
Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.6312.86 Safari/537.36166 IPs569
Mozilla/5.0 (compatible; GenomeCrawlerd/1.0; +https://www.nokia.com/genomecrawler)19 IPs381
Mozilla/5.0 zgrab/0.x221 IPs298
Source IPCCNetwork Last seenEvents
18.218.118.203USAS16509 Amazon.com, Inc.2026-09-23400
18.116.101.220USAS16509 Amazon.com, Inc.2026-09-23360
3.129.187.38USAS16509 Amazon.com, Inc.2026-09-23234
167.94.146.60USAS398705 Censys, Inc.2026-09-23145
167.94.146.56USAS398705 Censys, Inc.2026-09-23140
167.94.146.62USAS398705 Censys, Inc.2026-09-23128
167.94.146.49USAS398705 Censys, Inc.2026-09-23126
167.94.146.58USAS398705 Censys, Inc.2026-09-23123
167.94.146.61USAS398705 Censys, Inc.2026-09-23123
167.94.146.51USAS398705 Censys, Inc.2026-09-23114
167.94.146.50USAS398705 Censys, Inc.2026-09-23105
167.94.146.59USAS398705 Censys, Inc.2026-09-23103
167.94.146.57USAS398705 Censys, Inc.2026-09-23102
167.94.146.55USAS398705 Censys, Inc.2026-09-2399
216.180.246.65USAS396982 Google LLC2026-09-2296
167.94.146.63USAS398705 Censys, Inc.2026-09-2394
167.94.146.53USAS398705 Censys, Inc.2026-09-2393
167.94.146.54USAS398705 Censys, Inc.2026-09-2391
167.94.146.48USAS398705 Censys, Inc.2026-09-2390
62.210.142.179FRAS12876 Scaleway SAS2026-09-2380

Fingerprint family: 2 shapes, 1.3K IPs, 9.0K events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

a11cun040_0000004d_aa48e2c8 this one1.3K IPs9.0Ka11cun040_0000004d_50f908882 IPs2

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

a11cun040_0000004d_4110f156same header set9 IPs3.0Ka11cun040_0000004d_c2bd490fsame header set28 IPs220a11cun040_0000004d_f36dd82esame header set6 IPs160a11cun040_0000004d_c5bb04c5same header set3 IPs70a11cun051_0000004d_a7cb51b4same header set1 IPs12a11cun051_0000004d_6289c865same header set5 IPs5a11cun062_0000004d_c61c0cf4same header set1 IPs4a11cun040_0000004d_1d05953dsame header set1 IPs2

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.