HoneyLabs

Akin HTTP request fingerprint

a11cun040_0000004d_fb523147

Seen 2026-09-25 to 2026-09-26 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS31898 sends an email when it next hits a sensor.

22

Source IPs

1

Networks

1

Countries

6

Ports hit

1.2K

Events

22

IPs / network

This fingerprint is concentrated: many addresses on very few networks, which is what a single coordinated operation tends to look like.

Top networks

Countries

SG 22

Ports targeted

What it requests

GET/api/24
GET/24
GET/debug24
GET/.env24
GET/.npmrc24
GET/docs24
GET/env.js24

User agents claimed

Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.3622 IPs1.2K
Source IPCCNetwork Last seenEvents
161.118.232.83SGAS31898 Oracle Corporation2026-09-26102
161.118.205.249SGAS31898 Oracle Corporation2026-09-26102
140.245.122.65SGAS31898 Oracle Corporation2026-09-2651
161.118.214.196SGAS31898 Oracle Corporation2026-09-2551
161.118.241.225SGAS31898 Oracle Corporation2026-09-2651
140.245.117.201SGAS31898 Oracle Corporation2026-09-2651
140.245.110.72SGAS31898 Oracle Corporation2026-09-2651
140.245.108.34SGAS31898 Oracle Corporation2026-09-2651
138.2.77.205SGAS31898 Oracle Corporation2026-09-2551
140.245.117.121SGAS31898 Oracle Corporation2026-09-2551
168.107.72.188SGAS31898 Oracle Corporation2026-09-2651
161.118.243.214SGAS31898 Oracle Corporation2026-09-2651
213.35.99.240SGAS31898 Oracle Corporation2026-09-2651
140.245.107.4SGAS31898 Oracle Corporation2026-09-2651
134.185.86.28SGAS31898 Oracle Corporation2026-09-2651
161.118.218.217SGAS31898 Oracle Corporation2026-09-2551
168.138.173.95SGAS31898 Oracle Corporation2026-09-2651
158.178.234.142SGAS31898 Oracle Corporation2026-09-2651
161.118.211.34SGAS31898 Oracle Corporation2026-09-2551
161.118.222.26SGAS31898 Oracle Corporation2026-09-2651

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

a11cun040_0000004d_aa48e2c8same header set3.3K IPs139.1Ka11cun040_0000004d_4110f156same header set38 IPs21.5Ka11cun040_0000004d_c2bd490fsame header set38 IPs1.9Ka11cun040_0000004d_f36dd82esame header set9 IPs1.3Ka11cun040_0000004d_c5bb04c5same header set30 IPs1.1Ka11cun062_0000004d_84d4cebfsame header set2 IPs802a11cun040_0000004d_50f90888same header set26 IPs790a11cun051_0000004d_a7cb51b4same header set1 IPs56

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.