HoneyLabs

Akin HTTP request fingerprint

a11cun040_20000448_a31e7c35

Seen 2026-09-22 to 2026-09-23 across the retained window.

2

Source IPs

1

Networks

1

Countries

111

Ports hit

117

Events

2

IPs / network

Top networks

Countries

DE 2

Ports targeted

What it requests

GET/117

User agents claimed

what-vpn-go/0.12 IPs117
Source IPCCNetwork Last seenEvents
94.26.83.79AS0 Dedik Services Limited2026-09-2362
91.92.43.222AS0 Dedik Services Limited2026-09-2355

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

a11cun020_00000048_724c10fb2 headers apart105 IPs660a11cuq062_00000648_f2f3ae252 headers apart2 IPs118a11cun031_00000048_e62b6d852 headers apart2 IPs117a11cun064_00000048_f2f3ae252 headers apart2 IPs116a11cun040_0000044a_bf8a4cbb2 headers apart3 IPs24a10cun020_00000048_724c10fb2 headers apart2 IPs16a11cun031_00000440_e62b6d852 headers apart1 IPs11a11cuq051_00000648_800b45672 headers apart2 IPs2

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.