HoneyLabs

Akin HTTP request fingerprint

a11cun050_0000004f_0d8a8ff5

Seen 2026-09-22 to 2026-09-23 across the retained window.

77

Source IPs

9

Networks

8

Countries

123

Ports hit

737

Events

9

IPs / network

Top networks

Countries

US 47BE 24IN 1ID 1SC 1CM 1AT 1DE 1

Ports targeted

What it requests

GET/167

User agents claimed

Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.361 IPs559
python-requests/2.34.224 IPs110
python-requests/2.25.11 IPs6
python-requests/2.27.11 IPs5
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36 Edg/125.0.0.01 IPs4
Source IPCCNetwork Last seenEvents
203.175.125.156IDAS139952 PT Trisari Data Indonusa2026-09-22565
34.79.30.146BEAS396982 Google LLC2026-09-2312
34.76.199.251BEAS396982 Google LLC2026-09-2310
34.34.177.236BEAS396982 Google LLC2026-09-238
34.77.125.222BEAS396982 Google LLC2026-09-238
34.140.134.245BEAS396982 Google LLC2026-09-237
35.187.95.46BEAS396982 Google LLC2026-09-237
34.52.139.66BEAS396982 Google LLC2026-09-237
35.195.11.198BEAS396982 Google LLC2026-09-237
34.140.146.112BEAS396982 Google LLC2026-09-237
34.62.17.249BEAS396982 Google LLC2026-09-235
34.156.156.224BEAS396982 Google LLC2026-09-235
34.22.222.15BEAS396982 Google LLC2026-09-235
34.140.129.51BEAS396982 Google LLC2026-09-235
160.119.76.210SCAS49870 Alsycon B.V.2026-09-235
165.22.220.129INAS14061 DigitalOcean, LLC2026-09-234
207.175.170.227BEAS396982 Google LLC2026-09-233
18.97.5.29USAS14618 Amazon.com, Inc.2026-09-232
35.240.97.242BEAS396982 Google LLC2026-09-232
35.187.182.21BEAS396982 Google LLC2026-09-232

Fingerprint family: 2 shapes, 77 IPs, 746 events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

a11cun050_0000004f_0d8a8ff5 this one77 IPs734a11cun050_0000004f_94db1cf712 IPs12

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

a11cun050_0000004f_af924659same header set29 IPs239a11cun149_0000004f_abf74e9dsame header set7 IPs129a11cun050_0000004f_90cbaab3same header set49 IPs124a11cun149_0000004f_0366fcaesame header set6 IPs45a11cun050_0000004f_16dcd1e4same header set2 IPs45a11cun050_0000004f_5938b494same header set1 IPs18a11cun050_0000004f_588d51acsame header set1 IPs17a11cun050_0000004f_94db1cf7same header set12 IPs12

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.