HoneyLabs

Akin HTTP request fingerprint

a11cun050_0000004f_90cbaab3

Seen 2026-09-23 to 2026-09-23 across the retained window.

56

Source IPs

2

Networks

2

Countries

74

Ports hit

132

Events

28

IPs / network

This fingerprint is concentrated: many addresses on very few networks, which is what a single coordinated operation tends to look like.

Top networks

Countries

GB 55HK 1

Ports targeted

What it requests

GET/132

User agents claimed

Mozilla/5.0 (X11; U; Linux x86_64; en-US) AppleWebKit/534.15 (KHTML, like Gecko) Chrome/10.0.613.0 Safari/534.151 IPs74
Mozilla/5.0 (compatible; InternetMeasurement/1.0; +https://internet-measurement.com/)55 IPs58
Source IPCCNetwork Last seenEvents
150.107.36.82HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-2374
87.236.176.222GBAS211298 Driftnet Ltd2026-09-232
195.96.139.50GBAS211298 Driftnet Ltd2026-09-232
87.236.176.31GBAS211298 Driftnet Ltd2026-09-232
195.96.139.170GBAS211298 Driftnet Ltd2026-09-231
195.96.139.230GBAS211298 Driftnet Ltd2026-09-231
87.236.176.134GBAS211298 Driftnet Ltd2026-09-231
185.247.137.118GBAS211298 Driftnet Ltd2026-09-231
195.96.139.121GBAS211298 Driftnet Ltd2026-09-231
195.96.139.142GBAS211298 Driftnet Ltd2026-09-231
87.236.176.34GBAS211298 Driftnet Ltd2026-09-231
185.247.137.135GBAS211298 Driftnet Ltd2026-09-231
185.247.137.105GBAS211298 Driftnet Ltd2026-09-231
195.96.139.183GBAS211298 Driftnet Ltd2026-09-231
87.236.176.95GBAS211298 Driftnet Ltd2026-09-231
185.247.137.232GBAS211298 Driftnet Ltd2026-09-231
185.247.137.82GBAS211298 Driftnet Ltd2026-09-231
185.247.137.214GBAS211298 Driftnet Ltd2026-09-231
87.236.176.243GBAS211298 Driftnet Ltd2026-09-231
185.247.137.103GBAS211298 Driftnet Ltd2026-09-231

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

a11cun050_0000004f_0d8a8ff5same header set84 IPs762a11cun050_0000004f_af924659same header set30 IPs249a11cun149_0000004f_abf74e9dsame header set7 IPs129a11cun149_0000004f_0366fcaesame header set6 IPs45a11cun050_0000004f_16dcd1e4same header set2 IPs45a11cun050_0000004f_5938b494same header set1 IPs18a11cun050_0000004f_588d51acsame header set1 IPs18a11cun050_0000004f_94db1cf7same header set14 IPs14

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.