HoneyLabs

Akin HTTP request fingerprint

a11cun050_0000004f_94db1cf7

Seen 2026-09-22 to 2026-09-23 across the retained window.

14

Source IPs

1

Networks

1

Countries

13

Ports hit

14

Events

14

IPs / network

Top networks

Countries

US 14

Ports targeted

What it requests

GET/14

User agents claimed

Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.3614 IPs14
Source IPCCNetwork Last seenEvents
44.220.188.29USAS14618 Amazon.com, Inc.2026-09-231
18.97.26.56USAS14618 Amazon.com, Inc.2026-09-231
98.80.4.14USAS14618 Amazon.com, Inc.2026-09-221
18.97.5.126USAS14618 Amazon.com, Inc.2026-09-231
18.97.19.182USAS14618 Amazon.com, Inc.2026-09-231
44.220.188.73USAS14618 Amazon.com, Inc.2026-09-231
44.220.188.99USAS14618 Amazon.com, Inc.2026-09-231
44.220.188.116USAS14618 Amazon.com, Inc.2026-09-231
18.97.5.73USAS14618 Amazon.com, Inc.2026-09-231
18.97.26.47USAS14618 Amazon.com, Inc.2026-09-231
44.220.185.237USAS14618 Amazon.com, Inc.2026-09-231
18.97.5.111USAS14618 Amazon.com, Inc.2026-09-221
98.80.4.28USAS14618 Amazon.com, Inc.2026-09-221
44.220.188.117USAS14618 Amazon.com, Inc.2026-09-231

Fingerprint family: 2 shapes, 84 IPs, 776 events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 5 headers, no body: accept, connection, accept-encoding, host, user-agent

asks for/ · /admin/config.php · /api/usage/stats · /.git-credentials (GET / HEAD)
asMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 · python-requests/2.34.2 · python-requests/2.25.1 and 60 more
ports443 · 80 · 6664 · 20128
fromID · BE · US · SC · PT Trisari Data Indonusa · Google LLC · Amazon.com, Inc.
a11cun050_0000004f_0d8a8ff5Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 · /84 IPs762a11cun050_0000004f_94db1cf7 this oneMozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like · /14 IPs14

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

a11cun050_0000004f_0d8a8ff5same header set84 IPs762a11cun050_0000004f_af924659same header set30 IPs249a11cun050_0000004f_90cbaab3same header set56 IPs132a11cun149_0000004f_abf74e9dsame header set7 IPs129a11cun149_0000004f_0366fcaesame header set6 IPs45a11cun050_0000004f_16dcd1e4same header set2 IPs45a11cun050_0000004f_5938b494same header set1 IPs18a11cun050_0000004f_588d51acsame header set1 IPs18

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.