HoneyLabs

Akin HTTP request fingerprint

a11cun050_0000005d_fecf3944

Seen 2026-09-23 to 2026-09-23 across the retained window.

3

Source IPs

1

Networks

1

Countries

1

Ports hit

3

Events

3

IPs / network

Top networks

Countries

JP 3

Ports targeted

What it requests

GET/3

User agents claimed

Mozilla/5.0 (Windows NT 6.2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/28.0.1500.95 Safari/537.361 IPs1
Mozilla/5.0 (Windows NT 6.1; rv:2.0.1) Gecko/20100101 Firefox/4.0.11 IPs1
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:53.0) Gecko/20100101 Firefox/53.01 IPs1
Source IPCCNetwork Last seenEvents
47.74.9.19JPAS45102 Alibaba (US) Technology Co., Ltd.2026-09-231
8.211.145.158JPAS45102 Alibaba (US) Technology Co., Ltd.2026-09-231
8.209.206.203JPAS45102 Alibaba (US) Technology Co., Ltd.2026-09-231

Fingerprint family: 2 shapes, 10 IPs, 3.7K events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 4 headers, no body: accept, accept-encoding, host, user-agent

asks for/ · /version · /favicon.ico · /backend/.env (GET)
asPython/3.10 aiohttp/3.8.4 · Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) · Mozilla/5.0 and 7 more
ports2087 · 300 · 9876 · 6969
fromNL · US · JP · IP Volume inc · HostPapa · GravHosting LLC
a11cun040_0000004d_4110f156Python/3.10 aiohttp/3.8.4 · /10 IPs3.7Ka11cun050_0000005d_fecf3944 this one+/- accept-language · Mozilla/5.0 (Windows NT 6.1; WOW64; rv:53.0) Gecko/20100101 Firefox/53.0 · /3 IPs3

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

a11cun050_0000005d_361dcb62same header set94 IPs526a11cun050_0000005d_7266f93asame header set1 IPs34a11cun061_0000005d_e51d7db3same header set1 IPs1a11cun040_0000004d_aa48e2c81 header apart1.4K IPs10.3Ka11cun040_0000004d_4110f1561 header apart10 IPs3.7Ka11cun060_0000005f_7d5e642b1 header apart89 IPs463a11cun040_0000004d_c2bd490f1 header apart30 IPs244a11cun040_0000004d_f36dd82e1 header apart6 IPs165

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.