HoneyLabs

Akin HTTP request fingerprint

a11cun050_00000079_a47bb3dc

Seen 2026-09-22 to 2026-09-23 across the retained window.

2

Source IPs

2

Networks

2

Countries

4

Ports hit

13

Events

1

IPs / network

This fingerprint is spread thinly across many networks, which is the shape of a common, widely-used client.

Top networks

Countries

RO 1DE 1

Ports targeted

What it requests

User agents claimed

Mozilla/5.0 (X11; U; Linux x86_64; en-GB; rv:1.9.0.3) Gecko/2008092510 Ubuntu/8.04 (hardy) Firefox/3.0.31 IPs1
Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; Touch; MASPJS; rv:11.0) like Gecko1 IPs1
Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:25.0) Gecko/20100101 Firefox/25.01 IPs1
Mozilla/5.0 (Windows NT 5.2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/48.0.2564.97 Safari/537.361 IPs1
Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0; yie10)1 IPs1
Source IPCCNetwork Last seenEvents
213.209.159.175DEAS208137 Feo Prest SRL2026-09-238
80.94.95.211ROAS204428 SS-Net2026-09-235

Fingerprint family: 3 shapes, 2 IPs, 3.5K events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 6 headers, no body: accept, connection, host, accept-language, upgrade-insecure-requests, user-agent

asks for/credentials.xml · /.env.php · /old/.env · /api/.git/config (GET)
asMozilla/5.0 (Linux; Android 6.0.1; SM-G550T1 Build/MMB29K) AppleWebKit/537.36 (K · Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0; yie10) · Mozilla/5.0 (Windows NT 5.2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/48.0. and 36 more
ports443 · 8000 · 80 · 3000
fromDE · RO · Feo Prest SRL · SS-Net
a11cun060_0000007b_f55b17efMozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0; yie10) · /beta/2 IPs3.4Ka11cun050_00000079_a47bb3dc this one+/- connection · Mozilla/5.0 (Linux; U; Android 4.4.4; en-us; SM-G360P Build/KTU84P) AppleWebKit/ · /xxhlfmfbworx0l2 IPs13a11cun060_0000007b_8084a027Mozilla/5.0 (Linux; U; Android 4.4.4; en-us; SM-G360P Build/KTU84P) AppleWebKit/ · /var/.env.local.php2 IPs13

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

a11cun060_0000007b_f55b17ef1 header apart2 IPs3.4Ka11cun060_0000007b_8084a0271 header apart2 IPs13a11cun051_00000059_d97268c31 header apart1 IPs1a11cun030_00000049_03330a182 headers apart2 IPs15.3Ka11cun050_0000005b_09001b3e2 headers apart966 IPs4.7Ka11cun030_00000049_54d07b6d2 headers apart580 IPs1.2Ka11cun050_0000005d_361dcb622 headers apart94 IPs526a11cun050_0000005b_e6fe1ac32 headers apart1 IPs266

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.