HoneyLabs

Akin HTTP request fingerprint

a11cun060_0000005f_4dbae000

Seen 2026-09-22 to 2026-09-23 across the retained window.

8

Source IPs

2

Networks

3

Countries

39

Ports hit

79

Events

4

IPs / network

Top networks

Countries

IR 4RU 3DE 1

Ports targeted

What it requests

GET/79

User agents claimed

Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.08 IPs79
Source IPCCNetwork Last seenEvents
158.173.155.33DEAS212238 Datacamp Limited2026-09-2331
62.133.46.5IRAS9009 M247 Europe SRL2026-09-2310
146.70.52.246RUAS9009 M247 Europe SRL2026-09-2310
62.133.46.27IRAS9009 M247 Europe SRL2026-09-238
62.133.46.29IRAS9009 M247 Europe SRL2026-09-238
146.70.52.220RUAS9009 M247 Europe SRL2026-09-236
146.70.52.117RUAS9009 M247 Europe SRL2026-09-234
62.133.46.14IRAS9009 M247 Europe SRL2026-09-232

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

a11cun060_0000005f_7d5e642bsame header set89 IPs463a11cun060_0000005f_720361ccsame header set2 IPs127a11cun060_0000005f_10f24f9asame header set4 IPs7a11cun060_0000005f_a83fa1e6same header set1 IPs6a11cun050_0000005b_09001b3e1 header apart966 IPs4.7Ka11cun050_0000004f_0d8a8ff51 header apart84 IPs762a11cun050_0000005d_361dcb621 header apart94 IPs530a11cun050_0000005b_e6fe1ac31 header apart1 IPs266

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.