HoneyLabs

Akin HTTP request fingerprint

a11cun060_0000005f_7d5e642b

Seen 2026-09-23 to 2026-09-23 across the retained window.

89

Source IPs

1

Networks

1

Countries

463

Ports hit

463

Events

89

IPs / network

This fingerprint is concentrated: many addresses on very few networks, which is what a single coordinated operation tends to look like.

Top networks

Countries

SG 89

Ports targeted

What it requests

GET/463

User agents claimed

Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.132 Safari/537.3689 IPs463
Source IPCCNetwork Last seenEvents
43.106.58.188SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-2316
43.106.48.6SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-2313
43.106.52.96SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-2313
43.106.58.146SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-2311
47.84.96.224SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-2311
43.106.52.37SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-2311
43.106.56.76SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-2311
43.98.200.1SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-2311
47.84.97.178SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-2310
47.84.111.144SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-2310
43.98.166.144SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-239
47.84.97.110SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-239
47.236.224.95SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-239
43.98.176.103SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-239
43.98.206.191SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-238
47.236.38.116SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-238
43.106.54.116SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-238
43.106.57.106SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-238
43.106.48.162SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-238
43.106.49.28SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-238

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

a11cun060_0000005f_720361ccsame header set2 IPs124a11cun060_0000005f_4dbae000same header set7 IPs69a11cun060_0000005f_10f24f9asame header set4 IPs7a11cun060_0000005f_a83fa1e6same header set1 IPs6a11cun050_0000005b_09001b3e1 header apart963 IPs4.4Ka11cun050_0000004f_0d8a8ff51 header apart78 IPs738a11cun050_0000005d_361dcb621 header apart90 IPs494a11cun050_0000005b_e6fe1ac31 header apart1 IPs266

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.