Akin HTTP request fingerprint
a11cun060_0000005f_fc0644f8
Seen 2026-09-25 to 2026-09-26 across the retained window.
The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked.
Or watch the top network: AS37963 sends an email when it next hits a sensor.
This fingerprint is concentrated: many addresses on very few networks, which is what a single coordinated operation tends to look like.
User agents claimed
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/59.0.3071.115 Safari/537.36152 IPs338
Source IPCCNetwork
Last seenEvents
39.100.86.191CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-266 47.95.199.236CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-265 47.95.205.12CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-265 47.95.209.9CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-264 47.95.198.252CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-264 39.100.84.119CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-264 39.100.86.140CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-264 39.100.77.193CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-264 47.94.138.70CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-264 39.100.85.23CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-264 121.43.54.111CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-264 47.95.210.228CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-264 112.124.56.43CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-264 47.97.111.180CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-264 121.43.117.235CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-263 47.95.197.5CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-263 47.95.202.163CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-263 118.31.189.46CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-263 121.41.164.122CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-253 47.95.209.135CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-263
About this fingerprint
Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.