HoneyLabs

Akin HTTP request fingerprint

a11cun060_0080005b_3af976da

Seen 2026-09-22 to 2026-09-24 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS135377 sends an email when it next hits a sensor.

113

Source IPs

3

Networks

4

Countries

105

Ports hit

289

Events

38

IPs / network

This fingerprint is concentrated: many addresses on very few networks, which is what a single coordinated operation tends to look like.

Top networks

Countries

HK 92CN 18US 2SG 1

Ports targeted

What it requests

GET/289

User agents claimed

Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36113 IPs289
Source IPCCNetwork Last seenEvents
156.225.1.97AS0 AGOTOZ PTE. LTD.2026-09-248
118.26.38.132AS0 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-247
128.1.132.17AS0 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-246
156.225.1.90AS0 AGOTOZ PTE. LTD.2026-09-246
118.193.45.220AS0 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-245
152.32.133.206AS0 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-245
118.193.45.234AS0 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-245
156.225.1.47AS0 AGOTOZ PTE. LTD.2026-09-245
152.32.188.12AS0 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-245
156.225.1.88AS0 AGOTOZ PTE. LTD.2026-09-245
152.32.209.108AS0 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-245
156.225.1.94AS0 AGOTOZ PTE. LTD.2026-09-245
156.225.1.114AS0 AGOTOZ PTE. LTD.2026-09-234
123.58.213.22AS0 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-244
156.225.1.112AS0 AGOTOZ PTE. LTD.2026-09-244
152.32.254.132AS0 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-244
118.26.38.29AS0 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-234
152.32.189.202AS0 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-234
101.36.116.230AS0 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-244
123.58.212.238AS0 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-244

Fingerprint family: 2 shapes, 113 IPs, 576 events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 6 headers, no body: accept, connection, host, accept-language, user-agent, accept-charset

asks for/ · /favicon.ico (GET)
asMozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0. and 1 more
ports49153 · 12323 · 12328 · 12330
fromHK · CN · US · SG · UCLOUD INFORMATION TECHNOLOGY (HK) LIMIT · AGOTOZ PTE. LTD. · China Unicom Beijing Province Network
a11cun060_0080005b_3af976da this oneMozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0. · /113 IPs288a11cun070_00c0005b_01a11761+/- referer · Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0. · /favicon.ico113 IPs288

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

a11cun060_0080005b_fb12cadfsame header set52 IPs87a11cun050_0000005b_09001b3e1 header apart976 IPs11.9Ka11cun050_0000005b_e6fe1ac31 header apart4 IPs613a11cun070_00c0005b_01a117611 header apart113 IPs289a11cun050_0000005b_fda4f7dc1 header apart1 IPs146a11cun050_0000005b_d5e10d851 header apart18 IPs22a11cun061_0000005b_fb1a47e41 header apart1 IPs21a11cun061_0000005b_c1238ccd1 header apart1 IPs2

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.