HoneyLabs

Akin HTTP request fingerprint

a11cun060_e000004a_ffe60107

Seen 2026-09-22 to 2026-09-28 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS135377 sends an email when it next hits a sensor.

24

Source IPs

8

Networks

7

Countries

19

Ports hit

170

Events

3

IPs / network

Top networks

Countries

HK 16FR 2NL 2CN 1IR 1US 1RU 1

Ports targeted

What it requests

GET/48
GET/ws36
GET/raw36

User agents claimed

rawgrab17 IPs144
Go-http-client/1.14 IPs20
CryptoHunter-Vite-2026/1.01 IPs4
cloudflared/2025.11.12 IPs2
Source IPCCNetwork Last seenEvents
101.36.116.230HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-2416
156.225.1.88HKAS9465 AGOTOZ PTE. LTD.2026-09-278
156.225.1.94HKAS9465 AGOTOZ PTE. LTD.2026-09-238
152.32.133.206HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-238
128.1.132.17HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-288
152.32.240.77HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-248
156.225.1.114HKAS9465 AGOTOZ PTE. LTD.2026-09-228
106.75.9.9CNAS4808 China Unicom Beijing Province Network2026-09-288
156.225.1.95HKAS9465 AGOTOZ PTE. LTD.2026-09-278
152.32.213.95HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-278
173.212.205.22FRAS51167 Contabo GmbH2026-09-268
156.225.1.47HKAS9465 AGOTOZ PTE. LTD.2026-09-248
156.225.1.42HKAS9465 AGOTOZ PTE. LTD.2026-09-228
101.36.106.109HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-248
156.225.1.115HKAS9465 AGOTOZ PTE. LTD.2026-09-228
118.193.44.104HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-248
152.32.254.132HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-278
156.225.1.40HKAS9465 AGOTOZ PTE. LTD.2026-09-248
213.177.179.12IRAS208137 Feo Prest SRL2026-09-248
72.46.85.71USAS396356 Latitude.sh2026-09-234

Fingerprint family: 2 shapes, 24 IPs, 174 events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 6 headers, no body: connection, host, user-agent, upgrade, sec-websocket-version, sec-websocket-key

asks for/ · /ws · /socket.io/?EIO=4&transport=websocket · /raw (GET)
asrawgrab · Go-http-client/1.1 · CryptoHunter-Vite-2026/1.0 and 2 more
ports8080 · 50001 · 443 · 4173
fromHK · FR · CN · IR · UCLOUD INFORMATION TECHNOLOGY (HK) LIMIT · AGOTOZ PTE. LTD. · Contabo GmbH
a11cun060_e000004a_ffe60107 this onerawgrab · /24 IPs170a11cun050_e000000a_96308994+/- user-agent · /2 IPs4

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

a11cun082_e000004a_966c00f7same header set1 IPs96a11cun071_e000004a_cfe69652same header set5 IPs27a11cun050_e000000a_985b94971 header apart11 IPs17a11cun050_e000000a_963089941 header apart2 IPs4a11cun081_e400004a_966c00f71 header apart1 IPs3a11cun080_e080004b_62abb4d42 headers apart1 IPs2

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.