HoneyLabs

Akin HTTP request fingerprint

a11cun064_00000048_f2f3ae25

Seen 2026-09-22 to 2026-09-24 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS207043 sends an email when it next hits a sensor.

2

Source IPs

1

Networks

1

Countries

112

Ports hit

113

Events

2

IPs / network

Top networks

Countries

DE 2

Ports targeted

What it requests

User agents claimed

what-vpn-go/0.12 IPs113
Source IPCCNetwork Last seenEvents
94.26.83.79DEAS207043 Dedik Services Limited2026-09-2461
91.92.43.222DEAS207043 Dedik Services Limited2026-09-2352

Fingerprint family: 4 shapes, 174 IPs, 1.1K events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 2 headers, no body: host, user-agent

asks for/ · http://api.ipify.org/?format=json · /my.policy · /vpntunnel (GET / HEAD)
aswhat-vpn-go/0.1 · fasthttp · Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) and 125 more
ports6379 · 8888 · 8080 · 8090
fromDE · US · RU · NL · Dedik Services Limited · Hurricane Electric LLC · JSC F6
a11cun020_00000048_724c10fbwhat-vpn-go/0.1 · /174 IPs805a11cuq030_00000248_e62b6d85+/- content-length · what-vpn-go/0.1 · /clients4 IPs115a11cun031_00000048_e62b6d85ncsrv · /dana-na2 IPs113a11cun064_00000048_f2f3ae25 this onewhat-vpn-go/0.1 · /sslvpnclient?launchplatform=mac&neProto=3&supportipv6=yes2 IPs113

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

a11cun020_00000048_724c10fbsame header set174 IPs805a10cun020_00000048_724c10fbsame header set3 IPs197a11cun031_00000048_e62b6d85same header set2 IPs113a11cun679_00000048_351eae82same header set1 IPs1a11cun030_00000049_03330a181 header apart4 IPs34.6Ka11cun030_0000004c_13ee3d341 header apart2.2K IPs10.3Ka11cun010_00000008_c4b2c4aa1 header apart390 IPs4.1Ka11cun030_00000049_54d07b6d1 header apart1.2K IPs3.2K

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.