HoneyLabs

Akin HTTP request fingerprint

a11cun070_00c0005b_01a11761

Seen 2026-09-22 to 2026-09-23 across the retained window.

78

Source IPs

3

Networks

3

Countries

57

Ports hit

118

Events

26

IPs / network

This fingerprint is concentrated: many addresses on very few networks, which is what a single coordinated operation tends to look like.

Top networks

Countries

HK 61CN 15US 2

Ports targeted

What it requests

User agents claimed

Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.3678 IPs118
Source IPCCNetwork Last seenEvents
156.225.1.97HKAS9465 AGOTOZ PTE. LTD.2026-09-235
118.26.38.29HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-234
152.32.188.12HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-234
156.225.1.114HKAS9465 AGOTOZ PTE. LTD.2026-09-233
128.1.132.17HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-233
152.32.133.206HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-233
106.75.12.68CNAS4808 China Unicom Beijing Province Network2026-09-233
152.32.213.85HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-233
123.58.219.233HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-233
101.36.119.242HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-233
106.75.9.73CNAS4808 China Unicom Beijing Province Network2026-09-232
106.75.16.92CNAS4808 China Unicom Beijing Province Network2026-09-232
152.32.190.84HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-232
156.225.1.89HKAS9465 AGOTOZ PTE. LTD.2026-09-232
106.75.5.38CNAS4808 China Unicom Beijing Province Network2026-09-232
128.1.132.84HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-232
106.75.7.49CNAS4808 China Unicom Beijing Province Network2026-09-232
118.193.45.234HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-232
156.225.1.90HKAS9465 AGOTOZ PTE. LTD.2026-09-232
152.32.188.242HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-222

Fingerprint family: 2 shapes, 78 IPs, 236 events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 6 headers, no body: accept, connection, host, accept-language, user-agent, accept-charset

asks for/ · /favicon.ico (GET)
asMozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0. and 1 more
ports12330 · 12331 · 12329 · 51002
fromHK · CN · US · UCLOUD INFORMATION TECHNOLOGY (HK) LIMIT · AGOTOZ PTE. LTD. · China Unicom Beijing Province Network
a11cun060_0080005b_3af976daMozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0. · /78 IPs118a11cun070_00c0005b_01a11761 this one+/- referer · Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0. · /favicon.ico78 IPs118

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

a11cun060_0080005b_3af976da1 header apart78 IPs118a11cun060_0080005b_fb12cadf1 header apart28 IPs36a11cun050_0000005b_09001b3e2 headers apart968 IPs5.0Ka11cun050_0000005b_e6fe1ac32 headers apart1 IPs266a11cun050_0000005b_fda4f7dc2 headers apart1 IPs146a11cun050_0000005b_d5e10d852 headers apart11 IPs11

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.