Akin HTTP request fingerprint
a11cun070_00c0005b_01a11761
Seen 2026-09-22 to 2026-09-23 across the retained window.
This fingerprint is concentrated: many addresses on very few networks, which is what a single coordinated operation tends to look like.
User agents claimed
Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.3678 IPs118
Source IPCCNetwork
Last seenEvents
156.225.1.97HKAS9465 AGOTOZ PTE. LTD.2026-09-235 118.26.38.29HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-234 152.32.188.12HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-234 156.225.1.114HKAS9465 AGOTOZ PTE. LTD.2026-09-233 128.1.132.17HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-233 152.32.133.206HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-233 106.75.12.68CNAS4808 China Unicom Beijing Province Network2026-09-233 152.32.213.85HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-233 123.58.219.233HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-233 101.36.119.242HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-233 106.75.9.73CNAS4808 China Unicom Beijing Province Network2026-09-232 106.75.16.92CNAS4808 China Unicom Beijing Province Network2026-09-232 152.32.190.84HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-232 156.225.1.89HKAS9465 AGOTOZ PTE. LTD.2026-09-232 106.75.5.38CNAS4808 China Unicom Beijing Province Network2026-09-232 128.1.132.84HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-232 106.75.7.49CNAS4808 China Unicom Beijing Province Network2026-09-232 118.193.45.234HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-232 156.225.1.90HKAS9465 AGOTOZ PTE. LTD.2026-09-232 152.32.188.242HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-222
Fingerprint family: 2 shapes, 78 IPs, 236 events in 30 days
Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.
HTTP/1.1, 6 headers, no body: accept, connection, host, accept-language, user-agent, accept-charset
asks for/ · /favicon.ico (GET)
asMozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0. and 1 more
ports12330 · 12331 · 12329 · 51002
fromHK · CN · US · UCLOUD INFORMATION TECHNOLOGY (HK) LIMIT · AGOTOZ PTE. LTD. · China Unicom Beijing Province Network
a11cun060_0080005b_3af976daMozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0. · /78 IPs118a11cun070_00c0005b_01a11761 this one+/- referer · Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0. · /favicon.ico78 IPs118
About this fingerprint
Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.