HoneyLabs

Akin HTTP request fingerprint

a11cun080_00000c5f_a498732e

Seen 2026-09-22 to 2026-09-24 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS21859 sends an email when it next hits a sensor.

50

Source IPs

2

Networks

1

Countries

298

Ports hit

557

Events

25

IPs / network

This fingerprint is concentrated: many addresses on very few networks, which is what a single coordinated operation tends to look like.

Top networks

Countries

PT 50

Ports targeted

What it requests

GET/sse557

User agents claimed

python-httpx/0.28.150 IPs557
Source IPCCNetwork Last seenEvents
45.156.129.187PTAS211680 Sistemas Informaticos, S.A.2026-09-2466
45.156.129.54PTAS211680 Sistemas Informaticos, S.A.2026-09-2458
109.105.210.102PTAS21859 Zenlayer Inc2026-09-2453
45.156.129.186PTAS211680 Sistemas Informaticos, S.A.2026-09-2451
45.156.128.10PTAS211680 Sistemas Informaticos, S.A.2026-09-2450
45.156.128.41PTAS211680 Sistemas Informaticos, S.A.2026-09-2440
185.226.197.117PTAS21859 Zenlayer Inc2026-09-2413
45.156.129.75PTAS211680 Sistemas Informaticos, S.A.2026-09-2412
185.180.141.90PTAS21859 Zenlayer Inc2026-09-2412
185.180.141.100PTAS21859 Zenlayer Inc2026-09-2412
185.180.141.85PTAS21859 Zenlayer Inc2026-09-2411
185.226.197.32PTAS21859 Zenlayer Inc2026-09-249
45.156.129.60PTAS211680 Sistemas Informaticos, S.A.2026-09-249
109.105.209.12PTAS21859 Zenlayer Inc2026-09-248
45.156.128.71PTAS211680 Sistemas Informaticos, S.A.2026-09-248
185.180.141.115PTAS21859 Zenlayer Inc2026-09-248
185.180.141.42PTAS21859 Zenlayer Inc2026-09-237
185.226.196.12PTAS21859 Zenlayer Inc2026-09-247
45.156.128.61PTAS211680 Sistemas Informaticos, S.A.2026-09-247
45.156.129.90PTAS211680 Sistemas Informaticos, S.A.2026-09-247

Fingerprint family: 2 shapes, 50 IPs, 1.1K events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 8 headers, no body: accept, connection, accept-encoding, host, accept-language, user-agent, content-type, sec-fetch-mode

asks for/sse · /mcp (GET / POST)
aspython-httpx/0.28.1 and 1 more
ports53 · 2762 · 7548 · 50100
fromPT · Sistemas Informaticos, S.A. · Zenlayer Inc
a11cun080_00000c5f_a498732e this onepython-httpx/0.28.1 · /sse50 IPs557a11cuq090_00000e5f_1cc9394e+/- content-length · python-httpx/0.28.1 · /mcp50 IPs557

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

a11cuq090_00000e5f_1cc9394e1 header apart50 IPs557a11cun060_0000005f_7d5e642b2 headers apart145 IPs613a11cun060_0000005f_720361cc2 headers apart2 IPs332a11cdn090_0020045f_e84e1db12 headers apart1 IPs200a11cun060_0000005f_4dbae0002 headers apart15 IPs159a11cun060_0000005f_d170ef012 headers apart5 IPs156a11cun060_0000005f_0d7d34dc2 headers apart1 IPs48a11cun060_0000005f_a83fa1e62 headers apart1 IPs21

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.