HoneyLabs

Akin HTTP request fingerprint

a11cun121_0000e95f_b585e99d

Seen 2026-09-22 to 2026-09-23 across the retained window.

4

Source IPs

1

Networks

1

Countries

4

Ports hit

4

Events

4

IPs / network

Top networks

Countries

US 4

Ports targeted

What it requests

GET/4

User agents claimed

Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/59.0.3001.101 Safari/537.321 IPs1
Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/59.0.3049.91 Safari/537.321 IPs1
Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/59.0.3092.52 Safari/537.321 IPs1
Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/58.0.3063.84 Safari/537.321 IPs1
Source IPCCNetwork Last seenEvents
18.97.19.252AS0 Amazon.com, Inc.2026-09-231
44.220.188.218AS0 Amazon.com, Inc.2026-09-231
44.220.185.110AS0 Amazon.com, Inc.2026-09-221
18.97.5.118AS0 Amazon.com, Inc.2026-09-231

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

a11cun121_0000e87f_842068992 headers apart30 IPs30

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.