HoneyLabs

Akin HTTP request fingerprint

a11cun150_001cf97d_49a62551

Seen 2026-09-22 to 2026-09-24 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS45102 sends an email when it next hits a sensor.

44

Source IPs

8

Networks

3

Countries

658

Ports hit

1.5K

Events

6

IPs / network

Top networks

Countries

US 24CN 19CA 1

Ports targeted

What it requests

GET/775

User agents claimed

Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.3644 IPs1.5K
Source IPCCNetwork Last seenEvents
123.160.223.74AS0 Chinanet2026-09-24262
123.160.223.72AS0 Chinanet2026-09-24229
123.160.223.73AS0 Chinanet2026-09-24225
123.160.223.75AS0 Chinanet2026-09-24223
47.251.118.89AS0 Alibaba (US) Technology Co., Ltd.2026-09-2428
47.251.188.16AS0 Alibaba (US) Technology Co., Ltd.2026-09-2426
47.89.246.29AS0 Alibaba (US) Technology Co., Ltd.2026-09-2426
47.251.88.238AS0 Alibaba (US) Technology Co., Ltd.2026-09-2426
47.77.228.238AS0 Alibaba (US) Technology Co., Ltd.2026-09-2425
47.251.79.205AS0 Alibaba (US) Technology Co., Ltd.2026-09-2423
47.251.186.126AS0 Alibaba (US) Technology Co., Ltd.2026-09-2423
47.254.76.66AS0 Alibaba (US) Technology Co., Ltd.2026-09-2423
47.251.24.105AS0 Alibaba (US) Technology Co., Ltd.2026-09-2422
47.77.220.146AS0 Alibaba (US) Technology Co., Ltd.2026-09-2422
185.126.82.201AS0 HostHatch, LLC2026-09-2421
47.88.94.125AS0 Alibaba (US) Technology Co., Ltd.2026-09-2421
198.44.130.102AS0 tzulo, inc.2026-09-2420
47.89.195.183AS0 Alibaba (US) Technology Co., Ltd.2026-09-2419
47.251.89.134AS0 Alibaba (US) Technology Co., Ltd.2026-09-2419
47.251.188.82AS0 Alibaba (US) Technology Co., Ltd.2026-09-2419

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

a11cun160_005cf97d_7acbd9b11 header apart4 IPs265a11cun160_005cf97d_d92d9ef71 header apart4 IPs76a11cun163_001ce87d_62d94f652 headers apart1 IPs1

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.