HoneyLabs

Akin HTTP request fingerprint

a11cun160_105ce87f_6f8bab43

Seen 2026-09-22 to 2026-09-23 across the retained window.

46

Source IPs

1

Networks

6

Countries

40

Ports hit

47

Events

46

IPs / network

This fingerprint is concentrated: many addresses on very few networks, which is what a single coordinated operation tends to look like.

Top networks

Countries

US 30NL 7DE 4CA 3IN 1GB 1

Ports targeted

What it requests

User agents claimed

Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.3646 IPs47
Source IPCCNetwork Last seenEvents
144.126.223.227USAS14061 DigitalOcean, LLC2026-09-232
188.166.14.247NLAS14061 DigitalOcean, LLC2026-09-221
178.62.209.33NLAS14061 DigitalOcean, LLC2026-09-231
143.198.137.22USAS14061 DigitalOcean, LLC2026-09-231
165.245.227.57CAAS14061 DigitalOcean, LLC2026-09-221
64.227.101.170USAS14061 DigitalOcean, LLC2026-09-221
143.198.54.116USAS14061 DigitalOcean, LLC2026-09-221
159.223.213.128NLAS14061 DigitalOcean, LLC2026-09-221
64.227.111.40USAS14061 DigitalOcean, LLC2026-09-221
188.166.107.89NLAS14061 DigitalOcean, LLC2026-09-221
67.205.185.201USAS14061 DigitalOcean, LLC2026-09-221
159.65.36.55USAS14061 DigitalOcean, LLC2026-09-231
134.122.32.57CAAS14061 DigitalOcean, LLC2026-09-221
64.227.100.242USAS14061 DigitalOcean, LLC2026-09-221
143.198.129.246USAS14061 DigitalOcean, LLC2026-09-221
167.71.53.237DEAS14061 DigitalOcean, LLC2026-09-231
209.97.143.247GBAS14061 DigitalOcean, LLC2026-09-231
146.190.137.254USAS14061 DigitalOcean, LLC2026-09-221
137.184.34.180USAS14061 DigitalOcean, LLC2026-09-231
64.23.249.117USAS14061 DigitalOcean, LLC2026-09-221

Fingerprint family: 2 shapes, 46 IPs, 94 events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 15 headers, no body: accept, connection, accept-encoding, host, accept-language, upgrade-insecure-requests, user-agent, sec-fetch-mode, sec-fetch-dest, sec-fetch-site, sec-fetch-user, sec-ch-ua-platform, sec-ch-ua-mobile, sec-ch-ua, sec-gpc

asks for/ · /favicon.ico (GET)
asMozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/14 and 1 more
ports1224 · 8001 · 1337 · 8081
fromUS · NL · DE · CA · DigitalOcean, LLC
a11cun150_101ce87f_80239852Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/14 · /46 IPs47a11cun160_105ce87f_6f8bab43 this one+/- referer · Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/14 · /favicon.ico46 IPs47

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

a11cun150_101ce87f_802398521 header apart46 IPs47a11cun259_001ce87f_5890ef002 headers apart1 IPs1

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.