Akin HTTP request fingerprint
a11cuq041_00000248_a31e7c35
Seen 2026-09-23 to 2026-09-24 across the retained window.
The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS8075 sends an email when it next hits a sensor.
395
Source IPs
146
Networks
54
Countries
1
Ports hit
554
Events
3
IPs / network
This fingerprint is spread across many networks, but its whole history is one short burst against one or two ports. That is the shape of a coordinated operation spread thinly on purpose, rather than a client in general circulation.
Top networks
Countries
Ports targeted
What it requests
User agents claimed
Related fingerprints
Clients whose header set is within two of this one, measured from the tokens themselves.
About this fingerprint
Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.