Akin HTTP request fingerprint
b10cun000_00000000_334359b9
Seen 2026-02-16 to 2026-10-06 across the retained window.
The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked.
Or watch the top network: AS14061 sends an email when it next hits a sensor.
Countries
US 1.1KDE 400BE 365PK 138CN 101SG 36CA 30GB 15AU 14IN 14
Source IPCCNetwork
Last seenEvents
16.5.0.236BRAS401661 AS4016612026-09-151.3K 112.124.56.253CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-11126 112.124.65.40CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-10-05124 121.43.230.7CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-28111 47.94.138.70CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-09107 121.41.165.113CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-10-04103 47.95.194.193CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-27102 47.95.210.78CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-10101 47.95.213.125CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-2897 206.189.79.156USAS14061 DigitalOcean, LLC2026-10-0596 47.95.199.141CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-2593 121.43.117.235CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-1689 121.40.43.190CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-10-0588 47.95.207.57CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-10-0584 47.95.206.102CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-2584 47.95.209.77CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-0984 121.41.167.96CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-10-0583 39.100.83.5CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-1681 121.199.163.202CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-10-0577 47.94.136.50CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-10-0476
Fingerprint family: 2 shapes, 2.2K IPs, 23.2K events in 30 days
Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.
HTTP/1.0, 0 headers, no body: no headers
asks for/ · /nice%20ports%2C/Tri%6Eity.txt%2ebak · /v1.24/version · /containers/json (GET / OPTIONS)
asMozilla/5.0 (compatible; opendir-scanner/1.0) · Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/) and 1 more
ports2375 · 2376 · 27017 · 80
fromUS · DE · CN · BE · DigitalOcean, LLC · Akamai Connected Cloud · Hangzhou Alibaba Advertising Co.,Ltd.
b10cun000_00000000_334359b9 this one/2.2K IPs23.2Kb10cun010_00000010_c4b2c4aa+/- user-agent · Mozilla/5.0 (compatible; opendir-scanner/1.0) · /3 IPs10
About this fingerprint
Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.