HoneyLabs

Akin HTTP request fingerprint

b10cun000_00000000_334359b9

Seen 2026-02-16 to 2026-10-06 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS14061 sends an email when it next hits a sensor.

2.2K

Source IPs

82

Networks

28

Countries

1.8K

Ports hit

23.2K

Events

27

IPs / network

Top networks

Countries

US 1.1KDE 400BE 365PK 138CN 101SG 36CA 30GB 15AU 14IN 14

Ports targeted

What it requests

GET/18.8K
GET/info215
GET/version215
Source IPCCNetwork Last seenEvents
16.5.0.236BRAS401661 AS4016612026-09-151.3K
112.124.56.253CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-11126
112.124.65.40CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-10-05124
121.43.230.7CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-28111
47.94.138.70CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-09107
121.41.165.113CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-10-04103
47.95.194.193CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-27102
47.95.210.78CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-10101
47.95.213.125CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-2897
206.189.79.156USAS14061 DigitalOcean, LLC2026-10-0596
47.95.199.141CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-2593
121.43.117.235CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-1689
121.40.43.190CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-10-0588
47.95.207.57CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-10-0584
47.95.206.102CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-2584
47.95.209.77CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-0984
121.41.167.96CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-10-0583
39.100.83.5CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-1681
121.199.163.202CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-10-0577
47.94.136.50CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-10-0476

Fingerprint family: 2 shapes, 2.2K IPs, 23.2K events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.0, 0 headers, no body: no headers

asks for/ · /nice%20ports%2C/Tri%6Eity.txt%2ebak · /v1.24/version · /containers/json (GET / OPTIONS)
asMozilla/5.0 (compatible; opendir-scanner/1.0) · Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/) and 1 more
ports2375 · 2376 · 27017 · 80
fromUS · DE · CN · BE · DigitalOcean, LLC · Akamai Connected Cloud · Hangzhou Alibaba Advertising Co.,Ltd.
b10cun000_00000000_334359b9 this one/2.2K IPs23.2Kb10cun010_00000010_c4b2c4aa+/- user-agent · Mozilla/5.0 (compatible; opendir-scanner/1.0) · /3 IPs10

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun000_00000000_334359b9same header set75 IPs1.4Kb11cun010_00040000_c4b2c4aa1 header apart672 IPs70.8Kb10cun010_00040000_c4b2c4aa1 header apart392 IPs2.3Kb10cun010_00000004_a37af9cb1 header apart9 IPs663b10cun010_00000010_c4b2c4aa1 header apart3 IPs10b10cun020_00000014_0a8d7f112 headers apart2.0K IPs566.4Kb11cun020_00040010_724c10fb2 headers apart1.5K IPs68.9Kb11cun020_00040001_78f1f19c2 headers apart41 IPs11.6K

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.