HoneyLabs

Akin HTTP request fingerprint

b10cun010_00040000_c4b2c4aa

Seen 2026-02-17 to 2026-10-01 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS396982 sends an email when it next hits a sensor.

365

Source IPs

21

Networks

19

Countries

323

Ports hit

1.9K

Events

17

IPs / network

Top networks

Countries

US 269SG 38FI 7DE 6BE 6GB 6BR 6NL 5AU 5CH 3

Ports targeted

What it requests

GET/719
Source IPCCNetwork Last seenEvents
46.151.178.11NLAS211443 Sino Worldwide Trading Limited2026-09-241.2K
195.178.110.204BGAS48090 Techoff Srv Limited2026-10-01150
31.170.22.205LVAS43513 Sia Nano IT2026-09-0338
23.94.99.34USAS36352 HostPapa2026-09-2817
188.92.79.113LVAS43513 Sia Nano IT2026-09-0313
155.103.157.133USAS42960 VH Global Limited2026-09-308
93.123.109.214BGAS48090 Techoff Srv Limited2026-10-016
216.180.246.224USAS396982 Google LLC2026-09-286
216.180.246.163USAS396982 Google LLC2026-09-275
216.180.246.143USAS396982 Google LLC2026-09-285
216.180.246.218USAS396982 Google LLC2026-09-195
216.180.246.119USAS396982 Google LLC2026-09-285
216.180.246.158USAS396982 Google LLC2026-09-195
216.180.246.122USAS396982 Google LLC2026-09-285
94.154.43.95NLAS219502 Storm Industries LLC2026-09-075
216.180.246.197USAS396982 Google LLC2026-09-275
216.180.246.75USAS396982 Google LLC2026-09-255
216.180.246.201USAS396982 Google LLC2026-09-194
216.180.246.234USAS396982 Google LLC2026-09-194
216.180.246.22USAS396982 Google LLC2026-09-164

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun010_00040000_c4b2c4aasame header set654 IPs64.5Kb11cun020_00040010_724c10fb1 header apart1.4K IPs70.5Kb10lun000_00000000_334359b91 header apart2.2K IPs24.5Kb11cun020_00040004_0a8d7f111 header apart3.9K IPs8.8Kb11cun020_00040001_78f1f19c1 header apart45 IPs4.6Kb10cun020_00040001_78f1f19c1 header apart610 IPs3.0Kb10cun020_00040010_724c10fb1 header apart14 IPs1.9Kb11cun020_00040002_5ff1c0a91 header apart129 IPs1.6K

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.