HoneyLabs

Akin HTTP request fingerprint

b10cun020_00040001_78f1f19c

Seen 2026-03-02 to 2026-09-28 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS45102 sends an email when it next hits a sensor.

604

Source IPs

78

Networks

27

Countries

534

Ports hit

2.9K

Events

8

IPs / network

Top networks

Countries

SG 243US 229CN 59KR 15IN 10FR 9RU 4ES 4VN 3IR 3

Ports targeted

What it requests

GET/2.9K
Source IPCCNetwork Last seenEvents
47.77.177.220USAS45102 Alibaba (US) Technology Co., Ltd.2026-09-1825
47.254.37.72USAS45102 Alibaba (US) Technology Co., Ltd.2026-09-2822
43.98.205.217SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-1320
43.106.48.44SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-1319
43.106.58.188SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-2818
47.251.120.117USAS45102 Alibaba (US) Technology Co., Ltd.2026-09-1818
47.77.231.118USAS45102 Alibaba (US) Technology Co., Ltd.2026-09-2818
47.251.6.51USAS45102 Alibaba (US) Technology Co., Ltd.2026-09-1817
43.98.199.249SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-1316
47.251.246.235USAS45102 Alibaba (US) Technology Co., Ltd.2026-09-1815
47.77.184.107USAS45102 Alibaba (US) Technology Co., Ltd.2026-09-2815
47.251.83.137USAS45102 Alibaba (US) Technology Co., Ltd.2026-09-1815
47.77.177.14USAS45102 Alibaba (US) Technology Co., Ltd.2026-09-2815
47.251.244.243USAS45102 Alibaba (US) Technology Co., Ltd.2026-09-1814
47.85.104.213USAS45102 Alibaba (US) Technology Co., Ltd.2026-09-2314
47.237.0.46SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-1314
47.251.32.230USAS45102 Alibaba (US) Technology Co., Ltd.2026-09-1814
43.106.53.209SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-1314
47.85.188.157USAS45102 Alibaba (US) Technology Co., Ltd.2026-09-0514
47.251.93.9USAS45102 Alibaba (US) Technology Co., Ltd.2026-09-1813

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun020_00040001_78f1f19csame header set49 IPs3.3Kb11cun020_00040001_4e1a3733same header set11 IPs186b11cun010_00040000_c4b2c4aa1 header apart647 IPs63.7Kb11cun030_00040011_c91eaf541 header apart547 IPs12.1Kb10cun010_00040000_c4b2c4aa1 header apart365 IPs2.0Kb11cun030_00040003_21fe282e1 header apart17 IPs1.4Kb11cun031_00040001_c91eaf54_x74db1 header apart1 IPs402b10cun030_00040011_c91eaf541 header apart14 IPs111

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.