HoneyLabs

Akin HTTP request fingerprint

b10cun020_00040004_1fdb23c0

Seen 2026-02-17 to 2026-10-01 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS4766 sends an email when it next hits a sensor.

393

Source IPs

75

Networks

22

Countries

25

Ports hit

431

Events

5

IPs / network

Top networks

Countries

KR 261JP 86FR 8BR 7DK 4AL 4SG 3IN 3SE 2AE 2

Ports targeted

What it requests

GET/431
Source IPCCNetwork Last seenEvents
210.131.181.74JPAS2519 ARTERIA Networks Corporation2026-09-303
150.31.64.177JPAS2497 Internet Initiative Japan Inc.2026-09-273
115.136.132.51KRAS17858 LG POWERCOMM2026-09-273
182.230.13.204KRAS17858 LG POWERCOMM2026-09-293
128.28.148.4JPAS2514 NTT PC Communications, Inc.2026-09-243
223.171.80.132KRAS17853 LGTELECOM2026-09-302
125.180.43.77KRAS17858 LG POWERCOMM2026-10-012
180.4.28.212JPAS4713 NTT DOCOMO BUSINESS,Inc.2026-09-232
82.65.99.189FRAS12322 Free SAS2026-09-302
183.91.119.235JPAS18278 Cable TV Corporation2026-09-222
222.114.236.62KRAS4766 Korea Telecom2026-09-142
217.21.155.173ALAS29238 Nisatel LTD2026-09-282
120.74.206.128JPAS2527 Sony Network Communications Inc.2026-09-272
195.198.73.66SEAS3301 Telia Company AB2026-09-272
211.248.51.41KRAS4766 Korea Telecom2026-09-202
119.47.165.191JPAS7679 QTnet,Inc.2026-09-292
85.202.68.220DKAS31027 GlobalConnect A/S2026-09-212
89.249.87.82LTAS15440 UAB Baltnetos komunikacijos2026-09-172
61.78.240.223KRAS4766 Korea Telecom2026-09-172
222.112.56.146KRAS4766 Korea Telecom2026-09-272

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun020_00040004_0a8d7f11same header set3.9K IPs8.8Kb10cun020_00040004_be1ad017same header set9 IPs476b11cun020_00040004_1cae80d4same header set14 IPs94b10cun020_00040004_0a8d7f11same header set27 IPs28b11cun030_00040014_03330a181 header apart3.9K IPs1.4Mb11cun030_00040014_54d07b6d1 header apart3.7K IPs105.0Kb11cun010_00040000_c4b2c4aa1 header apart654 IPs64.5Kb10cun010_00040000_c4b2c4aa1 header apart365 IPs2.0K

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.