HoneyLabs

Akin HTTP request fingerprint

b10cun030_00040011_c91eaf54

Seen 2026-02-17 to 2026-09-29 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS219502 sends an email when it next hits a sensor.

14

Source IPs

13

Networks

9

Countries

15

Ports hit

111

Events

1

IPs / network

This fingerprint is spread thinly across many networks, which is the shape of a common, widely-used client.

Top networks

Unattributed1 IPs2

Countries

NL 5US 2CH 1HK 1FR 1MA 1KR 1UA 1RU 1

Ports targeted

What it requests

GET/86
GET/login8

User agents claimed

Mozilla/5.06 IPs66
Mozilla/5.0 (Linux; Android 10; SM-G960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4324.181 Mobile Safari/537.361 IPs11
titlescan1 IPs8
9router/1.01 IPs7
Dahua/2.01 IPs6
Source IPCCNetwork Last seenEvents
204.76.203.7NLAS51396 Pfcloud UG (haftungsbeschrankt)2026-09-1739
209.99.189.222CHAS402253 SKN Subnet & Telecom Ltd2026-09-0412
94.154.43.222NLAS219502 Storm Industries LLC2026-09-2911
124.156.112.249HKAS132203 Tencent Building, Kejizhongyi Avenue2026-09-299
109.123.243.172FRAS51167 Contabo GmbH2026-09-249
94.154.43.43NLAS219502 Storm Industries LLC2026-09-169
196.124.225.74MAAS36925 MEDITELECOM2026-09-296
220.116.113.35KRAS4766 Korea Telecom2026-09-255
94.154.43.201NLAS219502 Storm Industries LLC2026-09-013
91.219.62.170NLAS50673 Serverius Holding B.V.2026-09-022
67.215.246.69USAS36352 HostPapa2026-09-212
47.42.234.181USAS20115 Charter Communications LLC2026-09-232
176.38.32.93UAAS39608 Lanet Network Ltd2026-09-231
95.71.86.219RUAS12389 Rostelecom2026-09-261

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun030_00040011_c91eaf54same header set546 IPs12.1Kb11cun030_00040011_213543bfsame header set9 IPs78b11cun030_00040011_07783b5dsame header set2 IPs5b11cun040_00040013_608dab681 header apart4.3K IPs243.3Kb11cun040_00040015_4c87b06e1 header apart1.5K IPs158.6Kb11cun020_00040010_724c10fb1 header apart1.4K IPs70.2Kb11cuq040_00040811_2daa70d61 header apart237 IPs6.4Kb11cun020_00040001_78f1f19c1 header apart49 IPs3.3K

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.