HoneyLabs

Akin HTTP request fingerprint

b10lun000_00000000_334359b9

Seen 2026-02-16 to 2026-09-30 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS14061 sends an email when it next hits a sensor.

2.2K

Source IPs

79

Networks

29

Countries

1.5K

Ports hit

24.8K

Events

28

IPs / network

Top networks

Countries

US 1.1KDE 404BE 367PK 129CN 90CA 38SG 26GB 18IN 16AU 15

Ports targeted

What it requests

GET/19.7K
GET/info274
GET/version274
Source IPCCNetwork Last seenEvents
16.5.0.236USAS401661 EMBNEX, LLC2026-09-151.6K
112.124.56.253CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-11126
121.43.230.7CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-28111
47.94.138.70CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-09107
47.95.194.193CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-27102
47.95.210.78CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-10101
47.95.213.125CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-2897
47.95.199.141CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-2593
206.189.79.156USAS14061 DigitalOcean, LLC2026-09-2891
121.43.117.235CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-1689
47.95.209.77CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-0984
47.95.206.102CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-2584
39.100.83.5CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-1681
204.48.20.222USAS14061 DigitalOcean, LLC2026-09-2980
173.255.206.221USAS63949 Akamai Connected Cloud2026-09-3075
47.95.210.236CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-0275
64.227.16.244USAS14061 DigitalOcean, LLC2026-09-3075
68.183.26.238USAS14061 DigitalOcean, LLC2026-09-2973
170.187.147.145USAS63949 Akamai Connected Cloud2026-09-2970
146.190.66.53USAS14061 DigitalOcean, LLC2026-09-2969

Fingerprint family: 2 shapes, 2.2K IPs, 24.8K events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.0, 0 headers, no body: no headers

asks for/ · /nice%20ports%2C/Tri%6Eity.txt%2ebak · /v1.44/version · /v1.24/version (GET / OPTIONS)
asMozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/) and 1 more
ports2375 · 2376 · 27017 · 12375
fromUS · DE · CN · BR · DigitalOcean, LLC · Akamai Connected Cloud · Hangzhou Alibaba Advertising Co.,Ltd.
b10lun000_00000000_334359b9 this one/2.2K IPs24.8Kb10cun010_00000010_c4b2c4aa+/- user-agent · Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/) · /spConn?action=getInfo2 IPs2

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11lun000_00000000_334359b9same header set70 IPs1.5Kb11cun010_00040000_c4b2c4aa1 header apart648 IPs63.6Kb10cun010_00040000_c4b2c4aa1 header apart374 IPs2.1Kb10cun010_00000004_a37af9cb1 header apart9 IPs624b10cun010_00000010_c4b2c4aa1 header apart2 IPs2b10cun011_00000000_c4b2c4aa_x4d8a1 header apart1 IPs1b11cuq010_00000800_c4b2c4aa1 header apart1 IPs1b10cun020_00000014_0a8d7f112 headers apart2.0K IPs617.5K

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.