HoneyLabs

Akin HTTP request fingerprint

b11cdn071_00040017_9f8bde3d_xd99b

Seen 2026-08-15 to 2026-09-21 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS213790 sends an email when it next hits a sensor.

2

Source IPs

2

Networks

2

Countries

4

Ports hit

412

Events

1

IPs / network

This fingerprint is spread thinly across many networks, which is the shape of a common, widely-used client.

Top networks

Countries

NL 1DE 1

Ports targeted

What it requests

GET/.env16

User agents claimed

Mozilla/5.0 (Macintosh; Intel Mac OS X 14_4_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.362 IPs64
Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.5 Safari/605.1.152 IPs64
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.362 IPs58
Mozilla/5.0 (X11; Linux x86_64; rv:126.0) Gecko/20100101 Firefox/126.02 IPs54
Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:126.0) Gecko/20100101 Firefox/126.02 IPs52
Source IPCCNetwork Last seenEvents
192.253.248.163NLAS213790 Limited Network LTD2026-09-21240
213.209.159.148DEAS208137 Feo Prest SRL2026-09-09172

Fingerprint family: 10 shapes, 1.3K IPs, 23.7K events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 5 headers, no body: connection, accept-encoding, accept, user-agent, host

asks for/panel/api/inbounds/list · /xui/API/inbounds/ · / · /panel/API/inbounds/ (GET / POST)
asMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) · Mozilla/5.0 (X11; Linux x86_64; rv:135.0) Gecko/20100101 Firefox/135.0 · Mozilla/5.0 (compatible; Infrawatch/1.0; +https://infrawat.ch/) and 146 more
ports2053 · 443 · 54321 · 80
fromCY · NL · HK · GB · NetCrafters OU · UCLOUD INFORMATION TECHNOLOGY (HK) LIMIT · Alsycon B.V.
b11cun050_00040017_6b90553bMozilla/5.0 (X11; Linux x86_64; rv:135.0) Gecko/20100101 Firefox/135.0 · /1.3K IPs9.3Kb11cun061_00040017_a9482ae2_x74db+/- proxy-authorization · python-requests/2.34.2 · http://ip-api.com/json/?fields=status,country,countryCode,qu3 IPs59b11cuq082_00040817_03a2bf31_xd368ff63+/- content-length, x-csrf-token, x-requested-with · Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) · /panel/api/inbounds/list2 IPs7.8Kb11cun072_00040017_4c344a22_xd368ff63+/- x-csrf-token, x-requested-with · Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) · /xui/API/inbounds/2 IPs5.8Kb11cdn071_00040017_9f8bde3d_xd99b this one+/- d99b · Mozilla/5.0 (Macintosh; Intel Mac OS X 14_4_1) AppleWebKit/537.36 (KHTML, like G · /.env.development.local2 IPs412b11cun061_00040017_c5b51fcd_xff63+/- x-requested-with · Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) · /csrf-token2 IPs221b11cun040_00040016_03bbcb12+/- connection · CryptoHunter-Vite-2026/1.0 · /src/index.js2 IPs50b11cuq060_00040817_1d464540+/- content-length · Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/118.0 · /cgi-bin/system_mgr.cgi2 IPs9b11cun050_00040017_3ef2f4acMozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:109.0) Gecko/20100101 Firefox/114.0 · /jsonapi/node/page?filter[t][condition][path]=title&filter[t2 IPs5b11cun050_00040017_69b07330Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) · /cgi-bin/login.cgi2 IPs5

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun050_00040017_976354f01 header apart1.3K IPs18.8Kb11cun050_00040017_6b90553b1 header apart1.3K IPs9.3Kb11cun050_00040017_e873236c1 header apart681 IPs6.1Kb11cun050_00040017_d1f380a61 header apart5 IPs3.2Kb11cun050_00040017_eba289fe1 header apart19 IPs2.8Kb11cun050_00040017_345c845b1 header apart469 IPs2.6Kb11cun050_00040017_97f1d74f1 header apart38 IPs2.0Kb11cun050_00040017_2015d6b21 header apart524 IPs1.2K

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.