HoneyLabs

Akin HTTP request fingerprint

b11cdn090_0034003d_bf528200

Seen 2026-09-02 to 2026-09-03 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS200373 sends an email when it next hits a sensor.

240

Source IPs

1

Networks

9

Countries

220

Ports hit

240

Events

240

IPs / network

This fingerprint is concentrated: many addresses on very few networks, which is what a single coordinated operation tends to look like.

Top networks

Countries

US 123FR 30BR 26DE 21GB 18CA 9IT 5TH 4ES 4

Ports targeted

What it requests

GET/240

User agents claimed

Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36240 IPs240
Source IPCCNetwork Last seenEvents
104.207.47.217USAS200373 3xK Tech GmbH2026-09-031
104.207.59.143CAAS200373 3xK Tech GmbH2026-09-031
104.207.58.112THAS200373 3xK Tech GmbH2026-09-031
209.50.162.63USAS200373 3xK Tech GmbH2026-09-031
104.207.49.192BRAS200373 3xK Tech GmbH2026-09-031
104.207.38.39USAS200373 3xK Tech GmbH2026-09-031
193.56.28.220USAS200373 3xK Tech GmbH2026-09-031
209.50.172.170USAS200373 3xK Tech GmbH2026-09-031
209.50.172.174USAS200373 3xK Tech GmbH2026-09-031
209.50.175.216USAS200373 3xK Tech GmbH2026-09-031
217.181.91.106DEAS200373 3xK Tech GmbH2026-09-031
216.26.252.128FRAS200373 3xK Tech GmbH2026-09-031
209.50.166.38USAS200373 3xK Tech GmbH2026-09-031
151.123.176.162FRAS200373 3xK Tech GmbH2026-09-031
104.207.54.50DEAS200373 3xK Tech GmbH2026-09-031
216.26.242.164BRAS200373 3xK Tech GmbH2026-09-031
104.207.48.141BRAS200373 3xK Tech GmbH2026-09-031
216.26.254.37FRAS200373 3xK Tech GmbH2026-09-031
209.50.173.165USAS200373 3xK Tech GmbH2026-09-031
104.207.46.177USAS200373 3xK Tech GmbH2026-09-031

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun080_0034003d_95095a1asame header set2 IPs1.4Kb11cdn100_0034003f_d1da082f1 header apart407 IPs1.1Kb11cun070_0034001d_7e8ea62d1 header apart2 IPs42b11cun090_0034003f_2b3ca27d1 header apart5 IPs9b11cun090_0034003f_f5e9688a1 header apart1 IPs2b11cun090_0034003f_eaca82e61 header apart2 IPs2b11cun060_0004003d_f55b17ef2 headers apart4 IPs126.2Kb11cun080_0034001f_ee1daacd2 headers apart762 IPs7.1K

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.