Akin HTTP request fingerprint
b11cuk105_00050016_5ccac048_x038e8e84d668e7f3ed80
Seen 2026-02-20 to 2026-10-01 across the retained window.
The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS6939 sends an email when it next hits a sensor.
27
Source IPs
1
Networks
1
Countries
28
Ports hit
34
Events
27
IPs / network
This fingerprint is concentrated: many addresses on very few networks, which is what a single coordinated operation tends to look like.
Top networks
Countries
What it requests
User agents claimed
Fingerprint family: 4 shapes, 6.2K IPs, 531.0K events in 30 days
Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.
HTTP/1.1, 4 headers, no body: accept-encoding, accept, user-agent, host
Related fingerprints
No other fingerprint seen in the last 30 days is within two headers of this one.
About this fingerprint
Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.