HoneyLabs

Akin HTTP request fingerprint

b11cun000_00000000_334359b9

Seen 2026-02-17 to 2026-10-06 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS9808 sends an email when it next hits a sensor.

75

Source IPs

28

Networks

20

Countries

37

Ports hit

1.4K

Events

3

IPs / network

Top networks

Countries

CN 18US 17NL 10KR 8RU 3IT 2BR 2IN 2DE 2ES 1

Ports targeted

What it requests

GET/version1.1K
GET/200
GET/?CAVIT23
GET/V9xU1
GET/5Iks1
GET/GIbj1
GET/VRZZ1
GET/HiN]1
GET/gTl51
Source IPCCNetwork Last seenEvents
172.233.62.80NLAS63949 Akamai Connected Cloud2026-09-21152
172.233.117.214ESAS63949 Akamai Connected Cloud2026-09-21138
172.232.221.148ITAS63949 Akamai Connected Cloud2026-09-21133
45.79.190.133USAS63949 Akamai Connected Cloud2026-09-21131
192.53.121.87CAAS63949 Akamai Connected Cloud2026-09-21130
172.233.26.186BRAS63949 Akamai Connected Cloud2026-09-21117
194.195.252.210AUAS63949 Akamai Connected Cloud2026-09-21116
172.232.160.26USAS63949 Akamai Connected Cloud2026-09-21109
172.105.56.8INAS63949 Akamai Connected Cloud2026-09-21100
185.189.182.234NLAS215747 NubaCloud B.V.2026-10-0679
45.91.64.6RUAS214664 JSC F62026-10-0635
114.55.232.178CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-2324
209.99.187.232CHAS402253 SKN Subnet & Telecom Ltd2026-10-0613
45.91.64.10RUAS214664 JSC F62026-10-0612
183.249.208.27CNAS56041 China Mobile communications corporation2026-09-2110
89.248.172.33NLAS202425 IP Volume inc2026-10-056
80.82.77.202NLAS202425 IP Volume inc2026-09-225
94.154.43.28NLAS219502 Storm Industries LLC2026-09-285
85.11.167.199NLAS197170 TechTies Inc.2026-09-104
176.65.139.135DEAS219502 Storm Industries LLC2026-10-023

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b10cun000_00000000_334359b9same header set2.2K IPs23.2Kb11cun010_00040000_c4b2c4aa1 header apart672 IPs70.8Kb10cun010_00040000_c4b2c4aa1 header apart392 IPs2.3Kb10cun010_00000004_a37af9cb1 header apart9 IPs663b10cun010_00000010_c4b2c4aa1 header apart3 IPs10b10cun020_00000014_0a8d7f112 headers apart2.0K IPs566.4Kb11cun020_00040010_724c10fb2 headers apart1.5K IPs68.9Kb11cun020_00040001_78f1f19c2 headers apart41 IPs11.6K

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.