HoneyLabs

Akin HTTP request fingerprint

b11cun020_00000014_0a8d7f11

Seen 2026-02-16 to 2026-09-29 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS396982 sends an email when it next hits a sensor.

139

Source IPs

9

Networks

3

Countries

4

Ports hit

161

Events

15

IPs / network

Top networks

Countries

US 99HK 28CN 12

Ports targeted

What it requests

GET/_config110
GET/51

User agents claimed

Hello from Palo Alto Networks, find out more about our scans in https://docs-cortex.paloaltonetworks.com/r/1/Cortex-Xpanse/Scanning-activity96 IPs110
NTRIP GNSSInternetRadio43 IPs51
Source IPCCNetwork Last seenEvents
205.210.31.215USAS396982 Google LLC2026-09-254
118.193.45.220HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-022
205.210.31.82USAS396982 Google LLC2026-09-102
156.225.1.33HKAS9465 AGOTOZ PTE. LTD.2026-09-022
147.185.132.48USAS396982 Google LLC2026-09-122
156.225.1.39HKAS9465 AGOTOZ PTE. LTD.2026-09-122
156.225.1.30HKAS9465 AGOTOZ PTE. LTD.2026-09-032
205.210.31.237USAS396982 Google LLC2026-09-292
198.235.24.240USAS396982 Google LLC2026-09-242
118.26.38.132HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-192
147.185.132.159USAS396982 Google LLC2026-09-172
156.225.1.37HKAS9465 AGOTOZ PTE. LTD.2026-09-212
198.235.24.104USAS396982 Google LLC2026-09-292
156.225.1.31HKAS9465 AGOTOZ PTE. LTD.2026-09-212
205.210.31.108USAS396982 Google LLC2026-09-162
147.185.132.150USAS396982 Google LLC2026-09-182
205.210.31.56USAS396982 Google LLC2026-09-202
198.235.24.51USAS396982 Google LLC2026-09-282
156.225.1.96HKAS9465 AGOTOZ PTE. LTD.2026-09-212
147.185.132.75USAS396982 Google LLC2026-09-082

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b10cun020_00000014_0a8d7f11same header set2.0K IPs617.5Kb11cun030_00040014_03330a181 header apart3.9K IPs1.4Mb11cun030_00040014_54d07b6d1 header apart3.7K IPs135.9Kb10cun010_00000004_a37af9cb1 header apart9 IPs622b10cun030_00040014_54d07b6d1 header apart53 IPs528b11cun030_00000016_6396c54d1 header apart59 IPs118b11cun030_00040014_e29c64ac1 header apart1 IPs80b11cun030_00040014_a626bc271 header apart1 IPs66

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.