HoneyLabs

Akin HTTP request fingerprint

b11cun020_00040001_78f1f19c

Seen 2026-02-18 to 2026-09-30 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS25369 sends an email when it next hits a sensor.

49

Source IPs

23

Networks

14

Countries

105

Ports hit

3.3K

Events

2

IPs / network

Top networks

Countries

NL 8GB 8FR 7DE 5RU 4PA 4US 3SG 3SC 2BG 1

Ports targeted

What it requests

GET/155
GET/app6
Source IPCCNetwork Last seenEvents
93.123.109.214BGAS48090 Techoff Srv Limited2026-09-302.6K
2.57.121.203ROAS47890 Unmanaged Ltd2026-09-30387
37.77.150.72RUAS198953 Proton66 OOO2026-09-2484
45.227.253.154PAAS209272 Alviva Holding Limited2026-09-2337
193.24.123.108RUAS200593 Prospero Ooo2026-09-2632
176.120.22.43RUAS198953 Proton66 OOO2026-09-1930
45.198.224.59USAS215925 Vpsvault.host Ltd2026-09-2818
160.119.76.137SCAS49870 Alsycon B.V.2026-09-1316
45.227.253.156PAAS209272 Alviva Holding Limited2026-09-2313
130.12.180.127NLAS202412 Omegatech LTD2026-09-179
172.104.190.164SGAS63949 Akamai Connected Cloud2026-09-119
190.159.36.43COAS14080 Telmex Colombia S.A.2026-09-209
64.62.194.197USAS6939 Hurricane Electric LLC2026-09-078
85.11.167.132NLAS197170 TechTies Inc.2026-09-117
94.154.43.222NLAS0 2026-09-247
45.227.253.150PAAS209272 Alviva Holding Limited2026-09-296
188.186.183.82RUAS41682 JSC ER-Telecom Holding2026-09-145
132.243.160.36FRAS219359 Edge Core FZE2026-09-045
66.179.31.143SGAS399629 BL Networks2026-09-224
69.48.229.164SGAS399629 BL Networks2026-09-224

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b10cun020_00040001_78f1f19csame header set604 IPs2.9Kb11cun020_00040001_4e1a3733same header set11 IPs186b11cun010_00040000_c4b2c4aa1 header apart647 IPs63.7Kb11cun030_00040011_c91eaf541 header apart547 IPs12.1Kb10cun010_00040000_c4b2c4aa1 header apart365 IPs2.0Kb11cun030_00040003_21fe282e1 header apart17 IPs1.4Kb11cun031_00040001_c91eaf54_x74db1 header apart1 IPs402b10cun030_00040011_c91eaf541 header apart14 IPs111

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.