HoneyLabs

Akin HTTP request fingerprint

b11cun020_00040002_5ff1c0a9

Seen 2026-02-17 to 2026-09-30 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS37963 sends an email when it next hits a sensor.

131

Source IPs

14

Networks

9

Countries

867

Ports hit

1.6K

Events

9

IPs / network

Top networks

Countries

CN 92US 18NL 9GB 5DE 4CA 3RU 1BR 1UA 1

Ports targeted

What it requests

GET/356
GET/status21
Source IPCCNetwork Last seenEvents
193.24.211.52DEAS215929 Data Campus Limited2026-09-10733
176.120.22.240RUAS198953 Proton66 OOO2026-09-2481
158.94.210.5NLAS202412 Omegatech LTD2026-09-3070
178.16.53.3NLAS202412 Omegatech LTD2026-09-3064
94.154.35.25NLAS202412 Omegatech LTD2026-09-3062
207.90.244.14USAS174 Cogent Communications, LLC2026-09-2741
71.6.135.131USAS10439 CariNet, Inc.2026-09-2937
158.94.211.254NLAS202412 Omegatech LTD2026-09-0132
66.240.192.138USAS10439 CariNet, Inc.2026-09-2831
80.82.77.33NLAS202425 IP Volume inc2026-09-2928
86.54.31.40CAAS12989 Black HOST Ltd2026-09-2927
93.174.95.106NLAS202425 IP Volume inc2026-09-2825
91.92.243.147USAS202412 Omegatech LTD2026-09-1825
71.6.199.23USAS10439 CariNet, Inc.2026-09-2822
94.102.49.193NLAS202425 IP Volume inc2026-09-3022
80.82.77.139NLAS202425 IP Volume inc2026-09-2719
86.54.31.32GBAS12989 Black HOST Ltd2026-09-2517
86.54.31.34GBAS12989 Black HOST Ltd2026-09-2216
86.54.31.38GBAS12989 Black HOST Ltd2026-09-2215
89.248.167.131NLAS202425 IP Volume inc2026-09-1613

Fingerprint family: 2 shapes, 131 IPs, 3.0K events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 2 headers, no body: accept-encoding, host

asks for/remote/login?lang=en · / · /robots.txt · /.well-known/security.txt (GET / HEAD)
ports443 · 4443 · 8443 · 80
fromDE · NL · US · RU · Data Campus Limited · Omegatech LTD · CariNet, Inc.
b11cun020_00040002_5ff1c0a9 this one/remote/login?lang=en131 IPs1.6Kb11cun030_00040003_21fe282e+/- connection · /remote/login?lang=en17 IPs1.4K

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun020_00040002_d6a4d258same header set1 IPs82b11cun030_00040012_13ee3d341 header apart5.1K IPs225.9Kb11cun010_00040000_c4b2c4aa1 header apart647 IPs63.7Kb11cun030_00040012_f6d8d7971 header apart62 IPs2.5Kb10cun010_00040000_c4b2c4aa1 header apart365 IPs2.0Kb11cun030_00040003_21fe282e1 header apart17 IPs1.4Kb11cun030_00040012_a6735d471 header apart2 IPs504b11cun030_00040006_72e648081 header apart1 IPs156

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.