HoneyLabs

Akin HTTP request fingerprint

b11cun020_00040004_0a8d7f11

Seen 2026-02-16 to 2026-10-01 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS4837 sends an email when it next hits a sensor.

3.9K

Source IPs

33

Networks

8

Countries

1.8K

Ports hit

8.7K

Events

119

IPs / network

Top networks

AS4134 Chinanet1.4K IPs1.6K

Countries

CN 3.8KHK 102US 5SG 1BG 1NZ 1SE 1KR 1

Ports targeted

What it requests

GET/8.4K
GET/v184
GET/state2
Source IPCCNetwork Last seenEvents
156.225.1.37HKAS9465 AGOTOZ PTE. LTD.2026-10-0154
152.32.254.132HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-3051
118.26.38.132HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-3051
156.225.1.45HKAS9465 AGOTOZ PTE. LTD.2026-10-0151
152.32.209.108HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-10-0150
156.225.1.39HKAS9465 AGOTOZ PTE. LTD.2026-10-0149
152.32.133.206HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-3047
156.225.1.105HKAS9465 AGOTOZ PTE. LTD.2026-10-0146
156.225.1.36HKAS9465 AGOTOZ PTE. LTD.2026-10-0144
123.58.209.194HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-10-0144
156.225.1.13HKAS9465 AGOTOZ PTE. LTD.2026-09-3044
101.36.116.230HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-10-0143
156.225.1.18HKAS9465 AGOTOZ PTE. LTD.2026-10-0143
128.1.132.17HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-3042
156.225.1.100HKAS9465 AGOTOZ PTE. LTD.2026-10-0142
118.193.45.220HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-10-0142
156.225.1.89HKAS9465 AGOTOZ PTE. LTD.2026-10-0142
156.225.1.30HKAS9465 AGOTOZ PTE. LTD.2026-10-0142
156.225.1.113HKAS9465 AGOTOZ PTE. LTD.2026-10-0142
156.225.1.47HKAS9465 AGOTOZ PTE. LTD.2026-09-3042

Fingerprint family: 2 shapes, 3.9K IPs, 8.8K events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 2 headers, no body: accept, host

asks for/ · /v1 · /system_stats · /version (GET)
ports443 · 9200 · 80 · 8080
fromCN · HK · US · SG · CHINA UNICOM China169 Backbone · AGOTOZ PTE. LTD. · UCLOUD INFORMATION TECHNOLOGY (HK) LIMIT
b11cun020_00040004_0a8d7f11 this one/3.9K IPs8.8Kb11cun030_00040005_9d74717e+/- connection · /api/v1/show_config8 IPs58

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b10cun020_00040004_be1ad017same header set9 IPs476b10cun020_00040004_1fdb23c0same header set393 IPs431b11cun020_00040004_1cae80d4same header set14 IPs94b10cun020_00040004_0a8d7f11same header set27 IPs28b11cun030_00040014_03330a181 header apart3.9K IPs1.4Mb11cun030_00040014_54d07b6d1 header apart3.7K IPs105.0Kb11cun010_00040000_c4b2c4aa1 header apart654 IPs64.5Kb10cun010_00040000_c4b2c4aa1 header apart365 IPs2.0K

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.