HoneyLabs

Akin HTTP request fingerprint

b11cun020_00040010_724c10fb

Seen 2026-02-16 to 2026-10-01 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS396982 sends an email when it next hits a sensor.

1.4K

Source IPs

47

Networks

24

Countries

3.7K

Ports hit

70.5K

Events

30

IPs / network

Top networks

Countries

US 1.2KGB 109NL 22JP 7DE 6CN 6RU 4CH 4PL 3MX 3

Ports targeted

What it requests

GET/3.0K
HEAD/_ping40
GET/.env37

User agents claimed

Hello from Palo Alto Networks, find out more about our scans in https://docs-cortex.paloaltonetworks.com/r/1/Cortex-Xpanse/Scanning-activity672 IPs35.7K
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.3610 IPs26.2K
what-vpn-go/0.12 IPs1.9K
fasthttp9 IPs1.7K
Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:47.0) Gecko/20100101 Firefox/47.01 IPs961
Source IPCCNetwork Last seenEvents
130.12.180.77NLAS202412 Omegatech LTD2026-09-1126.2K
45.148.10.95NLAS48090 Techoff Srv Limited2026-09-28969
94.26.83.79DEAS207043 Dedik Services Limited2026-09-30968
91.92.43.222DEAS207043 Dedik Services Limited2026-09-23944
35.203.210.12GBAS396982 Google LLC2026-09-27522
35.203.210.97GBAS396982 Google LLC2026-09-06449
162.216.150.16USAS396982 Google LLC2026-09-20449
162.216.149.42USAS396982 Google LLC2026-09-27438
147.185.133.201USAS396982 Google LLC2026-09-13431
35.203.210.6GBAS396982 Google LLC2026-09-06421
147.185.132.238USAS396982 Google LLC2026-09-13412
162.216.150.126USAS396982 Google LLC2026-09-27403
35.203.210.11GBAS396982 Google LLC2026-09-13403
45.91.64.6RUAS214664 JSC F62026-10-01394
80.82.77.202NLAS202425 IP Volume inc2026-10-01379
162.216.150.105USAS396982 Google LLC2026-09-06361
162.216.149.105USAS396982 Google LLC2026-09-13352
35.203.210.116GBAS396982 Google LLC2026-09-27347
162.216.149.252USAS396982 Google LLC2026-09-20313
35.203.211.74GBAS396982 Google LLC2026-09-27303

Fingerprint family: 3 shapes, 1.4K IPs, 71.5K events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 2 headers, no body: user-agent, host

asks for/.well-known/security.txt · / · http://api.ipify.org/?format=json · /my.policy (GET / HEAD)
asHello from Palo Alto Networks, find out more about our scans in https://docs-cor · Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) · what-vpn-go/0.1 and 224 more
ports443 · 4443 · 80 · 8000
fromNL · US · GB · DE · Google LLC · Omegatech LTD · Hurricane Electric LLC
b11cun020_00040010_724c10fb this oneHello from Palo Alto Networks, find out more about our scans in https://docs-cor · /.well-known/security.txt1.4K IPs70.5Kb11cun031_00040010_e62b6d85_xe394+/- e394 · ncsrv · /dana-na2 IPs478b11cun063_08040010_f2f3ae25_x543371d48ba3+/- cookie, 5433, 71d4, 8ba3 · what-vpn-go/0.1 · /sslvpnclient?launchplatform=mac&neProto=3&supportipv6=yes2 IPs478

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b10cun020_00040010_724c10fbsame header set14 IPs1.9Kb11cun030_00040014_03330a181 header apart3.9K IPs1.4Mb11cun030_00040012_13ee3d341 header apart5.1K IPs226.9Kb11cun030_00040014_54d07b6d1 header apart3.7K IPs105.0Kb11cun010_00040000_c4b2c4aa1 header apart655 IPs64.9Kb11cun030_00040011_c91eaf541 header apart593 IPs11.9Kb11cun030_00040018_f74a6e721 header apart564 IPs8.5Kb11cun030_00040012_f6d8d7971 header apart66 IPs2.6K

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.