HoneyLabs

Akin HTTP request fingerprint

b11cun030_00040011_c91eaf54

Seen 2026-02-16 to 2026-10-01 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS14061 sends an email when it next hits a sensor.

592

Source IPs

62

Networks

47

Countries

726

Ports hit

12.0K

Events

10

IPs / network

Top networks

Countries

DE 173US 110BE 78CN 73SG 53NL 21GB 12BR 7RU 6CA 6

Ports targeted

What it requests

GET/1.9K
GET/settings820
GET/HNAP1249

User agents claimed

Go-http-client/1.1204 IPs7.1K
Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)42 IPs2.1K
Mozilla/5.020 IPs925
proxy-prefilter/15 IPs379
Mozilla/5.0 (compatible)72 IPs360
Source IPCCNetwork Last seenEvents
94.154.43.203NLAS219502 Storm Industries LLC2026-09-29642
130.12.180.42NLAS202412 Omegatech LTD2026-09-29465
94.154.43.163NLAS219502 Storm Industries LLC2026-09-27336
137.184.68.95USAS14061 DigitalOcean, LLC2026-09-10207
134.209.78.7USAS14061 DigitalOcean, LLC2026-09-13193
159.223.134.160USAS14061 DigitalOcean, LLC2026-09-07186
167.99.149.178USAS14061 DigitalOcean, LLC2026-09-13185
142.93.255.243USAS14061 DigitalOcean, LLC2026-09-16183
167.172.132.204USAS14061 DigitalOcean, LLC2026-09-07182
147.182.162.208USAS14061 DigitalOcean, LLC2026-09-16181
178.128.144.168USAS14061 DigitalOcean, LLC2026-09-30176
104.248.225.113USAS14061 DigitalOcean, LLC2026-09-30173
68.183.126.140USAS14061 DigitalOcean, LLC2026-09-10172
157.230.181.63USAS14061 DigitalOcean, LLC2026-09-30171
137.184.218.48USAS14061 DigitalOcean, LLC2026-09-16167
147.182.143.140USAS14061 DigitalOcean, LLC2026-09-07167
157.245.131.187USAS14061 DigitalOcean, LLC2026-09-10165
68.183.112.48USAS14061 DigitalOcean, LLC2026-09-13162
137.184.138.198USAS14061 DigitalOcean, LLC2026-09-20149
112.124.56.253CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-11147

Fingerprint family: 2 shapes, 591 IPs, 12.2K events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 3 headers, no body: connection, user-agent, host

asks for/ · /solr/admin/cores?action=STATUS&wt=json · /solr/admin/info/system · /query?q=SHOW+DIAGNOSTICS (GET / OPTIONS)
asGo-http-client/1.1 · Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html) · Mozilla/5.0 and 46 more
ports443 · 80 · 1880 · 8080
fromUS · CN · DE · NL · DigitalOcean, LLC · Hangzhou Alibaba Advertising Co.,Ltd. · Storm Industries LLC
b11cun030_00040011_c91eaf54 this oneGo-http-client/1.1 · /591 IPs12.0Kb11cun084_40040011_966c00f7_x12be9f62a4acfdb1+/- upgrade, sec-websocket-extensions, sec-websocket-key, sec-websocket-protocol, sec-websocket-version · CryptoHunter-Vite-2026/1.0 · /2 IPs216

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b10cun030_00040011_c91eaf54same header set14 IPs113b11cun030_00040011_213543bfsame header set10 IPs79b11cun030_00040011_07783b5dsame header set2 IPs5b11cun040_00040013_608dab681 header apart4.3K IPs243.9Kb11cun040_00040015_4c87b06e1 header apart1.5K IPs152.7Kb11cun020_00040010_724c10fb1 header apart1.4K IPs70.5Kb11cuq040_00040811_2daa70d61 header apart248 IPs6.3Kb11cun020_00040001_78f1f19c1 header apart45 IPs4.6K

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.