HoneyLabs

Akin HTTP request fingerprint

b11cun030_00040012_13ee3d34

Seen 2026-02-16 to 2026-10-01 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS396982 sends an email when it next hits a sensor.

5.1K

Source IPs

99

Networks

40

Countries

5.2K

Ports hit

226.7K

Events

51

IPs / network

Top networks

AS396982 Google LLC3.6K IPs202.1K

Countries

US 2.3KBE 1.7KGB 504SG 241DE 129HK 107SC 76NL 34TR 7TW 5

Ports targeted

What it requests

GET/208.9K
GET/login709
GET/hms/37
GET/hotel/37
GET/admin/37
GET/ucp/37

User agents claimed

Hello from Palo Alto Networks, find out more about our scans in https://docs-cortex.paloaltonetworks.com/r/1/Cortex-Xpanse/Scanning-activity2.0K IPs199.2K
Go-http-client/1.1213 IPs3.1K
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36479 IPs2.9K
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/137.0.0.0 Safari/537.36531 IPs2.7K
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.361.7K IPs2.6K
Source IPCCNetwork Last seenEvents
38.127.51.32USAS18978 Enzu Inc2026-09-121.2K
45.67.211.147USAS199524 G-Core Labs S.A.2026-09-131.2K
193.169.239.152NLAS199524 G-Core Labs S.A.2026-09-151.2K
100.57.164.102USAS14618 Amazon.com, Inc.2026-09-15592
168.119.191.98DEAS24940 Hetzner Online GmbH2026-09-17592
188.34.154.227DEAS24940 Hetzner Online GmbH2026-09-17591
3.228.14.80USAS14618 Amazon.com, Inc.2026-09-15591
46.62.170.251FIAS24940 Hetzner Online GmbH2026-09-17590
34.204.194.129USAS14618 Amazon.com, Inc.2026-09-17590
5.252.26.87DEAS199524 G-Core Labs S.A.2026-09-15590
32.195.59.163USAS14618 Amazon.com, Inc.2026-09-15590
3.236.168.75USAS14618 Amazon.com, Inc.2026-09-16589
3.238.56.206USAS14618 Amazon.com, Inc.2026-09-15588
45.82.78.100DEAS212512 Detai Prosperous Technologies Limited2026-10-01569
45.82.78.108DEAS212512 Detai Prosperous Technologies Limited2026-10-01560
45.82.78.105DEAS212512 Detai Prosperous Technologies Limited2026-10-01560
45.82.78.104DEAS212512 Detai Prosperous Technologies Limited2026-10-01542
45.82.78.107DEAS212512 Detai Prosperous Technologies Limited2026-10-01538
45.82.78.102DEAS212512 Detai Prosperous Technologies Limited2026-10-01530
45.82.78.106DEAS212512 Detai Prosperous Technologies Limited2026-10-01518

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun030_00040012_f6d8d797same header set64 IPs2.5Kb11cun030_00040012_a6735d47same header set2 IPs504b11cun040_00040016_aa48e2c81 header apart6.2K IPs530.0Kb11cun040_00040013_608dab681 header apart4.3K IPs243.9Kb11cun040_00040016_4110f1561 header apart288 IPs170.8Kb11cun020_00040010_724c10fb1 header apart1.4K IPs70.5Kb11cun040_00040016_9e0aeda71 header apart50 IPs8.4Kb11cun040_00040016_c1d300831 header apart49 IPs6.4K

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.