HoneyLabs

Akin HTTP request fingerprint

b11cun030_00040014_03330a18

Seen 2026-02-18 to 2026-10-01 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS396982 sends an email when it next hits a sensor.

3.9K

Source IPs

5

Networks

18

Countries

222

Ports hit

1.4M

Events

783

IPs / network

Top networks

AS396982 Google LLC3.9K IPs405.9K

Countries

US 1.7KBE 314JP 274TW 187CA 140GB 125BR 123NL 119ES 119CH 118

Ports targeted

What it requests

User agents claimed

Mozilla/5.0 (compatible; Rota/1.0)1 IPs1.0M
Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.362.0K IPs338.8K
crusader-worker/1.02.3K IPs67.1K
Mozilla/5.01 IPs100
Mozilla/5.0 (compatible; GitFinder/1.0)1 IPs2
Source IPCCNetwork Last seenEvents
46.151.178.11NLAS211443 Sino Worldwide Trading Limited2026-10-011.0M
34.93.32.208INAS396982 Google LLC2026-09-064.8K
35.189.7.56AUAS396982 Google LLC2026-09-064.1K
34.88.217.176FIAS396982 Google LLC2026-09-064.1K
34.153.223.172JPAS396982 Google LLC2026-09-063.2K
34.53.45.204USAS396982 Google LLC2026-09-063.2K
34.146.10.239JPAS396982 Google LLC2026-09-063.1K
34.39.208.120BRAS396982 Google LLC2026-09-063.1K
34.106.96.134USAS396982 Google LLC2026-09-063.0K
136.67.125.61USAS396982 Google LLC2026-09-062.9K
136.117.50.181USAS396982 Google LLC2026-09-062.9K
34.95.158.26BRAS396982 Google LLC2026-09-072.8K
34.116.85.1AUAS396982 Google LLC2026-09-062.8K
34.20.230.32USAS396982 Google LLC2026-09-062.7K
34.146.205.220JPAS396982 Google LLC2026-09-072.6K
34.81.25.124TWAS396982 Google LLC2026-09-062.6K
34.97.2.189JPAS396982 Google LLC2026-09-072.5K
34.21.205.165SGAS396982 Google LLC2026-09-062.5K
34.100.179.178INAS396982 Google LLC2026-09-062.5K
35.233.75.198BEAS396982 Google LLC2026-09-072.4K

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun030_00040014_54d07b6dsame header set3.7K IPs105.0Kb10cun030_00040014_54d07b6dsame header set53 IPs517b11cun030_00040014_0a773432same header set39 IPs39b10cun020_00000014_0a8d7f111 header apart2.0K IPs606.5Kb11cun040_00040016_aa48e2c81 header apart6.2K IPs529.5Kb11cun040_00040016_4110f1561 header apart288 IPs171.1Kb11cun040_00040015_4c87b06e1 header apart1.5K IPs152.7Kb11cun020_00040010_724c10fb1 header apart1.4K IPs70.5K

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.