HoneyLabs

Akin HTTP request fingerprint

b11cun030_00050004_54d07b6d

Seen 2026-02-20 to 2026-09-17 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS4808 sends an email when it next hits a sensor.

2

Source IPs

1

Networks

1

Countries

1

Ports hit

2

Events

2

IPs / network

Top networks

Countries

CN 2

Ports targeted

What it requests

Source IPCCNetwork Last seenEvents
106.75.10.60CNAS4808 China Unicom Beijing Province Network2026-09-121
106.75.9.126CNAS4808 China Unicom Beijing Province Network2026-09-171

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun020_00040004_0a8d7f111 header apart3.9K IPs8.8Kb10cun020_00040004_be1ad0171 header apart9 IPs479b10cun020_00040004_1fdb23c01 header apart391 IPs428b11cun020_00040004_1cae80d41 header apart14 IPs94b10cun020_00040004_0a8d7f111 header apart26 IPs27b10cuq040_00050804_6e8c246c1 header apart7 IPs7b11cun030_00040014_03330a182 headers apart3.9K IPs1.4Mb11cun030_00040014_54d07b6d2 headers apart3.7K IPs105.0K

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.