HoneyLabs

Akin HTTP request fingerprint

b11cun031_00040010_e62b6d85_xe394

Seen 2026-07-07 to 2026-09-30 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS207043 sends an email when it next hits a sensor.

2

Source IPs

1

Networks

1

Countries

218

Ports hit

478

Events

2

IPs / network

Top networks

Countries

DE 2

Ports targeted

What it requests

GET/dana-na478

User agents claimed

ncsrv2 IPs478
Source IPCCNetwork Last seenEvents
94.26.83.79DEAS207043 Dedik Services Limited2026-09-30242
91.92.43.222DEAS207043 Dedik Services Limited2026-09-23236

Fingerprint family: 3 shapes, 1.4K IPs, 68.3K events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 2 headers, no body: user-agent, host

asks for/.well-known/security.txt · / · http://api.ipify.org/?format=json · /my.policy (GET / HEAD)
asHello from Palo Alto Networks, find out more about our scans in https://docs-cor · Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) · what-vpn-go/0.1 and 225 more
ports443 · 80 · 8000 · 8888
fromNL · US · GB · DE · Google LLC · Omegatech LTD · Hurricane Electric LLC
b11cun020_00040010_724c10fbHello from Palo Alto Networks, find out more about our scans in https://docs-cor · /.well-known/security.txt1.4K IPs67.3Kb11cun063_08040010_f2f3ae25_x543371d48ba3+/- cookie, 5433, 71d4, 8ba3 · what-vpn-go/0.1 · /sslvpnclient?launchplatform=mac&neProto=3&supportipv6=yes2 IPs479b11cun031_00040010_e62b6d85_xe394 this one+/- e394 · ncsrv · /dana-na2 IPs478

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun020_00040010_724c10fb1 header apart1.4K IPs67.3Kb10cun020_00040010_724c10fb1 header apart14 IPs1.9Kb11cun030_00040014_03330a182 headers apart3.9K IPs1.4Mb11cun030_00040012_13ee3d342 headers apart5.1K IPs227.8Kb11cun030_00040014_54d07b6d2 headers apart3.7K IPs105.3Kb11cun010_00040000_c4b2c4aa2 headers apart655 IPs65.6Kb11cun030_00040011_c91eaf542 headers apart591 IPs12.3Kb11cun030_00040018_f74a6e722 headers apart564 IPs8.0K

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.