HoneyLabs

Akin HTTP request fingerprint

b11cun040_00040013_608dab68

Seen 2026-09-30 to 2026-09-30 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS398324 sends an email when it next hits a sensor.

166

Source IPs

16

Networks

16

Countries

249

Ports hit

799

Events

10

IPs / network

Top networks

Countries

US 114HK 13DE 8JP 7TH 4NL 3RU 3MY 3SC 2SG 2

Ports targeted

What it requests

GET/82
GET/aab910
GET/aaa910
GET/login6

User agents claimed

Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/)88 IPs511
Go-http-client/1.133 IPs133
curl/7.74.032 IPs32
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.77 Safari/537.366 IPs20
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/50.0.2661.102 Safari/537.364 IPs4
Source IPCCNetwork Last seenEvents
93.123.109.214BGAS48090 Techoff Srv Limited2026-09-3057
167.94.146.53USAS398705 Censys, Inc.2026-09-3027
167.94.146.55USAS398705 Censys, Inc.2026-09-3027
167.94.146.63USAS398705 Censys, Inc.2026-09-3027
167.94.146.52USAS398705 Censys, Inc.2026-09-3024
167.94.146.48USAS398705 Censys, Inc.2026-09-3021
167.94.146.50USAS398705 Censys, Inc.2026-09-3021
167.94.146.62USAS398705 Censys, Inc.2026-09-3018
167.94.146.54USAS398705 Censys, Inc.2026-09-3018
167.94.146.57USAS398705 Censys, Inc.2026-09-3018
167.94.146.49USAS398705 Censys, Inc.2026-09-3018
95.214.53.196PLAS201814 MEVSPACE sp. z o.o.2026-09-3012
165.154.120.89THAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-3012
167.94.146.51USAS398705 Censys, Inc.2026-09-3012
152.32.170.230HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-3012
167.94.146.56USAS398705 Censys, Inc.2026-09-309
167.94.146.59USAS398705 Censys, Inc.2026-09-309
66.132.172.196USAS398324 Censys, Inc.2026-09-309
167.94.146.60USAS398705 Censys, Inc.2026-09-309
167.94.146.61USAS398705 Censys, Inc.2026-09-309

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun040_00040013_2178e07esame header set1 IPs1b11cun040_00040013_7df024fesame header set1 IPs1b11cun030_00040012_13ee3d341 header apart122 IPs149b11cun030_00040012_a6735d471 header apart1 IPs126b11cun050_00040017_976354f01 header apart23 IPs45b11cun050_00040017_6b90553b1 header apart19 IPs33b11cun030_00040011_c91eaf541 header apart9 IPs23b11cun050_00040017_ee17dab11 header apart3 IPs20

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.