HoneyLabs

Akin HTTP request fingerprint

b11cun040_00040013_ab9bb075

Seen 2026-02-20 to 2026-10-01 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS213954 sends an email when it next hits a sensor.

61

Source IPs

7

Networks

3

Countries

109

Ports hit

549

Events

9

IPs / network

Top networks

Countries

US 56NL 3RO 2

Ports targeted

What it requests

GET/login179
GET/13

User agents claimed

Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36 Edg/115.0.1901.20361 IPs549
Source IPCCNetwork Last seenEvents
130.12.180.19NLAS202412 Omegatech LTD2026-09-27270
151.240.104.196USAS137409 GSL Networks Pty LTD2026-09-1748
45.142.193.149ROAS213388 Iic Rail Limited2026-09-2537
151.240.46.176USAS137409 GSL Networks Pty LTD2026-09-3032
151.240.46.221USAS137409 GSL Networks Pty LTD2026-09-2116
130.12.180.138NLAS202412 Omegatech LTD2026-09-2811
151.240.104.132USAS137409 GSL Networks Pty LTD2026-09-225
94.154.113.150USAS46475 Limestone Networks, Inc.2026-09-244
83.97.117.178USAS46475 Limestone Networks, Inc.2026-09-234
104.245.240.175USAS213954 Global Transit Systems LLC2026-09-294
104.245.241.220USAS213954 Global Transit Systems LLC2026-09-244
45.159.23.40USAS213954 Global Transit Systems LLC2026-09-304
45.147.11.70USAS213954 Global Transit Systems LLC2026-09-214
104.245.243.30USAS213954 Global Transit Systems LLC2026-10-014
212.87.216.186USAS26548 PureVoltage Hosting Inc.2026-10-014
104.245.242.201USAS213954 Global Transit Systems LLC2026-09-224
193.142.37.48USAS213954 Global Transit Systems LLC2026-09-234
45.142.193.239ROAS213388 Iic Rail Limited2026-09-284
188.119.190.247USAS212238 Datacamp Limited2026-09-113
151.240.105.74USAS137409 GSL Networks Pty LTD2026-09-152

Fingerprint family: 2 shapes, 61 IPs, 569 events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 4 headers, no body: connection, accept-encoding, user-agent, host

asks for/login · /remote/login · /RDWeb/Pages/ · /sslvpn_logon.shtml (GET)
asMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) and 1 more
ports443 · 6443 · 80 · 1701
fromNL · US · RO · UA · Omegatech LTD · GSL Networks Pty LTD · Global Transit Systems LLC
b11cun040_00040013_ab9bb075 this oneMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) · /login61 IPs549b11cun073_00040013_33fea7fc_x20d25858e64b+/- 20d2, 5858, e64b · Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) · /vpn/index.html4 IPs20

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun040_00040013_608dab68same header set4.3K IPs243.9Kb11cun040_00040013_7df024fesame header set2 IPs53b11cun040_00040013_2178e07esame header set16 IPs17b11cun040_00040013_89f46b26same header set4 IPs12b11cun040_00040013_6c646f8fsame header set5 IPs5b11cun030_00040012_13ee3d341 header apart5.1K IPs226.7Kb11cun050_00040017_976354f01 header apart1.3K IPs19.1Kb11cun030_00040011_c91eaf541 header apart589 IPs12.0K

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.