HoneyLabs

Akin HTTP request fingerprint

b11cun040_00040015_4c87b06e

Seen 2026-02-19 to 2026-10-01 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS25369 sends an email when it next hits a sensor.

1.5K

Source IPs

49

Networks

20

Countries

18.9K

Ports hit

152.9K

Events

31

IPs / network

Top networks

Countries

GB 623DE 321NL 253US 212BR 77AE 47IN 4CH 4SC 4HK 3

Ports targeted

What it requests

GET/37.6K
GET/get_info1.9K
GET/Dr0v110
GET/.env24

User agents claimed

CryptoHunter-Vite-2026/1.03 IPs104.2K
curl/7.61.1114 IPs16.5K
Mozilla/5.0 (compatible; Infrawatch/1.0; +https://infrawat.ch/)1.2K IPs14.0K
Mozilla/5.0 (compatible; FlowIQ/1.0; +https://flowiq-labs.com/scanning-info)146 IPs9.7K
Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:146.0) Gecko/20100101 Firefox/146.02 IPs4.7K
Source IPCCNetwork Last seenEvents
64.34.80.225USAS396356 Latitude.sh2026-09-2668.1K
64.34.81.199USAS396356 Latitude.sh2026-09-2035.9K
192.161.49.2USAS23273 HostPapa2026-10-014.6K
151.243.11.196AEAS209630 LLC Vash Kredit Bank2026-09-291.6K
151.243.11.180AEAS209630 LLC Vash Kredit Bank2026-09-291.4K
16.5.0.244USAS401661 EMBNEX, LLC2026-09-091.1K
16.5.0.254USAS401661 EMBNEX, LLC2026-09-26457
16.5.0.245USAS401661 EMBNEX, LLC2026-09-09416
45.205.1.241BRAS215925 Vpsvault.host Ltd2026-09-08393
151.243.11.152AEAS209630 LLC Vash Kredit Bank2026-09-30387
45.205.1.245BRAS215925 Vpsvault.host Ltd2026-09-08381
45.205.1.247BRAS215925 Vpsvault.host Ltd2026-09-08377
45.205.1.246BRAS215925 Vpsvault.host Ltd2026-09-08372
45.205.1.240BRAS215925 Vpsvault.host Ltd2026-09-08358
45.205.1.243BRAS215925 Vpsvault.host Ltd2026-09-08357
45.205.1.242BRAS215925 Vpsvault.host Ltd2026-09-08353
16.5.0.241BRAS401661 EMBNEX, LLC2026-09-25347
16.5.0.239BRAS401661 EMBNEX, LLC2026-09-25343
16.5.0.238BRAS401661 EMBNEX, LLC2026-09-25322
45.205.1.244BRAS215925 Vpsvault.host Ltd2026-09-08308

Fingerprint family: 2 shapes, 1.5K IPs, 153.0K events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 4 headers, no body: connection, accept, user-agent, host

asks for/ · /..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd · /favicon.ico · /get_info (GET / HEAD)
asCryptoHunter-Vite-2026/1.0 · curl/7.61.1 · Mozilla/5.0 (compatible; Infrawatch/1.0; +https://infrawat.ch/) and 38 more
ports5173 · 443 · 4173 · 8000
fromUS · DE · GB · BR · Latitude.sh · Rethem Hosting LLC · Hydra Communications Ltd
b11cun040_00040015_4c87b06e this oneCryptoHunter-Vite-2026/1.0 · /1.5K IPs153.0Kb11cun050_10040015_df66fe0f+/- origin · CryptoHunter-Vite-2026/1.0 · /__optate/source?file=/tmp/miner-nx-probe2 IPs16

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun040_00040015_00b09b79same header set4 IPs3.0Kb10cun040_00040015_4c87b06esame header set16 IPs1.4Kb11cun040_00040015_a4cdfabfsame header set31 IPs583b11cun040_00040015_5cd6f744same header set2 IPs340b11cun040_00040015_ba182931same header set6 IPs152b11cun040_00040015_d76a48e1same header set3 IPs104b11cun040_00040015_b03a935bsame header set3 IPs64b11cun040_00040015_f0265a0esame header set34 IPs34

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.