HoneyLabs

Akin HTTP request fingerprint

b11cun040_00040015_f0265a0e

Seen 2026-02-18 to 2026-09-30 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS9541 sends an email when it next hits a sensor.

34

Source IPs

15

Networks

7

Countries

2

Ports hit

34

Events

2

IPs / network

Top networks

Countries

PK 19CN 6PH 3IN 2AR 2JP 1FR 1

Ports targeted

What it requests

User agents claimed

Hello, world33 IPs33
r00ts3c-owned-you1 IPs1
Source IPCCNetwork Last seenEvents
153.117.28.89PKAS9541 Cyber Internet Services (Pvt) Ltd.2026-09-271
72.255.17.38PKAS9541 Cyber Internet Services (Pvt) Ltd.2026-09-041
36.255.33.164PKAS9541 Cyber Internet Services (Pvt) Ltd.2026-09-301
222.127.55.224PHAS132199 Globe Telecom Inc.2026-09-161
124.29.194.194PKAS9541 Cyber Internet Services (Pvt) Ltd.2026-09-241
223.123.43.7PKAS138423 CMPak Limited2026-09-041
27.222.48.192CNAS4837 CHINA UNICOM China169 Backbone2026-09-061
139.135.46.126PKAS9541 Cyber Internet Services (Pvt) Ltd.2026-09-021
123.185.245.118CNAS134762 CHINANET Liaoning province Dalian MAN network2026-09-161
103.176.16.40INAS135687 Qwistel Network Service Private Limited2026-09-041
120.28.196.74PHAS132199 Globe Telecom Inc.2026-09-291
61.53.116.232CNAS4837 CHINA UNICOM China169 Backbone2026-09-281
59.180.128.31INAS17813 Mahanagar Telephone Nigam Limited2026-09-071
190.196.253.76ARAS266702 MEGALINK S.R.L.2026-09-091
203.101.186.93PKAS9541 Cyber Internet Services (Pvt) Ltd.2026-09-211
72.255.59.61PKAS9541 Cyber Internet Services (Pvt) Ltd.2026-09-011
175.107.1.182PKAS23888 National Telecommunication Corporation HQ,2026-09-101
190.196.253.29ARAS266702 MEGALINK S.R.L.2026-09-081
101.53.225.68PKAS9541 Cyber Internet Services (Pvt) Ltd.2026-09-101
223.74.83.101CNAS9808 China Mobile Communications Group Co., Ltd.2026-09-251

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun040_00040015_4c87b06esame header set1.5K IPs159.7Kb11cun040_00040015_00b09b79same header set4 IPs2.9Kb10cun040_00040015_4c87b06esame header set16 IPs1.4Kb11cun040_00040015_a4cdfabfsame header set34 IPs580b11cun040_00040015_5cd6f744same header set1 IPs336b11cun040_00040015_ba182931same header set6 IPs152b11cun040_00040015_d76a48e1same header set3 IPs105b11cun040_00040015_b03a935bsame header set3 IPs78

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.