HoneyLabs

Akin HTTP request fingerprint

b11cun040_00040016_50f90888

Seen 2026-02-17 to 2026-10-01 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS6939 sends an email when it next hits a sensor.

69

Source IPs

12

Networks

10

Countries

25

Ports hit

1.3K

Events

6

IPs / network

Top networks

Countries

US 53DE 6BG 2NL 2CY 1MD 1ES 1TR 1SG 1BR 1

Ports targeted

What it requests

GET/133
GET/login21
GET/api/14
GET/status14
GET/health10

User agents claimed

Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.366 IPs1.0K
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.3651 IPs102
Go-http-client/1.14 IPs67
tiagoscan (+mailto:scarf-snort-entree@duck.com)6 IPs42
curl/8.4.01 IPs8
Source IPCCNetwork Last seenEvents
185.141.60.128BGAS44901 Belcloud LTD2026-09-23296
185.141.63.27CYAS44901 Belcloud LTD2026-09-29152
154.44.186.37ESAS214036 Ultahost, Inc.2026-09-24152
143.246.221.223MDAS200019 Alexhost Srl2026-09-24152
72.240.2.223USAS13490 Buckeye Cablevision, Inc.2026-09-30152
185.141.60.161BGAS44901 Belcloud LTD2026-09-24151
94.154.43.7NLAS219502 Storm Industries LLC2026-09-3054
204.76.203.31NLAS51396 Pfcloud UG (haftungsbeschrankt)2026-09-2815
104.28.207.220DEAS13335 Cloudflare, Inc.2026-09-3013
104.28.239.219DEAS13335 Cloudflare, Inc.2026-09-278
104.28.207.219DEAS13335 Cloudflare, Inc.2026-09-308
104.28.207.218DEAS13335 Cloudflare, Inc.2026-09-307
65.49.1.202USAS6939 Hurricane Electric LLC2026-09-306
65.49.1.94USAS6939 Hurricane Electric LLC2026-10-016
64.62.156.10USAS6939 Hurricane Electric LLC2026-09-145
216.218.206.66USAS6939 Hurricane Electric LLC2026-09-254
88.230.64.245TRAS9121 Turk Telekom2026-09-184
184.105.139.70USAS6939 Hurricane Electric LLC2026-10-014
104.28.239.218DEAS13335 Cloudflare, Inc.2026-09-304
64.62.156.142USAS6939 Hurricane Electric LLC2026-09-283

Fingerprint family: 4 shapes, 6.2K IPs, 530.4K events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 4 headers, no body: accept-encoding, accept, user-agent, host

asks for/ · /squid-internal-mgr/cachemgr.cgi · /favicon.ico · /login (GET / OPTIONS)
asMozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/) · Mozilla/5.0 zgrab/0.x · visionheight.com/scan Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) Chrome/126 and 491 more
ports443 · 80 · 8443 · 8080
fromUS · IN · CA · GB · Censys, Inc. · Hurricane Electric LLC · DigitalOcean, LLC
b11cun040_00040016_aa48e2c8Mozilla/5.0 (compatible; CensysInspect/1.1; +https://about.censys.io/) · /6.2K IPs529.0Kb11cun040_00040016_50f90888 this oneMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) · /69 IPs1.3Kb11cun030_00000016_6396c54d+/- host · NTRIP · /58 IPs119b11cuk105_00050016_5ccac048_x038e8e84d668e7f3ed80+/- content-type, next-action, next-router-state-tree, transfer-encoding, x-nextjs-html-request-id, x-nextjs-request-id · Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chro · /27 IPs34

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun040_00040016_aa48e2c8same header set6.2K IPs529.0Kb11cun040_00040016_4110f156same header set289 IPs170.9Kb11cun040_00040016_9e0aeda7same header set50 IPs8.4Kb11cun040_00040016_c1d30083same header set49 IPs6.4Kb11cun040_00040016_f36dd82esame header set9 IPs5.6Kb11cun040_00040016_c5bb04c5same header set68 IPs3.6Kb11cun040_00040016_fb523147same header set46 IPs3.2Kb11cun040_00040016_1d05953dsame header set11 IPs1.6K

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.