HoneyLabs

Akin HTTP request fingerprint

b11cun040_00040016_c5bb04c5

Seen 2026-06-14 to 2026-09-30 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS51167 sends an email when it next hits a sensor.

65

Source IPs

18

Networks

12

Countries

2

Ports hit

3.5K

Events

4

IPs / network

Top networks

Countries

FR 28DE 11US 9SG 4CA 3FI 2GB 2IN 2KR 1PL 1

Ports targeted

What it requests

GET/406
GET/login393
GET/register392
GET/admin250
GET/api/trpc249

User agents claimed

Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.3659 IPs2.8K
Go-http-client/1.164 IPs713
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.361 IPs2
Source IPCCNetwork Last seenEvents
169.58.235.1FRAS51167 Contabo GmbH2026-09-29260
57.129.48.33DEAS16276 OVH SAS2026-09-28243
164.132.195.45FRAS16276 OVH SAS2026-09-30189
66.94.126.66USAS40021 Contabo Inc.2026-09-23162
155.133.26.49FRAS51167 Contabo GmbH2026-09-21138
167.148.33.235USAS23470 ReliableSite.Net LLC2026-09-16135
51.68.224.189FRAS16276 OVH SAS2026-09-26135
157.173.111.223FRAS51167 Contabo GmbH2026-09-28135
137.131.6.32USAS31898 Oracle Corporation2026-09-20108
82.165.190.49DEAS8560 IONOS SE2026-09-30108
62.164.211.80DEAS51167 Contabo GmbH2026-09-25108
2.26.60.113DEAS215590 DpkgSoft International Limited2026-09-30108
62.171.128.157DEAS51167 Contabo GmbH2026-09-2481
85.190.254.45FRAS51167 Contabo GmbH2026-09-3081
62.169.26.141FRAS51167 Contabo GmbH2026-09-2881
8.220.195.43KRAS45102 Alibaba (US) Technology Co., Ltd.2026-09-2579
77.237.232.88FRAS51167 Contabo GmbH2026-09-2970
38.242.156.80FRAS51167 Contabo GmbH2026-09-2354
151.115.99.171PLAS12876 Scaleway SAS2026-09-1954
172.236.142.254SGAS63949 Akamai Connected Cloud2026-09-3054

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun040_00040016_aa48e2c8same header set6.2K IPs527.6Kb11cun040_00040016_4110f156same header set259 IPs173.0Kb11cun040_00040016_9e0aeda7same header set52 IPs8.4Kb11cun040_00040016_c1d30083same header set48 IPs6.4Kb11cun040_00040016_f36dd82esame header set9 IPs5.5Kb11cun040_00040016_fb523147same header set46 IPs3.2Kb11cun040_00040016_1d05953dsame header set11 IPs1.6Kb11cun040_00040016_50f90888same header set70 IPs1.3K

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.