HoneyLabs

Akin HTTP request fingerprint

b11cun040_00040016_fb523147

Seen 2026-02-20 to 2026-09-26 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS31898 sends an email when it next hits a sensor.

46

Source IPs

1

Networks

1

Countries

6

Ports hit

3.2K

Events

46

IPs / network

This fingerprint is concentrated: many addresses on very few networks, which is what a single coordinated operation tends to look like.

Top networks

Countries

SG 46

Ports targeted

What it requests

GET/api/62
GET/62
GET/debug62
GET/.env62
GET/.npmrc62
GET/docs62
GET/env.js62

User agents claimed

Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.3646 IPs3.2K
Source IPCCNetwork Last seenEvents
161.118.237.87SGAS31898 Oracle Corporation2026-09-14153
161.118.232.83SGAS31898 Oracle Corporation2026-09-26153
140.245.108.34SGAS31898 Oracle Corporation2026-09-26153
140.245.101.62SGAS31898 Oracle Corporation2026-09-14153
161.118.211.34SGAS31898 Oracle Corporation2026-09-25102
161.118.218.217SGAS31898 Oracle Corporation2026-09-25102
161.118.219.94SGAS31898 Oracle Corporation2026-09-14102
140.245.102.95SGAS31898 Oracle Corporation2026-09-14102
161.118.205.249SGAS31898 Oracle Corporation2026-09-26102
168.107.72.188SGAS31898 Oracle Corporation2026-09-26102
161.118.218.203SGAS31898 Oracle Corporation2026-09-14102
138.2.106.209SGAS31898 Oracle Corporation2026-09-25101
161.118.240.138SGAS31898 Oracle Corporation2026-09-1151
161.118.241.225SGAS31898 Oracle Corporation2026-09-2651
134.185.95.195SGAS31898 Oracle Corporation2026-09-1151
140.245.110.72SGAS31898 Oracle Corporation2026-09-2651
168.107.81.70SGAS31898 Oracle Corporation2026-09-1151
161.118.229.234SGAS31898 Oracle Corporation2026-09-1451
213.35.112.238SGAS31898 Oracle Corporation2026-09-1151
168.107.78.73SGAS31898 Oracle Corporation2026-09-1151

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun040_00040016_aa48e2c8same header set6.2K IPs530.0Kb11cun040_00040016_4110f156same header set288 IPs170.8Kb11cun040_00040016_9e0aeda7same header set50 IPs8.4Kb11cun040_00040016_c1d30083same header set49 IPs6.4Kb11cun040_00040016_f36dd82esame header set9 IPs5.6Kb11cun040_00040016_c5bb04c5same header set68 IPs3.6Kb11cun040_00040016_1d05953dsame header set11 IPs1.6Kb11cun040_00040016_50f90888same header set69 IPs1.3K

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.