HoneyLabs

Akin HTTP request fingerprint

b11cun040_00050011_bf8a4cbb

Seen 2026-02-18 to 2026-09-30 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS45102 sends an email when it next hits a sensor.

6

Source IPs

1

Networks

5

Countries

1

Ports hit

152

Events

6

IPs / network

Top networks

Countries

US 2GB 1SG 1JP 1DE 1

Ports targeted

What it requests

User agents claimed

Go-http-client/1.16 IPs152
Source IPCCNetwork Last seenEvents
47.89.154.16USAS45102 Alibaba (US) Technology Co., Ltd.2026-09-3032
8.208.10.94GBAS45102 Alibaba (US) Technology Co., Ltd.2026-09-2332
47.245.117.221SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-3032
8.211.162.45JPAS45102 Alibaba (US) Technology Co., Ltd.2026-09-3032
8.209.96.179DEAS45102 Alibaba (US) Technology Co., Ltd.2026-09-3016
47.251.13.59USAS45102 Alibaba (US) Technology Co., Ltd.2026-09-168

Fingerprint family: 2 shapes, 7 IPs, 305 events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 5 headers, Content-Length body: connection, user-agent, content-length, content-type, host

asks for/resolve · /resolve?dns=QR0BAAABAAAAAAAAATEEb2RucwFtCmRuc21lYXN1cmUDdG9 · /dns-query · /resolve?dns=YyQBAAABAAAAAAAAATEEb2RucwFtCmRuc21lYXN1cmUDdG9 (POST / GET)
asGo-http-client/1.1 · Mozilla/5.0 (Windows NT; Windows NT 6.3; en-US) WindowsPowerShell/4.0 and 1 more
ports443 · 2053
fromUS · JP · SG · GB · Alibaba (US) Technology Co., Ltd. · Optimal Agency LLC
b11cuq050_00050811_9b8c433aGo-http-client/1.1 · /7 IPs153b11cun040_00050011_bf8a4cbb this one+/- content-length · Go-http-client/1.1 · /resolve?dns=wBEBAAABAAAAAAAAATEEb2RucwFtCmRuc21lYXN1cmUDdG96 IPs152

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun030_00040011_c91eaf541 header apart546 IPs12.1Kb11cuq050_00050811_9b8c433a1 header apart7 IPs153b10cun030_00040011_c91eaf541 header apart14 IPs111b11cun030_00040011_213543bf1 header apart9 IPs78b11cuq050_00050811_985b94971 header apart7 IPs66b11cun050_00050013_2619b3ac1 header apart4 IPs61b11cun030_00040011_07783b5d1 header apart2 IPs5b11cun050_00450011_985b94971 header apart1 IPs1

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.