HoneyLabs

Akin HTTP request fingerprint

b11cun040_08040011_2daa70d6

Seen 2026-02-21 to 2026-09-21 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS200373 sends an email when it next hits a sensor.

37

Source IPs

2

Networks

9

Countries

13

Ports hit

37

Events

18

IPs / network

This fingerprint is concentrated: many addresses on very few networks, which is what a single coordinated operation tends to look like.

Top networks

Countries

US 15FR 6BR 5ES 4GB 2TH 2NL 1CA 1DE 1

Ports targeted

What it requests

User agents claimed

Mozilla/5.0 (compatible; what-vpn-go/0.1)24 IPs24
AnyConnect12 IPs12
Mozilla/5.01 IPs1
Source IPCCNetwork Last seenEvents
45.3.47.82FRAS200373 3xK Tech GmbH2026-09-021
45.3.39.8USAS200373 3xK Tech GmbH2026-09-021
209.50.165.226USAS200373 3xK Tech GmbH2026-09-021
209.50.184.154ESAS200373 3xK Tech GmbH2026-09-021
209.50.173.26USAS200373 3xK Tech GmbH2026-09-021
209.50.165.241USAS200373 3xK Tech GmbH2026-09-021
216.26.239.61BRAS200373 3xK Tech GmbH2026-09-021
209.50.184.59ESAS200373 3xK Tech GmbH2026-09-021
104.207.33.13USAS200373 3xK Tech GmbH2026-09-021
45.3.53.115BRAS200373 3xK Tech GmbH2026-09-021
151.123.178.143FRAS200373 3xK Tech GmbH2026-09-021
65.111.2.26USAS200373 3xK Tech GmbH2026-09-021
104.207.58.202THAS200373 3xK Tech GmbH2026-09-021
216.26.230.116USAS200373 3xK Tech GmbH2026-09-021
65.111.9.237USAS200373 3xK Tech GmbH2026-09-021
209.50.189.133FRAS200373 3xK Tech GmbH2026-09-021
216.26.237.102USAS200373 3xK Tech GmbH2026-09-021
216.26.232.26USAS200373 3xK Tech GmbH2026-09-021
216.26.241.56BRAS200373 3xK Tech GmbH2026-09-021
45.3.55.223DEAS200373 3xK Tech GmbH2026-09-021

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun030_00040011_c91eaf541 header apart548 IPs12.1Kb11cun050_08040013_2619b3ac1 header apart1 IPs164b10cun030_00040011_c91eaf541 header apart14 IPs111b11cun030_00040011_213543bf1 header apart9 IPs78b11cun030_00040011_07783b5d1 header apart2 IPs5b11cun050_08040015_df66fe0f1 header apart1 IPs1b11cun040_00040013_608dab682 headers apart4.3K IPs243.3Kb11cun040_00040015_4c87b06e2 headers apart1.5K IPs159.7K

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.