HoneyLabs

Akin HTTP request fingerprint

b11cun050_00040017_27ddf488

Seen 2026-06-23 to 2026-09-23 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS207043 sends an email when it next hits a sensor.

3

Source IPs

3

Networks

3

Countries

3

Ports hit

6

Events

1

IPs / network

This fingerprint is spread thinly across many networks, which is the shape of a common, widely-used client.

Top networks

Countries

US 1BG 1BE 1

Ports targeted

What it requests

GET/6

User agents claimed

Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.362 IPs4
Mozilla/5.0 (compatible; RouterHunter/2.0)1 IPs2
Source IPCCNetwork Last seenEvents
185.218.86.25BGAS218785 Tc Datacenter Limited2026-09-212
34.140.3.155BEAS396982 Google LLC2026-09-222
151.243.18.193USAS207043 Dedik Services Limited2026-09-232

Fingerprint family: 4 shapes, 712 IPs, 9.8K events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 5 headers, no body: connection, accept-encoding, accept, user-agent, host

asks for/ · /mcp · /mcp/ · /api/mcp (GET)
asMozilla/5.0 (compatible; Infrawatch/1.0; +https://infrawat.ch/) · Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) · Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 and 51 more
ports3000 · 443 · 80 · 8080
fromDE · BG · GB · NL · Hydra Communications Ltd · Tc Datacenter Limited · Pfcloud UG (haftungsbeschrankt)
b11cun050_00040017_e873236cMozilla/5.0 (compatible; Infrawatch/1.0; +https://infrawat.ch/) · /712 IPs6.2Kb11cun050_00040017_2015d6b2Mozilla/5.0 (compatible; Infrawatch/1.0; +https://infrawat.ch/) · /sse524 IPs1.2Kb11cun050_00040017_27ddf488 this oneMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) · /3 IPs6b11cun060_0004001f_b9768d0e+/- accept-language · Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) · /2 IPs2.3K

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun050_00040017_976354f0same header set1.3K IPs19.1Kb11cun050_00040017_6b90553bsame header set1.3K IPs9.4Kb11cun050_00040017_e873236csame header set712 IPs6.2Kb11cun050_00040017_d1f380a6same header set4 IPs3.6Kb11cun050_00040017_eba289fesame header set19 IPs2.8Kb11cun050_00040017_345c845bsame header set464 IPs2.6Kb11cun050_00040017_97f1d74fsame header set38 IPs2.0Kb11cun050_00040017_2015d6b2same header set524 IPs1.2K

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.