Akin HTTP request fingerprint
b11cun050_00040017_345c845b
Seen 2026-02-16 to 2026-10-01 across the retained window.
The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked.
Or watch the top network: AS14618 sends an email when it next hits a sensor.
Countries
US 462NL 1CN 1FR 1
User agents claimed
Mozilla/5.0 (compatible; research-scan/1.0)1 IPs1.9K
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36459 IPs599
Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.361 IPs32
Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 Chrome/125.0 Safari/537.362 IPs27
Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; WOW64; Trident/6.0)1 IPs3
Source IPCCNetwork
Last seenEvents
129.213.151.234USAS31898 Oracle Corporation2026-09-271.9K 176.65.148.71NLAS51396 Pfcloud UG (haftungsbeschrankt)2026-09-2332 35.238.120.46USAS396982 Google LLC2026-09-1218 34.170.15.1USAS396982 Google LLC2026-09-129 18.97.26.12USAS14618 Amazon.com, Inc.2026-09-294 44.220.185.32USAS14618 Amazon.com, Inc.2026-09-194 98.80.4.120USAS14618 Amazon.com, Inc.2026-09-274 18.97.26.124USAS14618 Amazon.com, Inc.2026-09-233 44.220.188.103USAS14618 Amazon.com, Inc.2026-09-153 44.220.188.205USAS14618 Amazon.com, Inc.2026-09-293 98.80.4.67USAS14618 Amazon.com, Inc.2026-09-203 18.97.26.108USAS14618 Amazon.com, Inc.2026-09-223 98.80.4.63USAS14618 Amazon.com, Inc.2026-09-083 124.239.152.79CNAS4134 Chinanet2026-09-233 44.220.188.209USAS14618 Amazon.com, Inc.2026-09-143 18.97.19.251USAS14618 Amazon.com, Inc.2026-09-263 98.80.4.73USAS14618 Amazon.com, Inc.2026-09-143 44.220.188.126USAS14618 Amazon.com, Inc.2026-09-243 44.220.185.72USAS14618 Amazon.com, Inc.2026-09-113 18.97.26.122USAS14618 Amazon.com, Inc.2026-09-213
Fingerprint family: 2 shapes, 465 IPs, 2.6K events in 30 days
Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.
HTTP/1.1, 5 headers, no body: connection, accept-encoding, accept, user-agent, host
asks for/ · /.env · /config.js · /.docker/config.json (GET)
asMozilla/5.0 (compatible; research-scan/1.0) · Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like · Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/12 and 24 more
ports8443 · 5173 · 443 · 9443
fromUS · NL · CN · FR · Oracle Corporation · Amazon.com, Inc. · Pfcloud UG (haftungsbeschrankt)
b11cun050_00040017_345c845b this oneMozilla/5.0 (compatible; research-scan/1.0) · /465 IPs2.6Kb11cun060_0004001f_f6be99b4+/- accept-language · Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chr · /v1/openapi.json4 IPs20
About this fingerprint
Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.