HoneyLabs

Akin HTTP request fingerprint

b11cun050_00040017_632d8572

Seen 2026-03-13 to 2026-09-28 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS15169 sends an email when it next hits a sensor.

10

Source IPs

5

Networks

4

Countries

2

Ports hit

20

Events

2

IPs / network

Top networks

Countries

US 7IT 1KR 1TW 1

Ports targeted

What it requests

User agents claimed

Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)6 IPs10
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.364 IPs10
Source IPCCNetwork Last seenEvents
103.189.190.28ITAS395793 Arisk Communications inc.2026-09-094
66.249.68.70USAS15169 Google LLC2026-09-154
175.208.121.87KRAS4766 Korea Telecom2026-09-092
36.237.38.16TWAS3462 Data Communication Business Group2026-09-092
66.249.68.64USAS15169 Google LLC2026-09-112
38.213.66.212USAS174 Cogent Communications, LLC2026-09-092
66.249.66.201USAS15169 Google LLC2026-09-091
66.249.68.71USAS15169 Google LLC2026-09-051
66.249.68.67USAS15169 Google LLC2026-09-011
66.249.75.200USAS15169 Google LLC2026-09-281

Fingerprint family: 2 shapes, 10 IPs, 37 events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 5 headers, no body: connection, accept-encoding, accept, user-agent, host

asks for/robots.txt · /ads.txt · /api/general-info (GET)
asMozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html) · Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) and 1 more
ports443 · 80
fromUS · IT · KR · TW · Google LLC · Arisk Communications inc. · Cogent Communications, LLC
b11cun050_00040017_632d8572 this oneMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) · /api/general-info10 IPs20b11cun061_00040017_1e93cacd_x7585+/- from · Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html) · /ads.txt6 IPs17

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun050_00040017_976354f0same header set1.3K IPs19.1Kb11cun050_00040017_6b90553bsame header set1.3K IPs9.4Kb11cun050_00040017_e873236csame header set721 IPs6.2Kb11cun050_00040017_d1f380a6same header set4 IPs3.6Kb11cun050_00040017_eba289fesame header set19 IPs2.8Kb11cun050_00040017_345c845bsame header set462 IPs2.6Kb11cun050_00040017_97f1d74fsame header set38 IPs2.0Kb11cun050_00040017_2015d6b2same header set524 IPs1.2K

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.