HoneyLabs

Akin HTTP request fingerprint

b11cun050_00040017_6b90553b

Seen 2026-02-16 to 2026-09-30 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS25369 sends an email when it next hits a sensor.

1.3K

Source IPs

42

Networks

20

Countries

774

Ports hit

9.3K

Events

30

IPs / network

Top networks

Countries

GB 872DE 322NL 23US 13CN 6ID 2BG 2BR 2IR 2AE 2

Ports targeted

What it requests

GET/5.4K
GET/.env28

User agents claimed

Mozilla/5.0 (X11; Linux x86_64; rv:135.0) Gecko/20100101 Firefox/135.01 IPs2.5K
Mozilla/5.0 (compatible; Infrawatch/1.0; +https://infrawat.ch/)622 IPs2.5K
Mozilla/5.0 (compatible; InternetMeasurement/1.0; +https://internet-measurement.com/)563 IPs1.0K
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.3610 IPs652
Mozilla/5.0 (X11; U; Linux x86_64; en-US) AppleWebKit/534.15 (KHTML, like Gecko) Chrome/10.0.613.0 Safari/534.151 IPs406
Source IPCCNetwork Last seenEvents
150.107.36.82HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-282.9K
192.253.248.173NLAS213790 Limited Network LTD2026-09-05701
94.154.43.36NLAS219502 Storm Industries LLC2026-09-23633
69.5.20.14IDAS150436 Byteplus Pte. Ltd.2026-09-16440
192.253.248.163NLAS213790 Limited Network LTD2026-09-21394
75.127.6.2USAS36352 HostPapa2026-09-02134
168.76.20.229ZAAS137951 ASLINE LIMITED2026-09-3087
93.123.109.214BGAS48090 Techoff Srv Limited2026-09-3072
213.209.159.148DEAS208137 Feo Prest SRL2026-09-0960
171.22.114.108CYAS203273 NetCrafters OU2026-09-2559
129.213.151.234USAS31898 Oracle Corporation2026-09-0540
45.81.23.14NLAS49870 Alsycon B.V.2026-09-2938
45.194.92.14USAS215925 Vpsvault.host Ltd2026-09-0220
69.5.169.178DEAS25369 Hydra Communications Ltd2026-09-1416
64.34.81.199USAS396356 Latitude.sh2026-09-2015
177.104.180.43BRAS53107 EVEO S.A.2026-09-1615
51.15.23.21NLAS12876 Scaleway SAS2026-09-1215
69.5.169.157DEAS25369 Hydra Communications Ltd2026-09-1414
69.5.169.224DEAS25369 Hydra Communications Ltd2026-09-1413
82.158.131.39IDAS9341 PT INDONESIA COMNETS PLUS2026-09-2712

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun050_00040017_976354f0same header set1.3K IPs18.7Kb11cun050_00040017_e873236csame header set680 IPs6.1Kb11cun050_00040017_eba289fesame header set19 IPs2.8Kb11cun050_00040017_345c845bsame header set469 IPs2.6Kb11cun050_00040017_2015d6b2same header set524 IPs1.2Kb11cun050_00040017_91712619same header set1 IPs960b11cun050_00040017_ee17dab1same header set4 IPs644b11cun050_00040017_588d51acsame header set1 IPs610

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.