HoneyLabs

Akin HTTP request fingerprint

b11cun050_00040017_ee17dab1

Seen 2026-03-10 to 2026-10-01 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS50360 sends an email when it next hits a sensor.

4

Source IPs

4

Networks

2

Countries

120

Ports hit

821

Events

1

IPs / network

This fingerprint is spread thinly across many networks, which is the shape of a common, widely-used client.

Top networks

Countries

BG 2US 2

Ports targeted

What it requests

GET/login568
GET/246

User agents claimed

Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.362 IPs807
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.361 IPs3
Mozilla/5.0 (Macintosh; Intel Mac OS X 14_4_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4.1 Safari/605.1.151 IPs1
Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_5_7; de-de) AppleWebKit/525.18 (KHTML, like Gecko) Version/3.1.1 Safari/525.201 IPs1
Mozilla/5.0 (Macintosh, Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Safari/605.1.151 IPs1
Source IPCCNetwork Last seenEvents
78.128.114.66BGAS50360 Tamatiya EOOD2026-09-30478
109.238.87.243USAS55286 B2 Net Solutions Inc.2026-10-01329
93.123.109.214BGAS48090 Techoff Srv Limited2026-10-0113
104.30.167.164USAS13335 Cloudflare, Inc.2026-09-241

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun050_00040017_976354f0same header set1.3K IPs19.1Kb11cun050_00040017_6b90553bsame header set1.3K IPs9.4Kb11cun050_00040017_e873236csame header set710 IPs6.2Kb11cun050_00040017_d1f380a6same header set4 IPs3.6Kb11cun050_00040017_eba289fesame header set19 IPs2.8Kb11cun050_00040017_345c845bsame header set464 IPs2.6Kb11cun050_00040017_97f1d74fsame header set38 IPs2.0Kb11cun050_00040017_2015d6b2same header set524 IPs1.2K

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.