HoneyLabs

Akin HTTP request fingerprint

b11cun050_0004001d_e6fe1ac3

Seen 2026-08-15 to 2026-09-29 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS16276 sends an email when it next hits a sensor.

40

Source IPs

24

Networks

16

Countries

4

Ports hit

1.1K

Events

2

IPs / network

This fingerprint is spread thinly across many networks, which is the shape of a common, widely-used client.

Top networks

Countries

FR 8CN 7DE 5SG 4US 3IN 2VN 2TW 1PT 1HK 1

Ports targeted

What it requests

GET/1.0K
GET/en11
GET/en-de8
GET/en/6
GET/de/6
GET/cn4
GET/en42

User agents claimed

Software Security Research/1.0 (+https://reverse-proxies-measurements.softsec.ruhr-uni-bochum.de)1 IPs755
Software Security Research/1.0 (+https://goose.softsec.ruhr-uni-bochum.de)1 IPs307
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/125 Safari/537.3636 IPs73
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.363 IPs6
Source IPCCNetwork Last seenEvents
185.73.23.162DEAS29484 Ruhr-Universitaet Bochum2026-09-291.1K
213.177.179.52TWAS208137 Feo Prest SRL2026-09-046
103.106.104.187VNAS151858 INTERDIGI JOINT STOCK COMPANY2026-09-042
51.38.227.10FRAS16276 OVH SAS2026-09-042
62.171.174.208FRAS51167 Contabo GmbH2026-09-052
84.247.145.2SGAS141995 Contabo Asia Private Limited2026-09-042
93.46.24.112ITAS12874 Fastweb2026-09-052
51.91.8.17FRAS16276 OVH SAS2026-09-042
94.46.172.237PTAS24768 Almouroltec Servicos De Informatica E Internet Lda2026-09-052
117.50.174.65CNAS4808 China Unicom Beijing Province Network2026-09-042
38.156.13.6COAS272156 WEB MASTER COLOMBIA SAS2026-09-042
103.90.67.84IDAS150265 PT Rajawali Bintang Cemerlang Telkomedia2026-09-042
192.253.248.94NLAS213790 Limited Network LTD2026-09-242
43.131.58.26DEAS132203 Tencent Building, Kejizhongyi Avenue2026-09-042
192.99.42.5CAAS16276 OVH SAS2026-09-042
120.76.206.71CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-042
159.89.27.23DEAS14061 DigitalOcean, LLC2026-09-242
118.139.165.143SGAS26496 GoDaddy.com, LLC2026-09-042
92.205.29.113FRAS21499 Host Europe GmbH2026-09-242
185.243.53.182PLAS41079 Cyber_Folks S.A.2026-09-042

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun050_0004001d_5cbb346fsame header set977 IPs169.6Kb11cun050_0004001d_0667c978same header set1 IPs3.9Kb11cun050_0004001d_fda4f7dcsame header set2 IPs280b11cun050_0004001d_7a38a7f7same header set38 IPs56b11cun050_0004001d_74ae3f98same header set2 IPs14b11cun050_0004001d_7129ba85same header set2 IPs4b11cun050_0004001d_7a5b0fd7same header set1 IPs2b11cun050_0004001d_1cb8420bsame header set1 IPs1

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.