HoneyLabs

Akin HTTP request fingerprint

b11cun050_0004001e_00ecc3a8

Seen 2026-02-17 to 2026-09-30 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS14061 sends an email when it next hits a sensor.

82

Source IPs

23

Networks

12

Countries

158

Ports hit

3.7K

Events

4

IPs / network

Top networks

Countries

US 46DE 21BG 3RU 2NL 2CA 2IR 1PA 1CL 1CN 1

Ports targeted

What it requests

GET/389
GET/.env302
GET/.env.bak284
GET/api/.env284
GET/app/.env281

User agents claimed

Mozilla/5.0 (X11; Linux i686; en-US) Gecko/20010604 Firefox/109.012 IPs12
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; ClaudeBot/1.0; +claudebot@anthropic.com)9 IPs11
Mozilla/5.0 (Kubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/137.0.0.0 Safari/537.3610 IPs11
Mozilla/5.0 (Debian; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.369 IPs11
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6.1 Mobile/15E148 Safari/604.110 IPs11
Source IPCCNetwork Last seenEvents
195.178.110.97BGAS48090 Techoff Srv Limited2026-09-30195
159.89.20.206DEAS14061 DigitalOcean, LLC2026-09-27150
165.227.130.153DEAS14061 DigitalOcean, LLC2026-09-27140
46.101.157.116DEAS14061 DigitalOcean, LLC2026-09-27130
107.170.46.12USAS14061 DigitalOcean, LLC2026-09-27110
162.243.232.228USAS14061 DigitalOcean, LLC2026-09-27100
104.248.119.122USAS14061 DigitalOcean, LLC2026-09-27100
192.241.160.85USAS14061 DigitalOcean, LLC2026-09-27100
159.65.231.10USAS14061 DigitalOcean, LLC2026-09-27100
138.197.177.108DEAS14061 DigitalOcean, LLC2026-09-2790
167.172.182.242DEAS14061 DigitalOcean, LLC2026-09-2790
46.101.174.66DEAS14061 DigitalOcean, LLC2026-09-2780
162.243.11.223USAS14061 DigitalOcean, LLC2026-09-2780
134.209.212.64USAS14061 DigitalOcean, LLC2026-09-2780
68.183.78.151DEAS14061 DigitalOcean, LLC2026-09-2780
162.243.27.60USAS14061 DigitalOcean, LLC2026-09-2780
107.170.59.14USAS14061 DigitalOcean, LLC2026-09-2780
46.101.227.193DEAS14061 DigitalOcean, LLC2026-09-2870
162.243.92.16USAS14061 DigitalOcean, LLC2026-09-2770
134.122.71.111DEAS14061 DigitalOcean, LLC2026-09-2770

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun050_0004001e_a647ba7fsame header set26 IPs138.7Kb11cun050_0004001e_5f886858same header set562 IPs33.3Kb11cun050_0004001e_377ad04dsame header set114 IPs268b11cun050_0004001e_d490606fsame header set75 IPs189b11cun050_0004001e_b55602bcsame header set10 IPs115b11cun050_0004001e_0c87f8d1same header set8 IPs30b11cun050_0004001e_050e4ccesame header set15 IPs29b11cun050_0004001e_a3d0c27asame header set5 IPs8

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.