HoneyLabs

Akin HTTP request fingerprint

b11cun050_0004001e_050e4cce

Seen 2026-07-29 to 2026-09-24 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS63949 sends an email when it next hits a sensor.

15

Source IPs

1

Networks

2

Countries

2

Ports hit

29

Events

15

IPs / network

Top networks

Countries

US 8GB 7

Ports targeted

What it requests

GET/29

User agents claimed

Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.3615 IPs29
Source IPCCNetwork Last seenEvents
45.79.189.82USAS63949 Akamai Connected Cloud2026-09-242
66.175.211.161USAS63949 Akamai Connected Cloud2026-09-032
45.79.137.135USAS63949 Akamai Connected Cloud2026-09-242
172.239.120.43GBAS63949 Akamai Connected Cloud2026-09-032
172.239.118.138GBAS63949 Akamai Connected Cloud2026-09-172
172.239.120.244GBAS63949 Akamai Connected Cloud2026-09-242
97.107.138.210USAS63949 Akamai Connected Cloud2026-09-032
172.236.12.129GBAS63949 Akamai Connected Cloud2026-09-032
172.104.20.78USAS63949 Akamai Connected Cloud2026-09-172
172.237.120.62GBAS63949 Akamai Connected Cloud2026-09-102
45.79.131.4USAS63949 Akamai Connected Cloud2026-09-092
173.255.238.223USAS63949 Akamai Connected Cloud2026-09-162
172.239.111.91GBAS63949 Akamai Connected Cloud2026-09-242
66.228.36.198USAS63949 Akamai Connected Cloud2026-09-092
172.237.119.165GBAS63949 Akamai Connected Cloud2026-09-101

Fingerprint family: 2 shapes, 15 IPs, 58 events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 4 headers, no body: accept, accept-language, user-agent, host

asks for/favicon.ico · / (GET)
asMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) and 1 more
ports443 · 80
fromUS · GB · Akamai Connected Cloud
b11cun040_0004001c_cdac4f66Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) · /favicon.ico15 IPs29b11cun050_0004001e_050e4cce this one+/- accept-encoding · Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) · /15 IPs29

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun050_0004001e_a647ba7fsame header set28 IPs150.4Kb11cun050_0004001e_5f886858same header set562 IPs34.6Kb11cun050_0004001e_00ecc3a8same header set84 IPs3.7Kb11cun050_0004001e_377ad04dsame header set112 IPs273b11cun050_0004001e_d490606fsame header set76 IPs190b11cun050_0004001e_b55602bcsame header set10 IPs115b11cun050_0004001e_0c87f8d1same header set8 IPs30b11cun050_0004001e_7be04610same header set3 IPs24

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.