HoneyLabs

Akin HTTP request fingerprint

b11cun050_0004001e_377ad04d

Seen 2026-02-16 to 2026-10-01 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS45102 sends an email when it next hits a sensor.

114

Source IPs

1

Networks

3

Countries

49

Ports hit

268

Events

114

IPs / network

This fingerprint is concentrated: many addresses on very few networks, which is what a single coordinated operation tends to look like.

Top networks

Countries

SG 56JP 41HK 17

Ports targeted

What it requests

GET/268

User agents claimed

Opera/9.80 (Windows NT 6.1; U; en) Presto/2.8.131 Version/11.1131 IPs44
Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.133 Safari/534.1626 IPs29
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:53.0) Gecko/20100101 Firefox/53.021 IPs29
Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.11 (KHTML, like Gecko) Chrome/23.0.1271.64 Safari/537.1122 IPs27
Openwave/ UCWEB7.0.2.37/28/99926 IPs27
Source IPCCNetwork Last seenEvents
47.74.26.155JPAS45102 Alibaba (US) Technology Co., Ltd.2026-09-139
47.84.82.107SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-177
47.84.93.5SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-176
47.84.91.206SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-176
8.222.235.163SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-176
47.84.83.137SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-176
47.84.95.163SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-175
47.84.95.149SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-175
8.211.184.234JPAS45102 Alibaba (US) Technology Co., Ltd.2026-09-155
47.84.93.76SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-175
47.84.70.84SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-174
47.91.23.189JPAS45102 Alibaba (US) Technology Co., Ltd.2026-09-084
8.211.176.82JPAS45102 Alibaba (US) Technology Co., Ltd.2026-09-144
8.209.206.203JPAS45102 Alibaba (US) Technology Co., Ltd.2026-09-294
8.211.157.177JPAS45102 Alibaba (US) Technology Co., Ltd.2026-09-284
8.216.9.53JPAS45102 Alibaba (US) Technology Co., Ltd.2026-09-094
47.84.75.197SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-174
47.74.16.3JPAS45102 Alibaba (US) Technology Co., Ltd.2026-09-094
47.84.81.214SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-174
8.209.196.52JPAS45102 Alibaba (US) Technology Co., Ltd.2026-09-154

Fingerprint family: 9 shapes, 288 IPs, 171.9K events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 4 headers, no body: accept-encoding, accept, user-agent, host

asks for/ · /wp-json/wp/v2/posts · /wp-login.php · /favicon.ico (GET)
asPython/3.10 aiohttp/3.8.4 · Python/3.12 aiohttp/3.9.5 · CryptoHunter-Vite-2026/1.0 and 64 more
ports443 · 16464 · 3460 · 42069
fromNL · FR · US · UA · IP Volume inc · Contabo GmbH · Alibaba (US) Technology Co., Ltd.
b11cun040_00040016_4110f156Python/3.10 aiohttp/3.8.4 · /288 IPs170.8Kb11cun050_0004001e_377ad04d this one+/- accept-language · Opera/9.80 (Windows NT 6.1; U; en) Presto/2.8.131 Version/11.11 · /114 IPs268b11cun050_0004001e_d490606f+/- accept-language · Mozilla/5.0 (Windows NT 6.1; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 · /75 IPs189b11cun050_00140016_68e1581e+/- cache-control · vitesweep/1 · /__vite_ping3 IPs260b11cun050_00140016_3b2b8fe6+/- cache-control · vitesweep/1 · /?__vitesweep=d34c6a1043268a663 IPs129b11cun050_00140016_4af3f3b6+/- cache-control · vitesweep/1 · /?__vitesweep=d34c6a1043268a663 IPs129b11cun040_00040016_03bbcb12CryptoHunter-Vite-2026/1.0 · /src/main.ts2 IPs50b11cun050_00040116_a4d001fa+/- sec-fetch-dest · CryptoHunter-Vite-2026/1.0 · /node_modules/.vite/deps/_metadata.json2 IPs10b11cun050_10040016_a4d001fa+/- origin · CryptoHunter-Vite-2026/1.0 · /2 IPs6

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun050_0004001e_a647ba7fsame header set26 IPs138.7Kb11cun050_0004001e_5f886858same header set562 IPs33.3Kb11cun050_0004001e_00ecc3a8same header set82 IPs3.7Kb11cun050_0004001e_d490606fsame header set75 IPs189b11cun050_0004001e_b55602bcsame header set10 IPs115b11cun050_0004001e_0c87f8d1same header set8 IPs30b11cun050_0004001e_050e4ccesame header set15 IPs29b11cun050_0004001e_a3d0c27asame header set5 IPs8

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.