HoneyLabs

Akin HTTP request fingerprint

b11cun050_0004001e_5f886858

Seen 2026-02-16 to 2026-09-30 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS135377 sends an email when it next hits a sensor.

562

Source IPs

6

Networks

26

Countries

3.0K

Ports hit

34.6K

Events

94

IPs / network

Top networks

Countries

US 123HK 72JP 43KR 41TH 39DE 29GB 26IN 25TW 24NG 19

Ports targeted

What it requests

User agents claimed

Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36 Edg/120.0.0.0558 IPs25.7K
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_7_0) AppleWebKit/535.11 (KHTML, like Gecko) Chrome/17.0.963.56 Safari/535.11562 IPs8.9K
Source IPCCNetwork Last seenEvents
165.154.138.33DEAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-24172
152.32.183.209USAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-18156
152.32.243.98KRAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-24143
165.154.49.137IDAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-24143
165.154.174.206GBAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-18143
165.154.138.34DEAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-24139
118.193.56.184THAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-15137
152.32.180.86AEAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-18136
152.32.130.155HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-15136
152.32.199.112BRAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-24136
152.32.233.95USAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-15136
165.154.221.175VNAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-15135
152.32.191.98HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-24135
165.154.164.21DEAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-15135
152.32.159.79INAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-17135
152.32.181.210AEAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-24135
118.193.65.209GBAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-17133
152.32.150.215USAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-24132
118.193.36.56HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-15132
165.154.119.217THAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-15132

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun050_0004001e_a647ba7fsame header set28 IPs150.4Kb11cun050_0004001e_00ecc3a8same header set84 IPs3.7Kb11cun050_0004001e_377ad04dsame header set111 IPs272b11cun050_0004001e_d490606fsame header set76 IPs190b11cun050_0004001e_b55602bcsame header set10 IPs115b11cun050_0004001e_0c87f8d1same header set9 IPs44b11cun050_0004001e_050e4ccesame header set15 IPs29b11cun050_0004001e_7be04610same header set3 IPs24

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.