HoneyLabs

Akin HTTP request fingerprint

b11cun050_0004001e_d490606f

Seen 2026-02-16 to 2026-09-30 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS45102 sends an email when it next hits a sensor.

76

Source IPs

1

Networks

2

Countries

62

Ports hit

190

Events

76

IPs / network

This fingerprint is concentrated: many addresses on very few networks, which is what a single coordinated operation tends to look like.

Top networks

Countries

SG 48HK 28

Ports targeted

What it requests

GET/190

User agents claimed

Mozilla/5.0 (Windows NT 6.1; rv:2.0.1) Gecko/20100101 Firefox/4.0.119 IPs26
Mozilla/5.0 (Windows; U; Windows NT 6.1; en-US) AppleWebKit/534.16 (KHTML, like Gecko) Chrome/10.0.648.133 Safari/534.1617 IPs24
Mozilla/5.0 (Windows NT 10.0; WOW64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.122 Safari/537.3620 IPs24
Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Trident/5.0;21 IPs24
Openwave/ UCWEB7.0.2.37/28/99917 IPs21
Source IPCCNetwork Last seenEvents
8.218.203.94HKAS45102 Alibaba (US) Technology Co., Ltd.2026-09-097
8.217.139.22HKAS45102 Alibaba (US) Technology Co., Ltd.2026-09-096
47.76.47.196HKAS45102 Alibaba (US) Technology Co., Ltd.2026-09-096
47.76.114.159HKAS45102 Alibaba (US) Technology Co., Ltd.2026-09-095
8.217.25.5HKAS45102 Alibaba (US) Technology Co., Ltd.2026-09-095
47.84.32.213SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-175
8.217.185.77HKAS45102 Alibaba (US) Technology Co., Ltd.2026-09-095
8.217.156.139HKAS45102 Alibaba (US) Technology Co., Ltd.2026-09-095
47.84.81.214SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-175
47.84.93.5SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-175
8.217.29.196HKAS45102 Alibaba (US) Technology Co., Ltd.2026-09-095
47.84.196.131SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-175
47.84.91.206SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-164
47.76.53.130HKAS45102 Alibaba (US) Technology Co., Ltd.2026-09-094
47.243.28.103HKAS45102 Alibaba (US) Technology Co., Ltd.2026-09-094
47.84.89.191SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-174
8.218.200.241HKAS45102 Alibaba (US) Technology Co., Ltd.2026-09-094
8.218.147.167HKAS45102 Alibaba (US) Technology Co., Ltd.2026-09-094
47.237.140.3SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-174
47.84.87.251SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-173

Fingerprint family: 8 shapes, 261 IPs, 174.0K events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 4 headers, no body: accept-encoding, accept, user-agent, host

asks for/ · /wp-json/wp/v2/posts · /wp-login.php · /favicon.ico (GET)
asPython/3.10 aiohttp/3.8.4 · Python/3.12 aiohttp/3.9.5 · CryptoHunter-Vite-2026/1.0 and 61 more
ports42069 · 16464 · 3460 · 1293
fromNL · FR · US · UA · IP Volume inc · Contabo GmbH · Alibaba (US) Technology Co., Ltd.
b11cun040_00040016_4110f156Python/3.10 aiohttp/3.8.4 · /261 IPs173.0Kb11cun050_0004001e_377ad04d+/- accept-language · Opera/9.80 (Windows NT 6.1; U; en) Presto/2.8.131 Version/11.11 · /112 IPs273b11cun050_0004001e_d490606f this one+/- accept-language · Mozilla/5.0 (Windows NT 6.1; rv:2.0.1) Gecko/20100101 Firefox/4.0.1 · /76 IPs190b11cun050_00140016_68e1581e+/- cache-control · vitesweep/1 · /__vite_ping3 IPs260b11cun050_00140016_3b2b8fe6+/- cache-control · vitesweep/1 · /?__vitesweep=d34c6a1043268a663 IPs129b11cun050_00140016_4af3f3b6+/- cache-control · vitesweep/1 · /?__vitesweep=d34c6a1043268a663 IPs129b11cun050_00040116_a4d001fa+/- sec-fetch-dest · CryptoHunter-Vite-2026/1.0 · /node_modules/.vite/deps/_metadata.json2 IPs10b11cun050_10040016_a4d001fa+/- origin · CryptoHunter-Vite-2026/1.0 · /2 IPs6

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun050_0004001e_a647ba7fsame header set28 IPs150.4Kb11cun050_0004001e_5f886858same header set562 IPs34.6Kb11cun050_0004001e_00ecc3a8same header set84 IPs3.7Kb11cun050_0004001e_377ad04dsame header set112 IPs273b11cun050_0004001e_b55602bcsame header set10 IPs115b11cun050_0004001e_0c87f8d1same header set8 IPs30b11cun050_0004001e_050e4ccesame header set15 IPs29b11cun050_0004001e_7be04610same header set3 IPs24

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.