HoneyLabs

Akin HTTP request fingerprint

b11cun050_00060013_3ef9a8f6

Seen 2026-02-16 to 2026-09-30 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS135377 sends an email when it next hits a sensor.

664

Source IPs

52

Networks

31

Countries

867

Ports hit

9.0K

Events

13

IPs / network

Top networks

Countries

US 405HK 114SC 83NL 7DE 7FR 6IN 5RO 4SG 4IR 3

Ports targeted

What it requests

GET/5.2K
GET/.env155

User agents claimed

Mozilla/5.0 (Windows NT 10.0; WOW64; rv:50.0) Gecko/20100101 Firefox/50.011 IPs23
Mozilla/5.0 (X11; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/137.0.0.0 Safari/537.3611 IPs22
Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_2; en-us) AppleWebKit/531.21.8 (KHTML, like Gecko) Version/4.0.4 Safari/531.21.1011 IPs21
Mozilla/5.0 (Macintosh; Intel Mac OS X 11) AppleWebKit/619.23 (KHTML, like Gecko) Version/15.3.85 Safari/619.2310 IPs20
Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:126.0) Gecko/20100101 Firefox/126.09 IPs20
Source IPCCNetwork Last seenEvents
96.62.71.3USAS207043 Dedik Services Limited2026-09-19396
34.84.70.148JPAS396982 Google LLC2026-09-26284
34.26.12.70USAS396982 Google LLC2026-09-27269
35.205.162.104BEAS396982 Google LLC2026-09-27217
34.95.254.54BRAS396982 Google LLC2026-09-27208
2.27.160.71USAS207043 Dedik Services Limited2026-09-13200
34.35.75.191ZAAS396982 Google LLC2026-09-26191
34.175.71.81ESAS396982 Google LLC2026-09-27186
107.150.102.190USAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-29102
165.154.134.22USAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-2992
118.193.77.116USAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-2992
107.150.97.149USAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-2990
45.43.57.157USAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-2989
45.148.10.171NLAS48090 Techoff Srv Limited2026-09-3088
165.154.163.115USAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-2988
107.150.102.191USAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-2988
107.150.109.193USAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-2987
107.150.96.189USAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-3084
107.150.97.4USAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-3082
152.32.235.6USAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-3082

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun040_00040013_608dab681 header apart4.3K IPs243.3Kb11cun040_00040013_ab9bb0751 header apart57 IPs565b11cun060_00060413_0af44bea1 header apart40 IPs210b11cun040_00040013_7df024fe1 header apart2 IPs44b11cun040_00060011_0e46e4021 header apart8 IPs25b11cun040_00040013_2178e07e1 header apart12 IPs12b11cun040_00040013_89f46b261 header apart4 IPs12b11cun040_00040013_6c646f8f1 header apart5 IPs5

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.