HoneyLabs

Akin HTTP request fingerprint

b11cun050_0044001c_d97268c3

Seen 2026-02-19 to 2026-09-30 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS63199 sends an email when it next hits a sensor.

7

Source IPs

1

Networks

1

Countries

60

Ports hit

111

Events

7

IPs / network

Top networks

Countries

JP 7

Ports targeted

What it requests

GET/111

User agents claimed

Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.367 IPs111
Source IPCCNetwork Last seenEvents
164.52.24.181JPAS63199 CDS Global Cloud Co., Ltd2026-09-2929
164.52.24.190JPAS63199 CDS Global Cloud Co., Ltd2026-09-3022
164.52.24.184JPAS63199 CDS Global Cloud Co., Ltd2026-09-2922
164.52.24.180JPAS63199 CDS Global Cloud Co., Ltd2026-09-3021
164.52.24.182JPAS63199 CDS Global Cloud Co., Ltd2026-09-2014
164.52.0.92JPAS63199 CDS Global Cloud Co., Ltd2026-09-182
164.52.24.185JPAS63199 CDS Global Cloud Co., Ltd2026-09-201

Fingerprint family: 2 shapes, 7 IPs, 216 events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 5 headers, no body: accept, accept-language, user-agent, host, authorization

asks for/ (GET)
asMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) and 1 more
ports2087 · 5986 · 8114 · 7547
fromJP · CDS Global Cloud Co., Ltd
b11cun050_0044001c_d97268c3 this oneMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) · /7 IPs111b11cun060_0044001e_9fddb4ee+/- accept-encoding · Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) · /7 IPs105

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun040_0004001c_61f767741 header apart2 IPs5.4Kb11cun060_0044001e_9fddb4ee1 header apart7 IPs105b11cun040_0004001c_cdac4f661 header apart15 IPs29b11cun030_00040014_03330a182 headers apart3.9K IPs1.4Mb11cun050_0004001d_5cbb346f2 headers apart977 IPs169.2Kb11cun050_0004001e_a647ba7f2 headers apart27 IPs146.7Kb11cun030_00040014_54d07b6d2 headers apart3.7K IPs135.9Kb11cun050_0004001e_5f8868582 headers apart562 IPs34.5K

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.