HoneyLabs

Akin HTTP request fingerprint

b11cun051_00040016_6289c865_x2269

Seen 2026-06-20 to 2026-09-26 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS213790 sends an email when it next hits a sensor.

3

Source IPs

2

Networks

2

Countries

13

Ports hit

93.2K

Events

2

IPs / network

This fingerprint is spread thinly across many networks, which is the shape of a common, widely-used client.

Top networks

Countries

NL 2DE 1

Ports targeted

What it requests

GET/.env105

User agents claimed

Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:125.0) Gecko/20100101 Firefox/125.03 IPs11.9K
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.363 IPs11.8K
Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.5 Safari/605.1.153 IPs11.7K
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36 Edg/124.0.0.03 IPs11.7K
Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:126.0) Gecko/20100101 Firefox/126.03 IPs11.6K
Source IPCCNetwork Last seenEvents
192.253.248.173NLAS213790 Limited Network LTD2026-09-2687.2K
213.209.159.148DEAS208137 Feo Prest SRL2026-09-093.2K
192.253.248.163NLAS213790 Limited Network LTD2026-09-212.7K

Fingerprint family: 11 shapes, 1.3K IPs, 116.9K events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 5 headers, no body: connection, accept-encoding, accept, user-agent, host

asks for/.azure/credentials · /.aws/config · /my.ini · /.env.development (GET / POST)
asMozilla/5.0 (Windows NT 10.0; Win64; x64; rv:125.0) Gecko/20100101 Firefox/125.0 · Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) · Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/605.1.15 (KHTML, like G and 155 more
ports5000 · 5005 · 3000 · 1723
fromNL · DE · CY · HK · Limited Network LTD · Feo Prest SRL · NetCrafters OU
b11cun050_00040017_6b90553bMozilla/5.0 (X11; Linux x86_64; rv:135.0) Gecko/20100101 Firefox/135.0 · /1.3K IPs9.3Kb11cun051_00040016_6289c865_x2269 this one+/- connection, range · Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:125.0) Gecko/20100101 Firefox/125.0 · /.aws/config3 IPs93.2Kb11cun061_00040017_a9482ae2_x74db+/- proxy-authorization · python-requests/2.34.2 · http://ip-api.com/json/?fields=status,country,countryCode,qu3 IPs59b11cun060_00440017_1d464540+/- authorization · ghost-pay-hunter · /admin/3 IPs6b11cuq082_00040817_03a2bf31_xd368ff63+/- content-length, x-csrf-token, x-requested-with · Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) · /panel/api/inbounds/list2 IPs7.8Kb11cun072_00040017_4c344a22_xd368ff63+/- x-csrf-token, x-requested-with · Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) · /xui/API/inbounds/2 IPs5.8Kb11cdn071_00040017_9f8bde3d_xd99b+/- d99b · Mozilla/5.0 (Macintosh; Intel Mac OS X 14_4_1) AppleWebKit/537.36 (KHTML, like G · /.env.development.local2 IPs412b11cun061_00040017_c5b51fcd_xff63+/- x-requested-with · Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) · /csrf-token2 IPs221b11cun040_00040016_03bbcb12+/- connection · CryptoHunter-Vite-2026/1.0 · /src/main.ts2 IPs50b11cuq060_00040817_1d464540+/- content-length · Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_5) AppleWebKit/605.1.15 (KHTML, lik · /login.htm2 IPs9b11cun050_00040017_69b07330Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) · /cgi-bin/login.cgi2 IPs5

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun040_00040016_aa48e2c81 header apart6.2K IPs528.1Kb11cun040_00040016_4110f1561 header apart285 IPs172.8Kb11cun040_00040016_9e0aeda71 header apart51 IPs8.4Kb11cun040_00040016_c1d300831 header apart48 IPs6.4Kb11cun040_00040016_f36dd82e1 header apart9 IPs5.5Kb11cun040_00040016_c5bb04c51 header apart65 IPs3.5Kb11cun040_00040016_fb5231471 header apart46 IPs3.2Kb11cun040_00040016_1d05953d1 header apart11 IPs1.6K

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.