HoneyLabs

Akin HTTP request fingerprint

b11cun052_40040001_985b9497_x9f62fdb1

Seen 2026-02-19 to 2026-09-30 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS398324 sends an email when it next hits a sensor.

28

Source IPs

5

Networks

3

Countries

29

Ports hit

35

Events

6

IPs / network

Top networks

Countries

US 26NL 1BG 1

Ports targeted

What it requests

GET/28
GET/mqtt7
Source IPCCNetwork Last seenEvents
94.154.43.13NLAS219502 Storm Industries LLC2026-09-247
195.123.228.112BGAS59729 Route 95 LLC2026-09-192
167.94.146.51USAS398705 Censys, Inc.2026-09-281
167.94.146.61USAS398705 Censys, Inc.2026-09-231
167.94.146.52USAS398705 Censys, Inc.2026-09-281
66.132.172.206USAS398324 Censys, Inc.2026-09-081
167.94.146.60USAS398705 Censys, Inc.2026-09-021
66.132.172.108USAS398324 Censys, Inc.2026-09-301
66.132.195.94USAS398324 Censys, Inc.2026-09-071
66.132.186.200USAS398324 Censys, Inc.2026-09-191
66.132.172.40USAS398324 Censys, Inc.2026-09-031
66.132.186.168USAS398324 Censys, Inc.2026-09-231
66.132.172.177USAS398324 Censys, Inc.2026-09-231
167.94.146.53USAS398705 Censys, Inc.2026-09-241
66.132.224.84USAS398324 Censys, Inc.2026-09-081
66.132.172.220USAS398324 Censys, Inc.2026-09-191
66.132.224.82USAS398324 Censys, Inc.2026-09-021
167.94.146.56USAS398705 Censys, Inc.2026-09-221
167.94.146.62USAS398705 Censys, Inc.2026-09-231
66.132.186.167USAS398324 Censys, Inc.2026-09-011

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun052_40040001_96308994_x9f62fdb1same header set7 IPs16b11cun062_40040011_ffe60107_x9f62fdb11 header apart85 IPs1.1Kb11cun063_40040001_ffe60107_x9f62a4acfdb11 header apart6 IPs44b11cun062_50040001_ffe60107_x9f62fdb11 header apart1 IPs1b11cun073_40040011_cfe69652_x9f62a4acfdb12 headers apart12 IPs548b11cun072_50040011_cfe69652_x9f62fdb12 headers apart3 IPs325b11cun073_40040011_cfe69652_x12be9f62fdb12 headers apart2 IPs23

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.