HoneyLabs

Akin HTTP request fingerprint

b11cun060_0004001f_7d5e642b

Seen 2026-02-19 to 2026-09-30 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS45102 sends an email when it next hits a sensor.

449

Source IPs

3

Networks

2

Countries

558

Ports hit

2.7K

Events

150

IPs / network

This fingerprint is concentrated: many addresses on very few networks, which is what a single coordinated operation tends to look like.

Top networks

Countries

SG 236US 213

Ports targeted

What it requests

GET/2.7K

User agents claimed

Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.132 Safari/537.36449 IPs2.7K
Source IPCCNetwork Last seenEvents
47.254.37.72USAS45102 Alibaba (US) Technology Co., Ltd.2026-09-3024
47.77.177.220USAS45102 Alibaba (US) Technology Co., Ltd.2026-09-1822
47.88.20.65USAS45102 Alibaba (US) Technology Co., Ltd.2026-09-3022
43.106.48.44SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-1322
47.77.231.118USAS45102 Alibaba (US) Technology Co., Ltd.2026-09-3020
43.98.205.217SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-1320
47.251.120.117USAS45102 Alibaba (US) Technology Co., Ltd.2026-09-1818
47.77.177.14USAS45102 Alibaba (US) Technology Co., Ltd.2026-09-3018
43.106.58.188SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-2817
47.251.6.51USAS45102 Alibaba (US) Technology Co., Ltd.2026-09-1817
47.77.184.107USAS45102 Alibaba (US) Technology Co., Ltd.2026-09-3017
47.85.104.213USAS45102 Alibaba (US) Technology Co., Ltd.2026-09-3016
43.98.199.249SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-1316
8.221.115.78USAS45102 Alibaba (US) Technology Co., Ltd.2026-09-3015
47.251.32.230USAS45102 Alibaba (US) Technology Co., Ltd.2026-09-1815
47.251.83.137USAS45102 Alibaba (US) Technology Co., Ltd.2026-09-1815
43.110.146.219USAS45102 Alibaba (US) Technology Co., Ltd.2026-09-3015
47.251.246.235USAS45102 Alibaba (US) Technology Co., Ltd.2026-09-1815
47.251.244.243USAS45102 Alibaba (US) Technology Co., Ltd.2026-09-1815
43.98.197.47SGAS45102 Alibaba (US) Technology Co., Ltd.2026-09-1314

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun060_0004001f_d170ef01same header set16 IPs37.5Kb11cun060_0004001f_eefe5210same header set19 IPs5.8Kb11cun060_0004001f_b9768d0esame header set2 IPs2.3Kb11cun060_0004001f_9b6188bfsame header set29 IPs1.3Kb11cun060_0004001f_e609a46csame header set311 IPs852b11cun060_0004001f_561f323asame header set157 IPs591b11cun060_0004001f_9dee14a7same header set3 IPs144b11cun060_0004001f_efc53d1esame header set5 IPs55

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.