HoneyLabs

Akin HTTP request fingerprint

b11cun060_0004001f_89f0332c

Seen 2026-02-19 to 2026-09-22 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS4134 sends an email when it next hits a sensor.

2

Source IPs

1

Networks

1

Countries

1

Ports hit

2

Events

2

IPs / network

Top networks

Countries

CN 2

Ports targeted

What it requests

GET/2

User agents claimed

Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.362 IPs2
Source IPCCNetwork Last seenEvents
183.36.35.198CNAS4134 Chinanet2026-09-221
183.36.35.205CNAS4134 Chinanet2026-09-181

Fingerprint family: 3 shapes, 38 IPs, 2.0K events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 5 headers, no body: connection, accept-encoding, accept, user-agent, host

asks for/ · /squelettes-dist/ · /local/ · /ecrire/ (GET / POST)
asMozilla/5.0 (Macintosh; Intel Mac OS X 14_6_1) AppleWebKit/605.1.15 Safari/605.1 · Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/128.0.0.0 Sa · Mozilla/5.0 (X11; Linux x86_64; rv:128.0) Gecko/20100101 Firefox/128.0 and 28 more
ports12286 · 12287 · 12288 · 9443
fromCA · SC · US · IN · OVH SAS · Datashield, Inc. · Google LLC
b11cun050_00040017_97f1d74fMozilla/5.0 (Macintosh; Intel Mac OS X 14_6_1) AppleWebKit/605.1.15 Safari/605.1 · /38 IPs2.0Kb11cuq060_00040817_1d464540+/- content-length · Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/118.0 · /cgi-bin/system_mgr.cgi2 IPs9b11cun060_0004001f_89f0332c this one+/- accept-language · Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like · /2 IPs2

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun060_0004001f_d170ef01same header set16 IPs35.6Kb11cun060_0004001f_eefe5210same header set19 IPs4.0Kb11cun060_0004001f_7d5e642bsame header set441 IPs2.7Kb11cun060_0004001f_b9768d0esame header set2 IPs2.2Kb11cun060_0004001f_9b6188bfsame header set29 IPs1.3Kb11cun060_0004001f_e609a46csame header set311 IPs852b11cun060_0004001f_561f323asame header set154 IPs524b11cun060_0004001f_9dee14a7same header set3 IPs144

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.