HoneyLabs

Akin HTTP request fingerprint

b11cun060_0004001f_b9768d0e

Seen 2026-04-17 to 2026-10-01 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS218785 sends an email when it next hits a sensor.

2

Source IPs

2

Networks

2

Countries

3

Ports hit

2.3K

Events

1

IPs / network

This fingerprint is spread thinly across many networks, which is the shape of a common, widely-used client.

Top networks

Countries

BG 1BE 1

Ports targeted

What it requests

GET/2.3K

User agents claimed

Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.362 IPs2.3K
Source IPCCNetwork Last seenEvents
185.218.86.25BGAS218785 Tc Datacenter Limited2026-10-012.2K
34.140.3.155BEAS396982 Google LLC2026-10-01121

Fingerprint family: 4 shapes, 709 IPs, 9.7K events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 5 headers, no body: connection, accept-encoding, accept, user-agent, host

asks for/ · /mcp · /mcp/ · /api/mcp (GET)
asMozilla/5.0 (compatible; Infrawatch/1.0; +https://infrawat.ch/) · Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) · Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 and 51 more
ports3000 · 443 · 8080 · 80
fromDE · BG · GB · NL · Hydra Communications Ltd · Tc Datacenter Limited · Pfcloud UG (haftungsbeschrankt)
b11cun050_00040017_e873236cMozilla/5.0 (compatible; Infrawatch/1.0; +https://infrawat.ch/) · /709 IPs6.2Kb11cun050_00040017_2015d6b2Mozilla/5.0 (compatible; Infrawatch/1.0; +https://infrawat.ch/) · /sse524 IPs1.2Kb11cun050_00040017_27ddf488Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) · /3 IPs6b11cun060_0004001f_b9768d0e this one+/- accept-language · Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) · /2 IPs2.3K

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun060_0004001f_d170ef01same header set16 IPs37.5Kb11cun060_0004001f_eefe5210same header set19 IPs5.8Kb11cun060_0004001f_7d5e642bsame header set450 IPs2.8Kb11cun060_0004001f_9b6188bfsame header set29 IPs1.3Kb11cun060_0004001f_e609a46csame header set311 IPs852b11cun060_0004001f_561f323asame header set157 IPs587b11cun060_0004001f_9dee14a7same header set3 IPs144b11cun060_0004001f_efc53d1esame header set5 IPs55

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.