HoneyLabs

Akin HTTP request fingerprint

b11cun060_0004001f_d170ef01

Seen 2026-02-17 to 2026-10-01 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS212835 sends an email when it next hits a sensor.

16

Source IPs

4

Networks

4

Countries

2.3K

Ports hit

37.5K

Events

4

IPs / network

Top networks

Countries

RU 6SG 5BG 3US 2

Ports targeted

What it requests

GET/37.5K

User agents claimed

Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.3616 IPs37.5K
Source IPCCNetwork Last seenEvents
87.251.64.133RUAS212835 Shesternin Vladimir Anatolievich2026-10-014.2K
87.251.64.18RUAS212835 Shesternin Vladimir Anatolievich2026-10-014.2K
87.251.64.19RUAS212835 Shesternin Vladimir Anatolievich2026-10-014.1K
87.251.64.129RUAS212835 Shesternin Vladimir Anatolievich2026-10-014.0K
87.251.64.131RUAS212835 Shesternin Vladimir Anatolievich2026-10-013.7K
93.152.208.26BGAS211486 Alferov Aleksey Aleksandrovich2026-09-102.9K
93.152.208.38BGAS211486 Alferov Aleksey Aleksandrovich2026-09-102.9K
193.8.186.31SGAS201002 PebbleHost Ltd2026-10-012.6K
77.91.118.50USAS209896 Contrust Solutions S.R.L.2026-09-102.5K
193.8.186.29SGAS201002 PebbleHost Ltd2026-10-012.4K
93.152.208.42BGAS211486 Alferov Aleksey Aleksandrovich2026-09-082.0K
77.91.118.18USAS209896 Contrust Solutions S.R.L.2026-09-081.8K
193.8.186.7SGAS201002 PebbleHost Ltd2026-09-1344
193.8.186.6SGAS201002 PebbleHost Ltd2026-09-0220
193.8.186.33SGAS201002 PebbleHost Ltd2026-09-2916
87.251.64.16RUAS212835 Shesternin Vladimir Anatolievich2026-09-022

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun060_0004001f_eefe5210same header set19 IPs5.8Kb11cun060_0004001f_7d5e642bsame header set449 IPs2.7Kb11cun060_0004001f_b9768d0esame header set2 IPs2.3Kb11cun060_0004001f_9b6188bfsame header set29 IPs1.3Kb11cun060_0004001f_e609a46csame header set311 IPs852b11cun060_0004001f_561f323asame header set157 IPs591b11cun060_0004001f_9dee14a7same header set3 IPs144b11cun060_0004001f_efc53d1esame header set5 IPs55

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.