HoneyLabs

Akin HTTP request fingerprint

b11cun060_0004001f_f6be99b4

Seen 2026-08-22 to 2026-10-01 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS14618 sends an email when it next hits a sensor.

4

Source IPs

1

Networks

1

Countries

3

Ports hit

20

Events

4

IPs / network

Top networks

Countries

US 4

Ports targeted

What it requests

User agents claimed

Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/55.0.3011.95 Safari/537.321 IPs1
Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/55.0.3013.104 Safari/537.321 IPs1
Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/54.0.3025.84 Safari/537.321 IPs1
Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/56.0.3048.79 Safari/537.321 IPs1
Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/54.0.3078.109 Safari/537.321 IPs1
Source IPCCNetwork Last seenEvents
98.80.4.85USAS14618 Amazon.com, Inc.2026-10-015
18.97.26.123USAS14618 Amazon.com, Inc.2026-10-015
44.220.188.200USAS14618 Amazon.com, Inc.2026-09-305
18.97.5.3USAS14618 Amazon.com, Inc.2026-10-015

Fingerprint family: 3 shapes, 464 IPs, 2.6K events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 5 headers, no body: connection, accept-encoding, accept, user-agent, host

asks for/ · /.env · /config.js · /.docker/config.json (GET)
asMozilla/5.0 (compatible; research-scan/1.0) · Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like · Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/12 and 25 more
ports8443 · 5173 · 443 · 9443
fromUS · NL · CN · FR · Oracle Corporation · Amazon.com, Inc. · Pfcloud UG (haftungsbeschrankt)
b11cun050_00040017_345c845bMozilla/5.0 (compatible; research-scan/1.0) · /464 IPs2.6Kb11cun060_0004001f_f6be99b4 this one+/- accept-language · Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chr · /v1/openapi.json4 IPs20b11cun060_80040017_8e5e346c+/- x-forwarded-for · Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 Chrome/125.0 Safari/537.36 · /api/config2 IPs3

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun060_0004001f_d170ef01same header set16 IPs37.5Kb11cun060_0004001f_eefe5210same header set19 IPs5.8Kb11cun060_0004001f_7d5e642bsame header set449 IPs2.7Kb11cun060_0004001f_b9768d0esame header set2 IPs2.3Kb11cun060_0004001f_9b6188bfsame header set29 IPs1.3Kb11cun060_0004001f_e609a46csame header set311 IPs852b11cun060_0004001f_561f323asame header set159 IPs599b11cun060_0004001f_9dee14a7same header set3 IPs144

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.