Akin HTTP request fingerprint
b11cun060_0006001d_3af976da
Seen 2026-02-16 to 2026-09-30 across the retained window.
The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked.
Or watch the top network: AS213412 sends an email when it next hits a sensor.
Countries
HK 107CN 99US 3SG 1SC 1
User agents claimed
Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36147 IPs4.1K
Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:134.0) Gecko/20100101 Firefox/134.064 IPs1.3K
Source IPCCNetwork
Last seenEvents
152.32.209.108HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-3047 156.225.1.31HKAS9465 AGOTOZ PTE. LTD.2026-09-3044 156.225.1.37HKAS9465 AGOTOZ PTE. LTD.2026-09-3043 156.225.1.18HKAS9465 AGOTOZ PTE. LTD.2026-09-2943 156.225.1.113HKAS9465 AGOTOZ PTE. LTD.2026-09-2941 152.32.133.206HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-2941 156.225.1.45HKAS9465 AGOTOZ PTE. LTD.2026-09-3041 128.1.132.17HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-3041 156.225.1.96HKAS9465 AGOTOZ PTE. LTD.2026-09-3040 106.75.3.6CNAS4808 China Unicom Beijing Province Network2026-09-2839 128.1.132.84HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-2939 152.32.254.132HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-3039 152.32.188.12HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-3038 156.225.1.100HKAS9465 AGOTOZ PTE. LTD.2026-09-3038 123.58.212.238HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-2938 123.58.209.194HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-3037 123.58.217.155HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-2837 106.75.8.124CNAS4808 China Unicom Beijing Province Network2026-09-2837 118.26.38.132HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-3037 156.225.1.13HKAS9465 AGOTOZ PTE. LTD.2026-09-3037
Fingerprint family: 2 shapes, 211 IPs, 9.5K events in 30 days
Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.
HTTP/1.1, 6 headers, no body: connection, accept, accept-language, user-agent, accept-charset, host
asks for/favicon.ico · / (GET)
asMozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0. · Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:134.0) Gecko/20100101 Firefox/134.0 and 1 more
ports554 · 28017 · 58603 · 8983
fromHK · CN · SG · US · AGOTOZ PTE. LTD. · UCLOUD INFORMATION TECHNOLOGY (HK) LIMIT · ONYPHE SAS
b11cun060_0006001d_3af976da this oneMozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0. · /211 IPs5.4Kb11cun070_0006041d_01a11761+/- referer · Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0. · /favicon.ico147 IPs4.1K
About this fingerprint
Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.