HoneyLabs

Akin HTTP request fingerprint

b11cun060_00060413_0af44bea

Seen 2026-06-18 to 2026-09-25 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS14061 sends an email when it next hits a sensor.

40

Source IPs

2

Networks

3

Countries

50

Ports hit

210

Events

20

IPs / network

This fingerprint is concentrated: many addresses on very few networks, which is what a single coordinated operation tends to look like.

Top networks

Countries

DE 20US 19FR 1

Ports targeted

What it requests

GET/209

User agents claimed

Mozilla/5.0 (Debian; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.363 IPs4
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.363 IPs3
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/117.0.0.0 Safari/537.363 IPs3
Mozilla/5.0 (X11; Linux x86_64; rv:1.9.5.20) Gecko/ Firefox/3.6.123 IPs3
Mozilla/5.0 (CentOS; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.362 IPs2
Source IPCCNetwork Last seenEvents
162.243.226.225USAS14061 DigitalOcean, LLC2026-09-2511
161.35.221.135DEAS14061 DigitalOcean, LLC2026-09-2510
165.227.141.56DEAS14061 DigitalOcean, LLC2026-09-259
147.182.140.20USAS14061 DigitalOcean, LLC2026-09-259
165.227.167.59DEAS14061 DigitalOcean, LLC2026-09-259
46.101.227.193DEAS14061 DigitalOcean, LLC2026-09-258
192.241.160.85USAS14061 DigitalOcean, LLC2026-09-257
164.90.238.135DEAS14061 DigitalOcean, LLC2026-09-257
167.99.12.84USAS14061 DigitalOcean, LLC2026-09-257
104.131.233.218USAS14061 DigitalOcean, LLC2026-09-257
192.241.168.220USAS14061 DigitalOcean, LLC2026-09-256
46.101.174.66DEAS14061 DigitalOcean, LLC2026-09-256
201.79.3.253DEAS14061 DigitalOcean, LLC2026-09-256
159.89.20.206DEAS14061 DigitalOcean, LLC2026-09-256
137.184.217.216USAS14061 DigitalOcean, LLC2026-09-256
104.248.119.122USAS14061 DigitalOcean, LLC2026-09-255
162.243.11.223USAS14061 DigitalOcean, LLC2026-09-255
64.225.97.56DEAS14061 DigitalOcean, LLC2026-09-255
165.22.21.73DEAS14061 DigitalOcean, LLC2026-09-255
107.170.59.14USAS14061 DigitalOcean, LLC2026-09-255

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun050_00060013_3ef9a8f61 header apart664 IPs9.0Kb10cun050_00040413_a4fc9b3e1 header apart41 IPs5.0Kb11cun050_00040413_2619b3ac1 header apart10 IPs289b11cun050_00040413_ca60424e1 header apart1 IPs4b11cun040_00040013_608dab682 headers apart4.3K IPs243.3Kb11cun040_00040013_ab9bb0752 headers apart57 IPs565b11cun040_00040411_2daa70d62 headers apart7 IPs149b11cun040_00040013_7df024fe2 headers apart2 IPs44

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.