HoneyLabs

Akin HTTP request fingerprint

b11cun060_00440017_1d464540

Seen 2026-09-24 to 2026-09-28 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS4134 sends an email when it next hits a sensor.

3

Source IPs

3

Networks

3

Countries

3

Ports hit

6

Events

1

IPs / network

This fingerprint is spread thinly across many networks, which is the shape of a common, widely-used client.

Top networks

Countries

CN 1NL 1BG 1

Ports targeted

What it requests

User agents claimed

ghost-pay-hunter1 IPs1
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Safari/605.1.151 IPs1
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.361 IPs1
Mozilla/5.0 (X11; Linux x86_64; rv:116.0) Gecko/20100101 Firefox/116.01 IPs1
Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.361 IPs1
Source IPCCNetwork Last seenEvents
106.58.237.189CNAS4134 Chinanet2026-09-254
195.178.110.50BGAS48090 Techoff Srv Limited2026-09-271
94.154.43.222NLAS219502 Storm Industries LLC2026-09-281

Fingerprint family: 11 shapes, 1.3K IPs, 116.9K events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 5 headers, no body: connection, accept-encoding, accept, user-agent, host

asks for/.azure/credentials · /.aws/config · /my.ini · /.env.development (GET / POST)
asMozilla/5.0 (Windows NT 10.0; Win64; x64; rv:125.0) Gecko/20100101 Firefox/125.0 · Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) · Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/605.1.15 (KHTML, like G and 155 more
ports5000 · 5005 · 3000 · 1723
fromNL · DE · CY · HK · Limited Network LTD · Feo Prest SRL · NetCrafters OU
b11cun050_00040017_6b90553bMozilla/5.0 (X11; Linux x86_64; rv:135.0) Gecko/20100101 Firefox/135.0 · /1.3K IPs9.3Kb11cun051_00040016_6289c865_x2269+/- connection, range · Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:125.0) Gecko/20100101 Firefox/125.0 · /.aws/config3 IPs93.2Kb11cun061_00040017_a9482ae2_x74db+/- proxy-authorization · python-requests/2.34.2 · http://ip-api.com/json/?fields=status,country,countryCode,qu3 IPs59b11cun060_00440017_1d464540 this one+/- authorization · ghost-pay-hunter · /admin/3 IPs6b11cuq082_00040817_03a2bf31_xd368ff63+/- content-length, x-csrf-token, x-requested-with · Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) · /panel/api/inbounds/list2 IPs7.8Kb11cun072_00040017_4c344a22_xd368ff63+/- x-csrf-token, x-requested-with · Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) · /xui/API/inbounds/2 IPs5.8Kb11cdn071_00040017_9f8bde3d_xd99b+/- d99b · Mozilla/5.0 (Macintosh; Intel Mac OS X 14_4_1) AppleWebKit/537.36 (KHTML, like G · /.env.development.local2 IPs412b11cun061_00040017_c5b51fcd_xff63+/- x-requested-with · Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) · /csrf-token2 IPs221b11cun040_00040016_03bbcb12+/- connection · CryptoHunter-Vite-2026/1.0 · /src/main.ts2 IPs50b11cuq060_00040817_1d464540+/- content-length · Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_5) AppleWebKit/605.1.15 (KHTML, lik · /login.htm2 IPs9b11cun050_00040017_69b07330Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) · /cgi-bin/login.cgi2 IPs5

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun060_00440017_db470247same header set3 IPs42b11cun060_00440017_a9482ae2same header set1 IPs4b11cun060_00440017_229ec904same header set1 IPs2b11cun050_00040017_976354f01 header apart1.3K IPs18.8Kb11cun050_00040017_6b90553b1 header apart1.3K IPs9.3Kb11cun050_00040017_e873236c1 header apart680 IPs6.1Kb11cun050_00040017_eba289fe1 header apart19 IPs2.8Kb11cun050_00040017_345c845b1 header apart467 IPs2.6K

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.