HoneyLabs

Akin HTTP request fingerprint

b11cun060_0044001e_9fddb4ee

Seen 2026-02-19 to 2026-09-30 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS63199 sends an email when it next hits a sensor.

7

Source IPs

1

Networks

1

Countries

57

Ports hit

105

Events

7

IPs / network

Top networks

Countries

JP 7

Ports targeted

What it requests

GET/105

User agents claimed

Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.367 IPs105
Source IPCCNetwork Last seenEvents
164.52.24.181JPAS63199 CDS Global Cloud Co., Ltd2026-09-2929
164.52.24.190JPAS63199 CDS Global Cloud Co., Ltd2026-09-3022
164.52.24.184JPAS63199 CDS Global Cloud Co., Ltd2026-09-2922
164.52.24.180JPAS63199 CDS Global Cloud Co., Ltd2026-09-3015
164.52.24.182JPAS63199 CDS Global Cloud Co., Ltd2026-09-2014
164.52.0.92JPAS63199 CDS Global Cloud Co., Ltd2026-09-182
164.52.24.185JPAS63199 CDS Global Cloud Co., Ltd2026-09-201

Fingerprint family: 2 shapes, 7 IPs, 216 events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 5 headers, no body: accept, accept-language, user-agent, host, authorization

asks for/ (GET)
asMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) and 1 more
ports14344 · 6666 · 12345 · 8880
fromJP · CDS Global Cloud Co., Ltd
b11cun050_0044001c_d97268c3Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) · /7 IPs111b11cun060_0044001e_9fddb4ee this one+/- accept-encoding · Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) · /7 IPs105

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun050_0004001e_a647ba7f1 header apart27 IPs146.7Kb11cun050_0004001e_5f8868581 header apart562 IPs34.5Kb11cun050_0004001e_00ecc3a81 header apart83 IPs3.7Kb11cun050_0004001e_377ad04d1 header apart113 IPs271b11cun050_0004001e_d490606f1 header apart76 IPs190b11cun050_0004001e_b55602bc1 header apart10 IPs115b11cun050_0044001c_d97268c31 header apart7 IPs111b11cun050_00440016_6289c8651 header apart54 IPs65

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.