HoneyLabs

Akin HTTP request fingerprint

b11cun060_80040017_8e5e346c

Seen 2026-09-12 to 2026-09-12 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS396982 sends an email when it next hits a sensor.

2

Source IPs

1

Networks

1

Countries

1

Ports hit

3

Events

2

IPs / network

Top networks

Countries

US 2

Ports targeted

What it requests

User agents claimed

Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 Chrome/125.0 Safari/537.362 IPs3
Source IPCCNetwork Last seenEvents
35.238.120.46USAS396982 Google LLC2026-09-122
34.170.15.1USAS396982 Google LLC2026-09-121

Fingerprint family: 3 shapes, 464 IPs, 2.6K events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 5 headers, no body: connection, accept-encoding, accept, user-agent, host

asks for/ · /.env · /config.js · /.docker/config.json (GET)
asMozilla/5.0 (compatible; research-scan/1.0) · Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like · Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/12 and 25 more
ports8443 · 5173 · 443 · 9443
fromUS · NL · CN · FR · Oracle Corporation · Amazon.com, Inc. · Pfcloud UG (haftungsbeschrankt)
b11cun050_00040017_345c845bMozilla/5.0 (compatible; research-scan/1.0) · /464 IPs2.6Kb11cun060_0004001f_f6be99b4+/- accept-language · Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chr · /v1/openapi.json4 IPs20b11cun060_80040017_8e5e346c this one+/- x-forwarded-for · Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 Chrome/125.0 Safari/537.36 · /api/config2 IPs3

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun050_00040017_976354f01 header apart1.3K IPs19.1Kb11cun050_00040017_6b90553b1 header apart1.3K IPs9.4Kb11cun050_00040017_e873236c1 header apart713 IPs6.2Kb11cun050_00040017_d1f380a61 header apart4 IPs3.6Kb11cun050_00040017_eba289fe1 header apart19 IPs2.8Kb11cun050_00040017_345c845b1 header apart464 IPs2.6Kb11cun050_00040017_97f1d74f1 header apart38 IPs2.0Kb11cun050_00040017_2015d6b21 header apart524 IPs1.2K

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.