HoneyLabs

Akin HTTP request fingerprint

b11cun061_00040017_1e93cacd_x7585

Seen 2026-05-04 to 2026-09-15 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS15169 sends an email when it next hits a sensor.

7

Source IPs

1

Networks

1

Countries

2

Ports hit

19

Events

7

IPs / network

Top networks

Countries

US 7

Ports targeted

What it requests

User agents claimed

Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)7 IPs19
Source IPCCNetwork Last seenEvents
66.249.68.70USAS15169 Google LLC2026-09-159
66.249.68.64USAS15169 Google LLC2026-09-134
66.249.68.71USAS15169 Google LLC2026-09-142
66.249.68.66USAS15169 Google LLC2026-09-021
66.249.68.67USAS15169 Google LLC2026-09-011
66.249.66.36USAS15169 Google LLC2026-09-091
66.249.68.65USAS15169 Google LLC2026-08-311

Fingerprint family: 2 shapes, 10 IPs, 39 events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 5 headers, no body: connection, accept-encoding, accept, user-agent, host

asks for/robots.txt · /ads.txt · /api/general-info (GET)
asMozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html) · Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) and 1 more
ports443 · 80
fromUS · IT · KR · TW · Google LLC · Arisk Communications inc. · Cogent Communications, LLC
b11cun050_00040017_632d8572Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) · /api/general-info10 IPs20b11cun061_00040017_1e93cacd_x7585 this one+/- from · Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html) · /ads.txt7 IPs19

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun061_00040017_8e5e346c_x7585same header set2 IPs2b11cun050_00040017_976354f01 header apart1.3K IPs18.9Kb11cun050_00040017_6b90553b1 header apart1.3K IPs9.3Kb11cun050_00040017_e873236c1 header apart685 IPs6.1Kb11cun050_00040017_d1f380a61 header apart4 IPs3.4Kb11cun050_00040017_eba289fe1 header apart19 IPs2.8Kb11cun050_00040017_345c845b1 header apart468 IPs2.6Kb11cun050_00040017_97f1d74f1 header apart38 IPs2.0K

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.