HoneyLabs

Akin HTTP request fingerprint

b11cun061_00040017_415fcbe9_x70fd

Seen 2026-02-16 to 2026-10-01 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS211680 sends an email when it next hits a sensor.

22

Source IPs

2

Networks

1

Countries

7

Ports hit

47

Events

11

IPs / network

This fingerprint is concentrated: many addresses on very few networks, which is what a single coordinated operation tends to look like.

Top networks

Countries

PT 22

Ports targeted

What it requests

User agents claimed

Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.6312.86 Safari/537.3622 IPs47
Source IPCCNetwork Last seenEvents
45.156.129.172PTAS211680 Sistemas Informaticos, S.A.2026-10-018
45.156.129.120PTAS211680 Sistemas Informaticos, S.A.2026-09-304
185.226.197.67PTAS21859 Zenlayer Inc2026-09-244
45.156.129.136PTAS211680 Sistemas Informaticos, S.A.2026-09-254
45.156.129.125PTAS211680 Sistemas Informaticos, S.A.2026-09-303
185.226.196.17PTAS21859 Zenlayer Inc2026-09-243
109.105.209.17PTAS21859 Zenlayer Inc2026-09-302
185.226.196.27PTAS21859 Zenlayer Inc2026-09-292
45.156.128.152PTAS211680 Sistemas Informaticos, S.A.2026-09-292
45.156.129.152PTAS211680 Sistemas Informaticos, S.A.2026-09-252
109.105.210.87PTAS21859 Zenlayer Inc2026-10-012
45.156.129.115PTAS211680 Sistemas Informaticos, S.A.2026-09-011
45.156.129.176PTAS211680 Sistemas Informaticos, S.A.2026-09-081
45.156.128.11PTAS211680 Sistemas Informaticos, S.A.2026-09-161
45.156.129.168PTAS211680 Sistemas Informaticos, S.A.2026-09-301
45.156.129.110PTAS211680 Sistemas Informaticos, S.A.2026-09-111
185.226.198.4PTAS211680 Sistemas Informaticos, S.A.2026-09-231
185.226.197.57PTAS21859 Zenlayer Inc2026-09-071
45.156.129.156PTAS211680 Sistemas Informaticos, S.A.2026-09-131
45.156.128.168PTAS211680 Sistemas Informaticos, S.A.2026-09-101

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun050_00040017_976354f01 header apart1.3K IPs19.1Kb11cun050_00040017_6b90553b1 header apart1.3K IPs9.4Kb11cun050_00040017_e873236c1 header apart712 IPs6.2Kb11cun050_00040017_d1f380a61 header apart4 IPs3.6Kb11cun050_00040017_eba289fe1 header apart19 IPs2.8Kb11cun050_00040017_345c845b1 header apart464 IPs2.6Kb11cun050_00040017_97f1d74f1 header apart38 IPs2.0Kb11cun050_00040017_2015d6b21 header apart524 IPs1.2K

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.