HoneyLabs

Akin HTTP request fingerprint

b11cun061_00050013_f5830403_x0659

Seen 2026-02-19 to 2026-09-29 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS14618 sends an email when it next hits a sensor.

53

Source IPs

1

Networks

1

Countries

5

Ports hit

165

Events

53

IPs / network

This fingerprint is concentrated: many addresses on very few networks, which is what a single coordinated operation tends to look like.

Top networks

Countries

US 53

Ports targeted

What it requests

GET/_alias55
GET/55
GET/*55

User agents claimed

elasticsearch-py/7.13.4 (Python 3.10.21)53 IPs165
Source IPCCNetwork Last seenEvents
44.220.185.68USAS14618 Amazon.com, Inc.2026-09-296
44.220.185.219USAS14618 Amazon.com, Inc.2026-09-256
18.97.19.236USAS14618 Amazon.com, Inc.2026-09-183
44.220.185.249USAS14618 Amazon.com, Inc.2026-09-013
44.220.188.153USAS14618 Amazon.com, Inc.2026-09-063
44.220.185.209USAS14618 Amazon.com, Inc.2026-09-153
44.220.188.100USAS14618 Amazon.com, Inc.2026-09-213
98.80.4.27USAS14618 Amazon.com, Inc.2026-09-083
18.97.19.182USAS14618 Amazon.com, Inc.2026-09-243
44.220.188.221USAS14618 Amazon.com, Inc.2026-09-273
44.220.188.106USAS14618 Amazon.com, Inc.2026-09-283
18.97.26.62USAS14618 Amazon.com, Inc.2026-09-133
44.220.188.12USAS14618 Amazon.com, Inc.2026-09-233
44.220.188.244USAS14618 Amazon.com, Inc.2026-09-053
44.220.185.105USAS14618 Amazon.com, Inc.2026-09-013
98.80.4.64USAS14618 Amazon.com, Inc.2026-09-153
18.97.19.140USAS14618 Amazon.com, Inc.2026-09-213
44.220.185.213USAS14618 Amazon.com, Inc.2026-09-053
98.80.4.69USAS14618 Amazon.com, Inc.2026-09-263
44.220.185.240USAS14618 Amazon.com, Inc.2026-09-243

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun050_00050013_2619b3ac1 header apart4 IPs61b11cun040_00040013_608dab682 headers apart4.3K IPs243.3Kb11cuq060_00050813_95cc9d022 headers apart55 IPs3.1Kb11cun040_00040013_ab9bb0752 headers apart57 IPs565b11cun040_00050011_bf8a4cbb2 headers apart6 IPs152b11cuq060_00050813_8587a3e32 headers apart4 IPs107b11cun040_00040013_7df024fe2 headers apart2 IPs44b11cuk061_00050013_95cc9d02_xed802 headers apart1 IPs23

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.