HoneyLabs

Akin HTTP request fingerprint

b11cun063_08040010_f2f3ae25_x543371d48ba3

Seen 2026-07-07 to 2026-10-01 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS207043 sends an email when it next hits a sensor.

2

Source IPs

1

Networks

1

Countries

218

Ports hit

479

Events

2

IPs / network

Top networks

Countries

DE 2

Ports targeted

What it requests

User agents claimed

what-vpn-go/0.12 IPs479
Source IPCCNetwork Last seenEvents
94.26.83.79DEAS207043 Dedik Services Limited2026-10-01243
91.92.43.222DEAS207043 Dedik Services Limited2026-09-23236

Related fingerprints

No other fingerprint seen in the last 30 days is within two headers of this one.

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.