HoneyLabs

Akin HTTP request fingerprint

b11cun070_0006041d_01a11761

Seen 2026-02-16 to 2026-10-01 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS135377 sends an email when it next hits a sensor.

147

Source IPs

5

Networks

5

Countries

857

Ports hit

4.2K

Events

29

IPs / network

Top networks

Countries

HK 107CN 35US 3SG 1SC 1

Ports targeted

What it requests

User agents claimed

Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36147 IPs4.2K
Source IPCCNetwork Last seenEvents
152.32.209.108HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-10-0147
152.32.254.132HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-3043
156.225.1.37HKAS9465 AGOTOZ PTE. LTD.2026-10-0143
156.225.1.18HKAS9465 AGOTOZ PTE. LTD.2026-10-0142
156.225.1.113HKAS9465 AGOTOZ PTE. LTD.2026-10-0141
156.225.1.45HKAS9465 AGOTOZ PTE. LTD.2026-10-0141
152.32.133.206HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-3041
156.225.1.31HKAS9465 AGOTOZ PTE. LTD.2026-09-3041
156.225.1.100HKAS9465 AGOTOZ PTE. LTD.2026-10-0140
156.225.1.96HKAS9465 AGOTOZ PTE. LTD.2026-09-3040
101.36.106.109HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-10-0139
128.1.132.84HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-3039
156.225.1.13HKAS9465 AGOTOZ PTE. LTD.2026-09-3039
123.58.209.194HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-10-0138
123.58.212.238HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-10-0138
156.225.1.43HKAS9465 AGOTOZ PTE. LTD.2026-10-0138
118.26.38.132HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-3037
156.225.1.112HKAS9465 AGOTOZ PTE. LTD.2026-10-0137
106.75.3.6CNAS4808 China Unicom Beijing Province Network2026-10-0137
128.1.132.17HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-3037

Fingerprint family: 2 shapes, 211 IPs, 9.6K events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 6 headers, no body: connection, accept, accept-language, user-agent, accept-charset, host

asks for/favicon.ico · / (GET)
asMozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0. · Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:134.0) Gecko/20100101 Firefox/134.0 and 1 more
ports9443 · 5601 · 554 · 9100
fromHK · CN · SG · US · AGOTOZ PTE. LTD. · UCLOUD INFORMATION TECHNOLOGY (HK) LIMIT · ONYPHE SAS
b11cun060_0006001d_3af976daMozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0. · /211 IPs5.5Kb11cun070_0006041d_01a11761 this one+/- referer · Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0. · /favicon.ico147 IPs4.2K

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun060_0006001d_3af976da1 header apart211 IPs5.5Kb11cun050_0004001d_5cbb346f2 headers apart977 IPs168.4Kb11cun050_0004001d_e6fe1ac32 headers apart40 IPs1.1Kb11cun050_0004001d_fda4f7dc2 headers apart3 IPs282b11cun050_0004001d_7a38a7f72 headers apart38 IPs65b11cun050_0004001d_7a5b0fd72 headers apart2 IPs5b11cun050_0004001d_7129ba852 headers apart2 IPs4

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.