Akin HTTP request fingerprint
b11cun070_0006041d_01a11761
Seen 2026-02-16 to 2026-10-01 across the retained window.
The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked.
Or watch the top network: AS135377 sends an email when it next hits a sensor.
Countries
HK 107CN 35US 3SG 1SC 1
User agents claimed
Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36147 IPs4.2K
Source IPCCNetwork
Last seenEvents
152.32.209.108HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-10-0147 152.32.254.132HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-3043 156.225.1.37HKAS9465 AGOTOZ PTE. LTD.2026-10-0143 156.225.1.18HKAS9465 AGOTOZ PTE. LTD.2026-10-0142 156.225.1.113HKAS9465 AGOTOZ PTE. LTD.2026-10-0141 156.225.1.45HKAS9465 AGOTOZ PTE. LTD.2026-10-0141 152.32.133.206HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-3041 156.225.1.31HKAS9465 AGOTOZ PTE. LTD.2026-09-3041 156.225.1.100HKAS9465 AGOTOZ PTE. LTD.2026-10-0140 156.225.1.96HKAS9465 AGOTOZ PTE. LTD.2026-09-3040 101.36.106.109HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-10-0139 128.1.132.84HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-3039 156.225.1.13HKAS9465 AGOTOZ PTE. LTD.2026-09-3039 123.58.209.194HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-10-0138 123.58.212.238HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-10-0138 156.225.1.43HKAS9465 AGOTOZ PTE. LTD.2026-10-0138 118.26.38.132HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-3037 156.225.1.112HKAS9465 AGOTOZ PTE. LTD.2026-10-0137 106.75.3.6CNAS4808 China Unicom Beijing Province Network2026-10-0137 128.1.132.17HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-3037
Fingerprint family: 2 shapes, 211 IPs, 9.6K events in 30 days
Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.
HTTP/1.1, 6 headers, no body: connection, accept, accept-language, user-agent, accept-charset, host
asks for/favicon.ico · / (GET)
asMozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0. · Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:134.0) Gecko/20100101 Firefox/134.0 and 1 more
ports9443 · 5601 · 554 · 9100
fromHK · CN · SG · US · AGOTOZ PTE. LTD. · UCLOUD INFORMATION TECHNOLOGY (HK) LIMIT · ONYPHE SAS
b11cun060_0006001d_3af976daMozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0. · /211 IPs5.5Kb11cun070_0006041d_01a11761 this one+/- referer · Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0. · /favicon.ico147 IPs4.2K
About this fingerprint
Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.