HoneyLabs

Akin HTTP request fingerprint

b11cun070_0014001f_0e0f40c9

Seen 2026-05-12 to 2026-09-26 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS12552 sends an email when it next hits a sensor.

32

Source IPs

1

Networks

1

Countries

13

Ports hit

38

Events

32

IPs / network

This fingerprint is concentrated: many addresses on very few networks, which is what a single coordinated operation tends to look like.

Top networks

Countries

SE 32

Ports targeted

What it requests

GET/38

User agents claimed

Mozilla/5.0 (Windows NT 6.3; Win64; x64; rv:109.0) Gecko/20100101 Firefox/11511 IPs13
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.311 IPs13
Mozilla/5.0 (Linux; U; Android 13; sk-sk; Xiaomi 11T Pro Build/TKQ1.220829.002) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/112.0.5615.136 Mobile Safari/537.36 XiaoMi/MiuiBrowser/14.4.0-g10 IPs12
Source IPCCNetwork Last seenEvents
93.158.90.155SEAS12552 GlobalConnect AB2026-09-262
93.158.90.55SEAS12552 GlobalConnect AB2026-09-092
93.158.90.169SEAS12552 GlobalConnect AB2026-09-262
93.158.90.65SEAS12552 GlobalConnect AB2026-09-092
93.158.90.53SEAS12552 GlobalConnect AB2026-09-192
93.158.90.29SEAS12552 GlobalConnect AB2026-09-192
93.158.90.57SEAS12552 GlobalConnect AB2026-09-091
93.158.90.62SEAS12552 GlobalConnect AB2026-09-091
93.158.90.168SEAS12552 GlobalConnect AB2026-09-261
93.158.90.144SEAS12552 GlobalConnect AB2026-09-261
93.158.90.142SEAS12552 GlobalConnect AB2026-09-261
93.158.90.58SEAS12552 GlobalConnect AB2026-09-091
93.158.90.46SEAS12552 GlobalConnect AB2026-09-191
93.158.90.67SEAS12552 GlobalConnect AB2026-09-091
93.158.90.41SEAS12552 GlobalConnect AB2026-09-191
93.158.90.30SEAS12552 GlobalConnect AB2026-09-191
93.158.90.164SEAS12552 GlobalConnect AB2026-09-261
93.158.90.136SEAS12552 GlobalConnect AB2026-09-261
93.158.90.42SEAS12552 GlobalConnect AB2026-09-191
93.158.90.143SEAS12552 GlobalConnect AB2026-09-261

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun070_0014001f_ee0f0ad4same header set14 IPs177b11cun070_0014001f_c92214f9same header set5 IPs155b11cun070_0014001f_431a2e96same header set34 IPs66b11cun070_0014001f_85240426same header set12 IPs53b11cun070_0014001f_52bdf4casame header set3 IPs3b11cun070_0014001f_19cf7b58same header set1 IPs2b11cun070_0014001f_a178c378same header set1 IPs1b11cun070_0014001f_dec2e7a6same header set1 IPs1

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.