HoneyLabs

Akin HTTP request fingerprint

b11cun070_0014001f_431a2e96

Seen 2026-02-20 to 2026-09-05 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS16276 sends an email when it next hits a sensor.

34

Source IPs

21

Networks

14

Countries

4

Ports hit

66

Events

2

IPs / network

This fingerprint is spread thinly across many networks, which is the shape of a common, widely-used client.

Top networks

Countries

CN 7FR 6SG 4DE 3US 3IN 2VN 2TW 1PT 1HK 1

Ports targeted

What it requests

User agents claimed

Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/125 Safari/537.3634 IPs66
Source IPCCNetwork Last seenEvents
213.177.179.52TWAS208137 Feo Prest SRL2026-09-046
103.106.104.187VNAS151858 INTERDIGI JOINT STOCK COMPANY2026-09-042
124.223.38.27CNAS45090 Shenzhen Tencent Computer Systems Company Limited2026-09-052
62.171.174.208FRAS51167 Contabo GmbH2026-09-052
84.247.145.2SGAS141995 Contabo Asia Private Limited2026-09-042
93.46.24.112ITAS12874 Fastweb2026-09-052
51.91.8.17FRAS16276 OVH SAS2026-09-042
94.46.172.237PTAS24768 Almouroltec Servicos De Informatica E Internet Lda2026-09-052
77.90.185.47DEAS213790 Limited Network LTD2026-09-042
135.148.46.133USAS16276 OVH SAS2026-09-042
38.156.13.6COAS272156 WEB MASTER COLOMBIA SAS2026-09-042
43.131.58.26DEAS132203 Tencent Building, Kejizhongyi Avenue2026-09-042
192.99.42.5CAAS16276 OVH SAS2026-09-042
160.250.204.33INAS140641 YOTTA NETWORK SERVICES PRIVATE LIMITED2026-09-052
118.139.165.143SGAS26496 GoDaddy.com, LLC2026-09-042
185.243.53.182PLAS41079 Cyber_Folks S.A.2026-09-042
43.163.81.168SGAS132203 Tencent Building, Kejizhongyi Avenue2026-09-052
51.38.115.161FRAS16276 OVH SAS2026-09-052
51.83.154.242FRAS16276 OVH SAS2026-09-042
167.233.139.13DEAS24940 Hetzner Online GmbH2026-09-042

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun070_0014001f_ee0f0ad4same header set14 IPs177b11cun070_0014001f_c92214f9same header set5 IPs155b11cun070_0014001f_85240426same header set12 IPs53b11cun070_0014001f_0e0f40c9same header set32 IPs38b11cun070_0014001f_e9d96a03same header set1 IPs5b11cun070_0014001f_52bdf4casame header set3 IPs3b11cun070_0014001f_19cf7b58same header set1 IPs2b11cun070_0014001f_a178c378same header set1 IPs1

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.