HoneyLabs

Akin HTTP request fingerprint

b11cun070_0014001f_ee0f0ad4

Seen 2026-07-23 to 2026-09-16 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS51167 sends an email when it next hits a sensor.

14

Source IPs

11

Networks

10

Countries

7

Ports hit

177

Events

1

IPs / network

This fingerprint is spread thinly across many networks, which is the shape of a common, widely-used client.

Top networks

Countries

FR 3IN 2US 2PE 1NL 1VN 1IR 1DE 1HK 1SG 1

Ports targeted

What it requests

GET/6

User agents claimed

Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36 Edg/125.0.0.012 IPs29
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.3611 IPs27
Mozilla/5.0 (iPhone; CPU iPhone OS 17_5 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.5 Mobile/15E148 Safari/604.110 IPs25
Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.3612 IPs25
Mozilla/5.0 (Android 14; Mobile; rv:128.0) Gecko/128.0 Firefox/128.012 IPs23
Source IPCCNetwork Last seenEvents
165.227.15.209USAS14061 DigitalOcean, LLC2026-09-1614
192.253.248.94NLAS213790 Limited Network LTD2026-09-1614
103.221.223.167VNAS63760 AZDIGI Corporation2026-09-1614
194.34.232.225FRAS51167 Contabo GmbH2026-09-1614
152.53.89.102USAS214996 netcup GmbH2026-09-1614
213.32.19.195FRAS16276 OVH SAS2026-09-1614
188.212.96.112IRAS60631 Vandad Vira Hooman LLC2026-09-1614
139.5.189.16INAS132420 282, Sector 192026-09-1614
192.26.215.2INAS142169 HIRDHAV TECHNOLOGIES PVT LTD2026-09-1614
161.132.42.84PEAS3132 Red Cientifica Peruana2026-09-1614
77.90.185.47DEAS213790 Limited Network LTD2026-09-1614
169.58.204.147FRAS51167 Contabo GmbH2026-09-1614
172.110.223.141HKAS23470 ReliableSite.Net LLC2026-09-046
15.235.185.191SGAS16276 OVH SAS2026-09-163

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun070_0014001f_c92214f9same header set5 IPs155b11cun070_0014001f_431a2e96same header set34 IPs66b11cun070_0014001f_85240426same header set12 IPs53b11cun070_0014001f_0e0f40c9same header set32 IPs38b11cun070_0014001f_e9d96a03same header set1 IPs5b11cun070_0014001f_52bdf4casame header set3 IPs3b11cun070_0014001f_19cf7b58same header set1 IPs2b11cun070_0014001f_dec2e7a6same header set1 IPs1

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.