HoneyLabs

Akin HTTP request fingerprint

b11cun080_0005005f_384a0c90

Seen 2026-02-16 to 2026-09-30 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS21859 sends an email when it next hits a sensor.

50

Source IPs

2

Networks

1

Countries

787

Ports hit

3.7K

Events

25

IPs / network

This fingerprint is concentrated: many addresses on very few networks, which is what a single coordinated operation tends to look like.

Top networks

Countries

PT 50

Ports targeted

What it requests

GET/sse3.7K

User agents claimed

python-httpx/0.28.150 IPs3.7K
Source IPCCNetwork Last seenEvents
185.226.197.117PTAS21859 Zenlayer Inc2026-09-30167
185.180.141.100PTAS21859 Zenlayer Inc2026-09-30125
185.180.141.80PTAS21859 Zenlayer Inc2026-09-30114
185.180.141.90PTAS21859 Zenlayer Inc2026-09-30111
185.180.141.85PTAS21859 Zenlayer Inc2026-09-30110
185.180.141.95PTAS21859 Zenlayer Inc2026-09-3098
45.156.129.187PTAS211680 Sistemas Informaticos, S.A.2026-09-2496
45.156.129.54PTAS211680 Sistemas Informaticos, S.A.2026-09-2491
109.105.210.102PTAS21859 Zenlayer Inc2026-09-2488
185.180.141.47PTAS21859 Zenlayer Inc2026-09-2982
109.105.210.72PTAS21859 Zenlayer Inc2026-09-2982
45.156.129.95PTAS211680 Sistemas Informaticos, S.A.2026-09-2579
45.156.129.186PTAS211680 Sistemas Informaticos, S.A.2026-09-2479
45.156.128.10PTAS211680 Sistemas Informaticos, S.A.2026-09-2478
185.180.141.7PTAS21859 Zenlayer Inc2026-09-3078
185.180.141.115PTAS21859 Zenlayer Inc2026-09-3077
45.156.129.85PTAS211680 Sistemas Informaticos, S.A.2026-09-2576
45.156.129.80PTAS211680 Sistemas Informaticos, S.A.2026-09-3075
45.156.128.76PTAS211680 Sistemas Informaticos, S.A.2026-09-2475
45.156.128.41PTAS211680 Sistemas Informaticos, S.A.2026-09-2473

Fingerprint family: 2 shapes, 50 IPs, 7.4K events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 9 headers, Content-Length body: connection, accept-encoding, accept, accept-language, user-agent, sec-fetch-mode, content-length, content-type, host

asks for/mcp · /sse (POST / GET)
aspython-httpx/0.28.1 and 1 more
ports53 · 1599 · 3310 · 7548
fromPT · Zenlayer Inc · Sistemas Informaticos, S.A.
b11cuq090_0005085f_0df56ff0python-httpx/0.28.1 · /mcp50 IPs3.7Kb11cun080_0005005f_384a0c90 this one+/- content-length · python-httpx/0.28.1 · /sse50 IPs3.7K

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cuq090_0005085f_0df56ff01 header apart50 IPs3.7Kb11cun070_0005001f_498e5f6c1 header apart1 IPs18b11cun070_0004005f_7d305ebf1 header apart2 IPs4b11cuq090_0005085f_959e607d1 header apart1 IPs1b11cun060_0004001f_d170ef012 headers apart16 IPs35.1Kb11cdn091_0005001f_70058852_xff632 headers apart9 IPs4.7Kb11cun060_0004001f_eefe52102 headers apart19 IPs4.0Kb11cun060_0004001f_7d5e642b2 headers apart441 IPs2.7K

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.