HoneyLabs

Akin HTTP request fingerprint

b11cun080_0014003f_c4330fcc

Seen 2026-05-13 to 2026-09-30 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS8075 sends an email when it next hits a sensor.

6

Source IPs

3

Networks

5

Countries

2

Ports hit

3.8K

Events

2

IPs / network

Top networks

Countries

US 2SG 1NL 1JP 1FR 1

Ports targeted

What it requests

User agents claimed

Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.366 IPs1.2K
Mozilla/5.0 (X11; Linux x86_64; rv:134.0) Gecko/20100101 Firefox/134.02 IPs304
Mozilla/5.0 (iPhone; CPU iPhone OS 18_2 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.2 Mobile/15E148 Safari/605.1.152 IPs296
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.362 IPs290
Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.362 IPs289
Source IPCCNetwork Last seenEvents
188.166.248.40SGAS14061 DigitalOcean, LLC2026-09-121.7K
45.148.10.238NLAS48090 Techoff Srv Limited2026-09-301.1K
40.81.186.168JPAS8075 Microsoft Corporation2026-09-17468
20.106.209.149USAS8075 Microsoft Corporation2026-09-14156
20.19.48.9FRAS8075 Microsoft Corporation2026-09-25156
74.235.187.110USAS8075 Microsoft Corporation2026-09-22156

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun080_0014003f_335d21efsame header set2 IPs193b11cun080_0014003f_ebbed6c4same header set3 IPs3b11cun080_0014003f_1ba155c2same header set2 IPs2b11cun080_0014003f_d6aeff2fsame header set1 IPs2b11cun080_0014003f_1cf44f23same header set1 IPs2b11cun080_0014003f_4dcc6592same header set1 IPs1b11cun080_0014003f_689862bcsame header set1 IPs1b11cun080_0014003f_e6239704same header set1 IPs1

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.