HoneyLabs

Akin HTTP request fingerprint

b11cun080_0034001f_ee1daacd

Seen 2026-02-16 to 2026-09-30 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS208843 sends an email when it next hits a sensor.

762

Source IPs

3

Networks

3

Countries

722

Ports hit

7.1K

Events

254

IPs / network

This fingerprint is concentrated: many addresses on very few networks, which is what a single coordinated operation tends to look like.

Top networks

Countries

DE 254US 254HK 254

Ports targeted

What it requests

GET/3.6K

User agents claimed

Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:65.0) Gecko/20100101 Firefox/65.0762 IPs7.1K
Source IPCCNetwork Last seenEvents
194.187.176.22DEAS208843 Alpha Strike Labs GmbH2026-09-2923
194.187.176.195DEAS208843 Alpha Strike Labs GmbH2026-09-2922
194.187.176.248DEAS208843 Alpha Strike Labs GmbH2026-09-3021
194.187.176.182DEAS208843 Alpha Strike Labs GmbH2026-09-2821
194.187.176.165DEAS208843 Alpha Strike Labs GmbH2026-09-2920
194.187.176.33DEAS208843 Alpha Strike Labs GmbH2026-09-2820
194.187.176.30DEAS208843 Alpha Strike Labs GmbH2026-09-2920
194.187.179.84USAS42969 Alpha Strike Labs GmbH2026-09-2820
194.187.176.106DEAS208843 Alpha Strike Labs GmbH2026-09-2819
194.187.176.91DEAS208843 Alpha Strike Labs GmbH2026-09-2819
194.187.176.66DEAS208843 Alpha Strike Labs GmbH2026-09-2819
194.187.179.128USAS42969 Alpha Strike Labs GmbH2026-09-2618
194.187.176.67DEAS208843 Alpha Strike Labs GmbH2026-09-2818
194.187.179.250USAS42969 Alpha Strike Labs GmbH2026-09-2818
194.187.176.3DEAS208843 Alpha Strike Labs GmbH2026-09-2917
194.187.176.114DEAS208843 Alpha Strike Labs GmbH2026-09-2717
194.187.176.163DEAS208843 Alpha Strike Labs GmbH2026-09-3017
194.187.176.52DEAS208843 Alpha Strike Labs GmbH2026-09-2917
194.187.176.170DEAS208843 Alpha Strike Labs GmbH2026-09-3017
194.187.176.62DEAS208843 Alpha Strike Labs GmbH2026-09-2717

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun080_0034001f_cf656185same header set1 IPs1b11cun080_0034001f_f0e5cf43same header set1 IPs1b11cun080_0034001f_c289267asame header set1 IPs1b11cdn100_0034003f_d1da082f1 header apart407 IPs1.1Kb11cun070_0014001f_ee0f0ad41 header apart14 IPs177b11cun070_0014001f_c92214f91 header apart5 IPs155b11cun070_0014001f_431a2e961 header apart34 IPs66b11cun070_0014001f_852404261 header apart12 IPs53

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.