HoneyLabs

Akin HTTP request fingerprint

b11cun120_000c03ff_bacda3cd

Seen 2026-02-17 to 2026-09-30 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS14061 sends an email when it next hits a sensor.

1.5K

Source IPs

2

Networks

7

Countries

131

Ports hit

1.5K

Events

731

IPs / network

This fingerprint is concentrated: many addresses on very few networks, which is what a single coordinated operation tends to look like.

Top networks

Unattributed2 IPs2

Countries

US 1.2KNL 68IN 67DE 58CA 49GB 42BR 3

Ports targeted

What it requests

GET/1.5K

User agents claimed

Mozilla/5.0 (X11; Linux x86_64; rv:142.0) Gecko/20100101 Firefox/142.0977 IPs997
Mozilla/5.0 (X11; Linux x86_64; rv:153.0) Gecko/20100101 Firefox/153.0487 IPs497
Source IPCCNetwork Last seenEvents
137.184.11.241USAS14061 DigitalOcean, LLC2026-09-102
137.184.15.119USAS14061 DigitalOcean, LLC2026-09-222
167.71.92.233USAS14061 DigitalOcean, LLC2026-09-072
143.198.146.164USAS14061 DigitalOcean, LLC2026-09-282
137.184.89.219USAS14061 DigitalOcean, LLC2026-09-132
165.232.143.54USAS14061 DigitalOcean, LLC2026-09-272
209.38.75.173USAS14061 DigitalOcean, LLC2026-09-152
159.89.229.22USAS14061 DigitalOcean, LLC2026-09-092
147.182.210.56USAS14061 DigitalOcean, LLC2026-09-242
206.189.203.124USAS14061 DigitalOcean, LLC2026-09-132
64.23.131.208USAS14061 DigitalOcean, LLC2026-09-222
143.198.225.183USAS14061 DigitalOcean, LLC2026-09-012
143.244.185.119USAS14061 DigitalOcean, LLC2026-09-202
137.184.2.218USAS14061 DigitalOcean, LLC2026-09-012
134.122.113.30USAS14061 DigitalOcean, LLC2026-09-282
164.90.153.15USAS14061 DigitalOcean, LLC2026-09-292
147.182.193.140USAS14061 DigitalOcean, LLC2026-09-102
137.184.94.51USAS14061 DigitalOcean, LLC2026-09-082
143.198.153.66USAS14061 DigitalOcean, LLC2026-09-102
147.182.241.21USAS14061 DigitalOcean, LLC2026-09-292

Fingerprint family: 2 shapes, 1.5K IPs, 3.0K events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 12 headers, no body: connection, accept-encoding, accept, accept-language, user-agent, upgrade-insecure-requests, sec-fetch-mode, sec-fetch-site, sec-fetch-dest, sec-fetch-user, host, priority

asks for/ · /favicon.ico (GET)
asMozilla/5.0 (X11; Linux x86_64; rv:142.0) Gecko/20100101 Firefox/142.0 · Mozilla/5.0 (X11; Linux x86_64; rv:153.0) Gecko/20100101 Firefox/153.0 and 2 more
ports50050 · 8089 · 31337 · 8088
fromUS · NL · IN · DE · DigitalOcean, LLC
b11cun120_000c03ff_bacda3cd this oneMozilla/5.0 (X11; Linux x86_64; rv:142.0) Gecko/20100101 Firefox/142.0 · /1.5K IPs1.5Kb11cun130_000c07ff_07814c6e+/- referer · Mozilla/5.0 (X11; Linux x86_64; rv:142.0) Gecko/20100101 Firefox/142.0 · /favicon.ico1.5K IPs1.5K

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun130_000c07ff_07814c6e1 header apart1.5K IPs1.5Kb11cdn140_000c83ff_367813631 header apart2 IPs66b11cun110_000403ff_023f08111 header apart10 IPs11b11cun110_000403ff_4f506d791 header apart2 IPs4b11cun100_000403df_ca7c9c5b2 headers apart2 IPs8b11cun120_001403ff_54ce9a6d2 headers apart1 IPs6b11cun120_000443ff_66e0f3732 headers apart1 IPs6b11cun120_001403ff_cec494bf2 headers apart1 IPs6

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.