Akin HTTP request fingerprint
b11cun120_011403df_782553ac
Seen 2026-02-19 to 2026-09-30 across the retained window.
The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked.
Or watch the top network: AS14618 sends an email when it next hits a sensor.
This fingerprint is concentrated: many addresses on very few networks, which is what a single coordinated operation tends to look like.
User agents claimed
Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/58.0.3017.97 Safari/537.321 IPs1
Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/55.0.3089.78 Safari/537.321 IPs1
Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/56.0.3076.89 Safari/537.321 IPs1
Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/51.0.3081.55 Safari/537.321 IPs1
Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/56.0.3070.93 Safari/537.321 IPs1
Source IPCCNetwork
Last seenEvents
44.220.188.143USAS14618 Amazon.com, Inc.2026-09-282 44.220.188.61USAS14618 Amazon.com, Inc.2026-09-202 44.220.185.22USAS14618 Amazon.com, Inc.2026-09-302 44.220.188.142USAS14618 Amazon.com, Inc.2026-09-242 44.220.188.83USAS14618 Amazon.com, Inc.2026-09-182 44.220.185.234USAS14618 Amazon.com, Inc.2026-09-192 44.220.188.48USAS14618 Amazon.com, Inc.2026-09-282 44.220.188.157USAS14618 Amazon.com, Inc.2026-09-192 18.97.26.81USAS14618 Amazon.com, Inc.2026-09-272 44.220.188.84USAS14618 Amazon.com, Inc.2026-09-212 18.97.26.5USAS14618 Amazon.com, Inc.2026-09-262 18.97.19.221USAS14618 Amazon.com, Inc.2026-09-192 44.220.185.136USAS14618 Amazon.com, Inc.2026-09-142 44.220.185.154USAS14618 Amazon.com, Inc.2026-09-292 44.220.188.178USAS14618 Amazon.com, Inc.2026-09-272 18.97.5.17USAS14618 Amazon.com, Inc.2026-09-302 44.220.185.189USAS14618 Amazon.com, Inc.2026-09-212 44.220.188.1USAS14618 Amazon.com, Inc.2026-09-132 44.220.188.45USAS14618 Amazon.com, Inc.2026-09-282 18.97.26.119USAS14618 Amazon.com, Inc.2026-09-222
About this fingerprint
Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.