HoneyLabs

Akin HTTP request fingerprint

b11cun120_011403df_782553ac

Seen 2026-02-19 to 2026-09-30 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS14618 sends an email when it next hits a sensor.

221

Source IPs

1

Networks

1

Countries

22

Ports hit

247

Events

221

IPs / network

This fingerprint is concentrated: many addresses on very few networks, which is what a single coordinated operation tends to look like.

Top networks

Countries

US 221

Ports targeted

What it requests

GET/247

User agents claimed

Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/58.0.3017.97 Safari/537.321 IPs1
Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/55.0.3089.78 Safari/537.321 IPs1
Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/56.0.3076.89 Safari/537.321 IPs1
Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/51.0.3081.55 Safari/537.321 IPs1
Mozilla/5.0 (Windows NT 6.2;en-US) AppleWebKit/537.32.36 (KHTML, live Gecko) Chrome/56.0.3070.93 Safari/537.321 IPs1
Source IPCCNetwork Last seenEvents
44.220.188.143USAS14618 Amazon.com, Inc.2026-09-282
44.220.188.61USAS14618 Amazon.com, Inc.2026-09-202
44.220.185.22USAS14618 Amazon.com, Inc.2026-09-302
44.220.188.142USAS14618 Amazon.com, Inc.2026-09-242
44.220.188.83USAS14618 Amazon.com, Inc.2026-09-182
44.220.185.234USAS14618 Amazon.com, Inc.2026-09-192
44.220.188.48USAS14618 Amazon.com, Inc.2026-09-282
44.220.188.157USAS14618 Amazon.com, Inc.2026-09-192
18.97.26.81USAS14618 Amazon.com, Inc.2026-09-272
44.220.188.84USAS14618 Amazon.com, Inc.2026-09-212
18.97.26.5USAS14618 Amazon.com, Inc.2026-09-262
18.97.19.221USAS14618 Amazon.com, Inc.2026-09-192
44.220.185.136USAS14618 Amazon.com, Inc.2026-09-142
44.220.185.154USAS14618 Amazon.com, Inc.2026-09-292
44.220.188.178USAS14618 Amazon.com, Inc.2026-09-272
18.97.5.17USAS14618 Amazon.com, Inc.2026-09-302
44.220.185.189USAS14618 Amazon.com, Inc.2026-09-212
44.220.188.1USAS14618 Amazon.com, Inc.2026-09-132
44.220.188.45USAS14618 Amazon.com, Inc.2026-09-282
18.97.26.119USAS14618 Amazon.com, Inc.2026-09-222

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun110_011401df_4655cc391 header apart2 IPs2b11cun100_000403df_ca7c9c5b2 headers apart2 IPs8b11cun120_001403ff_54ce9a6d2 headers apart1 IPs6b11cun120_001403ff_cec494bf2 headers apart1 IPs6b11cun120_011401ff_3f29ed352 headers apart1 IPs1b11cun100_001401df_09ea70d62 headers apart1 IPs1b11cun120_011401ff_516927ba2 headers apart1 IPs1b11cun120_011401ff_9d7259712 headers apart1 IPs1

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.