HoneyLabs

Akin HTTP request fingerprint

b11cun150_003473fe_14dc94d8

Seen 2026-02-16 to 2026-09-30 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS45102 sends an email when it next hits a sensor.

51

Source IPs

10

Networks

3

Countries

2.7K

Ports hit

24.8K

Events

5

IPs / network

Top networks

AS4134 Chinanet4 IPs16.9K

Countries

US 29CN 20CA 2

Ports targeted

What it requests

GET/12.6K
GET/favicon.ico12.2K

User agents claimed

Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.3651 IPs24.8K
Source IPCCNetwork Last seenEvents
123.160.223.74CNAS4134 Chinanet2026-09-304.4K
123.160.223.73CNAS4134 Chinanet2026-09-304.3K
123.160.223.72CNAS4134 Chinanet2026-09-304.2K
123.160.223.75CNAS4134 Chinanet2026-09-304.1K
47.251.79.205USAS45102 Alibaba (US) Technology Co., Ltd.2026-09-30279
47.251.188.16USAS45102 Alibaba (US) Technology Co., Ltd.2026-09-30260
47.77.228.238USAS45102 Alibaba (US) Technology Co., Ltd.2026-09-30249
47.254.76.66USAS45102 Alibaba (US) Technology Co., Ltd.2026-09-30247
47.251.24.105USAS45102 Alibaba (US) Technology Co., Ltd.2026-09-30247
47.77.220.146USAS45102 Alibaba (US) Technology Co., Ltd.2026-09-30246
47.251.89.134USAS45102 Alibaba (US) Technology Co., Ltd.2026-09-30246
47.251.118.89USAS45102 Alibaba (US) Technology Co., Ltd.2026-09-30244
47.77.223.127USAS45102 Alibaba (US) Technology Co., Ltd.2026-09-30242
47.251.186.126USAS45102 Alibaba (US) Technology Co., Ltd.2026-09-30241
47.77.216.189USAS45102 Alibaba (US) Technology Co., Ltd.2026-09-30238
47.89.195.183USAS45102 Alibaba (US) Technology Co., Ltd.2026-09-30233
47.89.246.29USAS45102 Alibaba (US) Technology Co., Ltd.2026-09-30233
47.251.88.238USAS45102 Alibaba (US) Technology Co., Ltd.2026-09-30232
47.251.188.82USAS45102 Alibaba (US) Technology Co., Ltd.2026-09-30229
47.88.94.125USAS45102 Alibaba (US) Technology Co., Ltd.2026-09-30227

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun150_003473fe_5e0a1b42same header set1 IPs665b11cun160_003477fe_6d1ef7161 header apart6 IPs3.5Kb11cun160_003477fe_56d8b2051 header apart6 IPs795b11cun160_003473ff_fa401f0f1 header apart3 IPs15b11cun130_000473fe_96c8c9a02 headers apart1 IPs39b11cun130_000473fe_f58b8bdf2 headers apart1 IPs5

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.