HoneyLabs

Akin HTTP request fingerprint

b11cun160_0004f7ff_3f747703

Seen 2026-02-17 to 2026-09-30 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS14061 sends an email when it next hits a sensor.

2.9K

Source IPs

2

Networks

7

Countries

131

Ports hit

3.0K

Events

1454

IPs / network

This fingerprint is concentrated: many addresses on very few networks, which is what a single coordinated operation tends to look like.

Top networks

Unattributed2 IPs2

Countries

US 2.3KNL 154DE 118CA 110GB 110IN 95BR 3

Ports targeted

What it requests

User agents claimed

Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.362.0K IPs2.1K
Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36894 IPs929
Source IPCCNetwork Last seenEvents
137.184.230.155USAS14061 DigitalOcean, LLC2026-09-293
144.126.210.232USAS14061 DigitalOcean, LLC2026-09-203
64.23.224.95USAS14061 DigitalOcean, LLC2026-09-283
164.92.73.106USAS14061 DigitalOcean, LLC2026-09-013
174.138.39.73USAS14061 DigitalOcean, LLC2026-09-033
162.243.80.145USAS14061 DigitalOcean, LLC2026-09-243
64.23.157.98USAS14061 DigitalOcean, LLC2026-09-132
134.199.225.172USAS14061 DigitalOcean, LLC2026-09-062
164.92.191.248DEAS14061 DigitalOcean, LLC2026-09-272
147.182.239.231USAS14061 DigitalOcean, LLC2026-09-202
164.92.72.211USAS14061 DigitalOcean, LLC2026-09-132
144.126.214.126USAS14061 DigitalOcean, LLC2026-09-292
146.190.171.158USAS14061 DigitalOcean, LLC2026-09-172
147.182.254.47USAS14061 DigitalOcean, LLC2026-09-292
143.198.236.119USAS14061 DigitalOcean, LLC2026-09-222
143.198.71.153USAS14061 DigitalOcean, LLC2026-09-172
159.203.172.84USAS14061 DigitalOcean, LLC2026-09-082
143.110.149.61USAS14061 DigitalOcean, LLC2026-09-102
137.184.84.167USAS14061 DigitalOcean, LLC2026-09-292
137.184.233.124USAS14061 DigitalOcean, LLC2026-09-082

Fingerprint family: 2 shapes, 2.9K IPs, 6.1K events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 15 headers, no body: connection, accept-encoding, accept, accept-language, user-agent, upgrade-insecure-requests, sec-fetch-mode, sec-fetch-site, sec-fetch-dest, sec-fetch-user, sec-ch-ua-platform, sec-ch-ua, sec-ch-ua-mobile, sec-gpc, host

asks for/ · /favicon.ico (GET)
asMozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/14 · Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/15 and 2 more
ports1912 · 8848 · 8808 · 2404
fromUS · NL · DE · GB · DigitalOcean, LLC
b11cun150_0004f3ff_28f866c0Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/14 · /2.9K IPs3.0Kb11cun160_0004f7ff_3f747703 this one+/- referer · Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/14 · /favicon.ico2.9K IPs3.0K

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun150_0004f3ff_28f866c01 header apart2.9K IPs3.0Kb11cun140_000473ff_fa6db48e2 headers apart13 IPs13b11cun140_000473ff_1b6187742 headers apart2 IPs6

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.