HoneyLabs

Akin HTTP request fingerprint

b11cuq040_00440801_bf8a4cbb

Seen 2026-02-18 to 2026-09-28 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS9541 sends an email when it next hits a sensor.

29

Source IPs

14

Networks

6

Countries

1

Ports hit

29

Events

2

IPs / network

Top networks

Countries

PK 17CN 8DZ 1PH 1RU 1AR 1

Ports targeted

What it requests

Source IPCCNetwork Last seenEvents
61.162.163.129CNAS4837 CHINA UNICOM China169 Backbone2026-09-251
154.242.143.76DZAS36947 Telecom Algeria2026-09-171
72.255.59.107PKAS9541 Cyber Internet Services (Pvt) Ltd.2026-09-231
124.135.10.58CNAS4837 CHINA UNICOM China169 Backbone2026-09-011
219.157.57.158CNAS4837 CHINA UNICOM China169 Backbone2026-09-261
120.85.115.201CNAS17622 China Unicom Guangzhou network2026-09-121
220.198.113.253CNAS17816 China Unicom IP network China169 Guangdong province2026-09-251
111.92.157.210PKAS135523 Multinet Broadband2026-09-041
72.255.37.223PKAS9541 Cyber Internet Services (Pvt) Ltd.2026-09-141
153.117.48.145PKAS9541 Cyber Internet Services (Pvt) Ltd.2026-09-281
223.123.72.238PKAS59257 CMPak Limited2026-09-231
153.117.1.42PKAS9541 Cyber Internet Services (Pvt) Ltd.2026-09-191
175.107.217.3PKAS9541 Cyber Internet Services (Pvt) Ltd.2026-09-011
202.63.207.103PKAS141342 FIBERISH (PVT) LTD2026-09-011
103.31.93.154PKAS9541 Cyber Internet Services (Pvt) Ltd.2026-09-171
120.28.166.185PHAS132199 Globe Telecom Inc.2026-09-101
123.11.203.106CNAS4837 CHINA UNICOM China169 Backbone2026-09-081
175.107.233.152PKAS9541 Cyber Internet Services (Pvt) Ltd.2026-09-231
59.103.119.15PKAS9541 Cyber Internet Services (Pvt) Ltd.2026-09-221
14.1.106.35PKAS9541 Cyber Internet Services (Pvt) Ltd.2026-09-061

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cuq050_00450801_985b94971 header apart1 IPs116b11cun030_00440001_c91eaf541 header apart1 IPs11b11cuq030_00040801_213543bf1 header apart1 IPs4b11cuq030_00040801_c91eaf541 header apart3 IPs4b11cuq040_00040811_2daa70d62 headers apart237 IPs6.4Kb11cun020_00040001_78f1f19c2 headers apart49 IPs3.3Kb10cun020_00040001_78f1f19c2 headers apart604 IPs2.9Kb11cuq040_00050801_2daa70d62 headers apart93 IPs659

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.