HoneyLabs

Akin HTTP request fingerprint

b11cuq080_10050c16_b8c2c87d

Seen 2026-08-20 to 2026-09-15 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS396982 sends an email when it next hits a sensor.

25

Source IPs

1

Networks

6

Countries

19

Ports hit

1.1K

Events

25

IPs / network

This fingerprint is concentrated: many addresses on very few networks, which is what a single coordinated operation tends to look like.

Top networks

Countries

US 13NL 4TW 4BE 2SG 1JP 1

Ports targeted

What it requests

POST/graphql266

User agents claimed

Mozilla/5.0 (compatible; TelegramBot/1.0)12 IPs21
Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GrokBot/1.0; +https://x.ai/grokbot)11 IPs18
Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)15 IPs18
Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user)13 IPs17
Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/grokbot)11 IPs14
Source IPCCNetwork Last seenEvents
34.125.130.62USAS396982 Google LLC2026-09-0460
34.158.109.130NLAS396982 Google LLC2026-09-1360
35.240.163.160SGAS396982 Google LLC2026-09-0260
34.77.20.113BEAS396982 Google LLC2026-09-1160
34.90.223.23NLAS396982 Google LLC2026-09-0760
34.81.32.10TWAS396982 Google LLC2026-09-0660
34.146.34.97JPAS396982 Google LLC2026-09-0160
8.229.251.12USAS396982 Google LLC2026-09-1260
34.21.89.109USAS396982 Google LLC2026-09-0557
34.182.164.122USAS396982 Google LLC2026-09-1256
8.228.19.130USAS396982 Google LLC2026-09-1456
34.34.151.241BEAS396982 Google LLC2026-09-1156
34.16.206.147USAS396982 Google LLC2026-09-0554
34.13.160.68NLAS396982 Google LLC2026-09-0552
34.34.109.114NLAS396982 Google LLC2026-09-0648
34.125.199.35USAS396982 Google LLC2026-09-1532
34.186.9.165USAS396982 Google LLC2026-08-3128
34.24.97.217USAS396982 Google LLC2026-09-0524
34.74.135.191USAS396982 Google LLC2026-09-0524
34.81.215.134TWAS396982 Google LLC2026-09-0324

Fingerprint family: 2 shapes, 25 IPs, 3.2K events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 10 headers, Content-Length body, 2 outside the core list: accept-encoding, accept, user-agent, referer, content-length, content-type, host, origin, metadata, metadata-flavor

asks for/fetch · /graphql · /proxy · /api/preview (POST)
asMozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1 · Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; · Mozilla/5.0 (compatible; TelegramBot/1.0) and 1759 more
ports9090 · 5173 · 8000 · 443
fromUS · NL · BE · TW · Google LLC
b11cuq102_10050c16_5ccac048_x45448512Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/grokbot) · /fetch25 IPs2.1Kb11cuq080_10050c16_b8c2c87d this one+/- metadata, metadata-flavor · Mozilla/5.0 (compatible; TelegramBot/1.0) · /graphql25 IPs1.1K

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cuq070_10050c12_b8f6b5c21 header apart1 IPs7b11cuq090_10050c17_a69ac9291 header apart1 IPs4b11cuq090_10050c17_adcf705b1 header apart1 IPs4b11cuq102_10050c16_5ccac048_x454485122 headers apart25 IPs2.1Kb11cuq060_00050816_84d4cebf2 headers apart324 IPs554b11cuq060_00050816_8092f7132 headers apart4 IPs125b11cuq060_00050816_9898e8b52 headers apart1 IPs65b11cuq060_00050816_5ad15e382 headers apart4 IPs52

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.