HoneyLabs

Akin HTTP request fingerprint

b11lun000_00000000_334359b9

Seen 2026-02-17 to 2026-09-30 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS9808 sends an email when it next hits a sensor.

71

Source IPs

27

Networks

21

Countries

37

Ports hit

1.5K

Events

3

IPs / network

Top networks

Countries

US 15CN 15NL 12KR 7RU 3BR 2IN 2JP 2ES 1CA 1

Ports targeted

What it requests

GET/version1.2K
GET/174
GET/?CAVIT10
GET/V9xU1
GET/gTl51
Source IPCCNetwork Last seenEvents
172.233.62.80NLAS63949 Akamai Connected Cloud2026-09-21167
172.233.117.214ESAS63949 Akamai Connected Cloud2026-09-21149
45.79.190.133USAS63949 Akamai Connected Cloud2026-09-21142
192.53.121.87CAAS63949 Akamai Connected Cloud2026-09-21140
172.232.221.148ITAS63949 Akamai Connected Cloud2026-09-21139
172.233.26.186BRAS63949 Akamai Connected Cloud2026-09-21136
172.232.160.26USAS63949 Akamai Connected Cloud2026-09-21126
194.195.252.210AUAS63949 Akamai Connected Cloud2026-09-21124
172.105.56.8INAS63949 Akamai Connected Cloud2026-09-21108
185.189.182.234NLAS215747 NubaCloud B.V.2026-09-3061
45.91.64.6RUAS214664 JSC Buduschee2026-09-2826
114.55.232.178CNAS37963 Hangzhou Alibaba Advertising Co.,Ltd.2026-09-2324
45.90.163.37FRAS39421 Sapinet SAS2026-09-0514
45.91.64.7RUAS214664 JSC Buduschee2026-09-1012
183.249.208.27CNAS56041 China Mobile communications corporation2026-09-2110
80.82.77.202NLAS202425 IP Volume inc2026-09-225
94.154.43.28NLAS219502 Storm Industries LLC2026-09-285
94.102.49.155NLAS202425 IP Volume inc2026-09-065
45.91.64.10RUAS214664 JSC F62026-09-304
85.11.167.199NLAS197170 TechTies Inc.2026-09-104

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b10lun000_00000000_334359b9same header set2.2K IPs24.8Kb11cun010_00040000_c4b2c4aa1 header apart648 IPs63.7Kb10cun010_00040000_c4b2c4aa1 header apart370 IPs2.1Kb10cun010_00000004_a37af9cb1 header apart9 IPs623b10cun010_00000010_c4b2c4aa1 header apart2 IPs2b10cun011_00000000_c4b2c4aa_x4d8a1 header apart1 IPs1b11cuq010_00000800_c4b2c4aa1 header apart1 IPs1b10cun020_00000014_0a8d7f112 headers apart2.0K IPs617.5K

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.