HoneyLabs

Akin HTTP request fingerprint

a11cuq041_00000248_a31e7c35

Seen 2026-09-23 to 2026-09-24 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS8075 sends an email when it next hits a sensor.

395

Source IPs

146

Networks

54

Countries

1

Ports hit

554

Events

3

IPs / network

This fingerprint is spread across many networks, but its whole history is one short burst against one or two ports. That is the shape of a coordinated operation spread thinly on purpose, rather than a client in general circulation.

Top networks

Countries

CN 124US 57IN 48HK 16BR 9ID 8NL 8VN 7GB 7SC 7

Ports targeted

What it requests

User agents claimed

Microsoft WinRM Client395 IPs554
Source IPCCNetwork Last seenEvents
78.109.237.210AS0 Earthlink Telecommunications Equipment Trading & Services DMCC2026-09-238
27.49.234.82AS0 Converge ICT Solutions Inc.2026-09-236
186.4.234.165AS0 Telconet S.A2026-09-235
111.68.108.84AS0 PERN AS Content Servie Provider, Islamabad, Pakistan2026-09-235
103.168.40.36AS0 SKIF Enterprises Private Limited2026-09-234
51.79.77.114AS0 OVH SAS2026-09-234
95.155.36.66AS0 Crnogorski Telekom a.d.Podgorica2026-09-234
59.45.124.62AS0 Chinanet2026-09-234
45.180.180.226AS0 ACAS TECNOLOGIAS S.A.2026-09-234
188.212.158.107AS0 CLOUDFOREST CO., LTD.2026-09-234
20.106.174.48AS0 Microsoft Corporation2026-09-233
36.94.9.51AS0 PT Telekomunikasi Indonesia2026-09-233
138.252.181.250AS0 Maher International2026-09-233
103.143.168.98AS0 Aspt Networks Pvt Ltd2026-09-233
5.40.184.143AS0 Vodafone Ono, S.A.2026-09-233
112.196.54.182AS0 Quadrant Televentures Limited2026-09-233
113.95.147.88AS0 Chinanet2026-09-233
117.220.10.166AS0 National Internet Backbone2026-09-233
60.52.77.204AS0 TM TECHNOLOGY SERVICES SDN. BHD.2026-09-233
36.93.21.138AS0 PT Telekomunikasi Indonesia2026-09-233

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

a11cuq030_00000248_e62b6d85same header set4 IPs115a11cun020_00000048_724c10fb1 header apart162 IPs765a11cuq040_0000024a_2daa70d61 header apart95 IPs247a10cun020_00000048_724c10fb1 header apart3 IPs186a11cun064_00000048_f2f3ae251 header apart2 IPs113a11cun031_00000048_e62b6d851 header apart2 IPs113a11cuq062_00000648_f2f3ae251 header apart2 IPs113a11cuq040_0000024c_cfad16f71 header apart4 IPs16

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.