HoneyLabs

Akin HTTP request fingerprint

b11cuq030_00040810_e62b6d85

Seen 2026-02-17 to 2026-09-30 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS207043 sends an email when it next hits a sensor.

19

Source IPs

16

Networks

14

Countries

219

Ports hit

496

Events

1

IPs / network

This fingerprint is spread thinly across many networks, which is the shape of a common, widely-used client.

Top networks

Countries

DE 2GE 2HK 2IR 2AR 2KR 1TZ 1ID 1BD 1PS 1

Ports targeted

What it requests

POST/clients478
GET/17

User agents claimed

what-vpn-go/0.12 IPs478
Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.103 Safari/537.365 IPs5
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.74 IPs4
Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.364 IPs4
Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/52.0.2743.116 Safari/537.362 IPs2
Source IPCCNetwork Last seenEvents
94.26.83.79DEAS207043 Dedik Services Limited2026-09-30242
91.92.43.222DEAS207043 Dedik Services Limited2026-09-23236
92.241.77.214GEAS35805 JSC Silknet2026-09-192
110.4.13.252HKAS38819 HKCSL GPRS NETWORK2026-09-201
190.104.195.210ARAS11014 CPS2026-09-151
202.4.101.78BDAS23956 AmberIT Limited2026-09-281
190.12.99.194ARAS11014 CPS2026-09-271
197.159.1.58CMAS15964 CAMTEL2026-09-291
185.82.165.26IRAS206065 Tose'h Fanavari Ertebabat Pasargad Arian Co. PJS2026-09-161
154.73.64.24TZAS327706 Power and Network, Backup Company Ltd2026-09-091
83.217.16.24RUAS30733 JSC Globus-Telecom2026-09-281
82.114.200.50CZAS41046 O2 Czech Republic, a.s.2026-09-221
81.16.249.96GEAS34666 JSC Global Erty2026-09-231
223.17.6.188HKAS9304 HGC Global Communications Limited2026-09-281
114.7.123.38IDAS4761 INDOSAT Internet Network Provider2026-09-271
213.6.101.83PSAS12975 Palestine Telecommunications Company (PALTEL)2026-09-041
185.190.20.228IRAS206065 Tose'h Fanavari Ertebabat Pasargad Arian Co. PJS2026-09-251
50.43.160.231USAS5650 Frontier Communications of America, Inc.2026-09-251
119.206.74.189KRAS4766 Korea Telecom2026-09-071

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun020_00040010_724c10fb1 header apart1.4K IPs70.2Kb11cuq040_00040811_2daa70d61 header apart237 IPs6.4Kb10cun020_00040010_724c10fb1 header apart14 IPs1.9Kb11cuq040_00440810_a31e7c351 header apart399 IPs560b11cuq040_00040812_cfad16f71 header apart24 IPs93b11cuq040_00050810_a31e7c351 header apart6 IPs20b11cuq040_00040814_6e8c246c1 header apart2 IPs12b11cuq020_00040800_724c10fb1 header apart2 IPs9

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.