HoneyLabs

Akin HTTP request fingerprint

b11cuq030_00050800_e62b6d85

Seen 2026-02-17 to 2026-09-30 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS396982 sends an email when it next hits a sensor.

197

Source IPs

14

Networks

14

Countries

14

Ports hit

552

Events

14

IPs / network

Top networks

Countries

US 147GB 31TH 4NL 3BG 2HK 2RU 1SC 1BR 1PL 1

Ports targeted

What it requests

POST/539
POST/wsman11
Source IPCCNetwork Last seenEvents
193.233.202.140RUAS203273 NetCrafters OU2026-09-0246
173.244.60.211USAS64286 LogicWeb Inc.2026-09-0236
94.154.43.114NLAS219502 Storm Industries LLC2026-09-0236
2.27.202.33USAS219337 Fzco2026-09-0236
124.198.132.45USAS210558 1337 Services GmbH2026-09-0234
160.119.71.182SCAS49870 Alsycon B.V.2026-09-0234
45.205.1.153BRAS215925 Vpsvault.host Ltd2026-09-0234
45.92.1.85NLAS210558 1337 Services GmbH2026-09-0231
45.138.16.164PLAS210558 1337 Services GmbH2026-09-0231
176.65.148.181NLAS51396 Pfcloud UG (haftungsbeschrankt)2026-09-0230
165.154.163.10USAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-213
198.235.24.197USAS396982 Google LLC2026-09-102
147.185.132.174USAS396982 Google LLC2026-09-132
198.235.24.228USAS396982 Google LLC2026-09-212
198.235.24.209USAS396982 Google LLC2026-09-252
35.203.210.187GBAS396982 Google LLC2026-09-202
35.203.210.204GBAS396982 Google LLC2026-09-262
195.123.228.112BGAS59729 Route 95 LLC2026-09-192
198.235.24.78USAS396982 Google LLC2026-09-302
150.107.38.251HKAS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED2026-09-202

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cuq040_00050801_2daa70d61 header apart93 IPs659b11cuq040_02050800_f46b29fb1 header apart178 IPs228b11cuq040_00050801_0e54e4f41 header apart1 IPs144b11cuq040_00050802_cfad16f71 header apart1 IPs68b10cuq040_00850800_a31e7c351 header apart28 IPs28b11cuq040_00050810_a31e7c351 header apart6 IPs20b11cuq040_00050801_bf8a4cbb1 header apart8 IPs10b10cuq040_00050804_6e8c246c1 header apart8 IPs9

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.