HoneyLabs

Akin HTTP request fingerprint

b11cuq040_00040811_2daa70d6

Seen 2026-02-17 to 2026-09-30 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS14987 sends an email when it next hits a sensor.

237

Source IPs

5

Networks

4

Countries

3.0K

Ports hit

6.4K

Events

47

IPs / network

Top networks

Countries

US 114DE 43BE 41CN 39

Ports targeted

What it requests

POST/wsman5.8K
POST/sdk510
POST/47

User agents claimed

Microsoft WinRM Client114 IPs5.8K
Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html)39 IPs468
Mozilla/5.0 (compatible)41 IPs47
Mozilla/5.0 (compatible; Odin; https://docs.getodin.com/)42 IPs42
kubo-probe/1.01 IPs10
Source IPCCNetwork Last seenEvents
104.152.52.210USAS14987 Rethem Hosting LLC2026-09-27115
104.152.52.201USAS14987 Rethem Hosting LLC2026-09-28113
104.152.52.213USAS14987 Rethem Hosting LLC2026-09-28109
104.152.52.202USAS14987 Rethem Hosting LLC2026-09-28107
104.152.52.207USAS14987 Rethem Hosting LLC2026-09-28106
104.152.52.209USAS14987 Rethem Hosting LLC2026-09-28103
104.152.52.200USAS14987 Rethem Hosting LLC2026-09-28100
104.152.52.204USAS14987 Rethem Hosting LLC2026-09-28100
104.152.52.205USAS14987 Rethem Hosting LLC2026-09-2897
104.152.52.203USAS14987 Rethem Hosting LLC2026-09-2796
104.152.52.206USAS14987 Rethem Hosting LLC2026-09-2896
104.152.52.212USAS14987 Rethem Hosting LLC2026-09-2896
104.152.52.214USAS14987 Rethem Hosting LLC2026-09-2893
104.152.52.211USAS14987 Rethem Hosting LLC2026-09-2890
104.152.52.208USAS14987 Rethem Hosting LLC2026-09-2887
104.152.52.138USAS14987 Rethem Hosting LLC2026-09-2772
104.152.52.137USAS14987 Rethem Hosting LLC2026-09-2869
104.152.52.117USAS14987 Rethem Hosting LLC2026-09-2868
104.152.52.110USAS14987 Rethem Hosting LLC2026-09-2767
104.152.52.127USAS14987 Rethem Hosting LLC2026-09-2864

Fingerprint family: 3 shapes, 548 IPs, 18.7K events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 3 headers, no body: connection, user-agent, host

asks for/ · /wsman · /solr/admin/cores?action=STATUS&wt=json · /solr/admin/info/system (GET / POST)
asGo-http-client/1.1 · Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html) · Microsoft WinRM Client and 47 more
ports80 · 443 · 8080 · 1880
fromUS · CN · DE · NL · DigitalOcean, LLC · Hangzhou Alibaba Advertising Co.,Ltd. · Rethem Hosting LLC
b11cun030_00040011_c91eaf54Go-http-client/1.1 · /548 IPs12.1Kb11cuq040_00040811_2daa70d6 this one+/- content-length · Microsoft WinRM Client · /wsman237 IPs6.4Kb11cun084_40040011_966c00f7_x12be9f62a4acfdb1+/- upgrade, sec-websocket-extensions, sec-websocket-key, sec-websocket-protocol, sec-websocket-version · CryptoHunter-Vite-2026/1.0 · /2 IPs216

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun030_00040011_c91eaf541 header apart548 IPs12.1Kb11cuq030_00040810_e62b6d851 header apart19 IPs496b11cuq050_00050811_9b8c433a1 header apart7 IPs153b11cuq050_00040813_2619b3ac1 header apart21 IPs113b10cun030_00040011_c91eaf541 header apart14 IPs111b11cun030_00040011_213543bf1 header apart9 IPs78b11cuq050_00050811_985b94971 header apart7 IPs66b11cuq050_00040815_df66fe0f1 header apart16 IPs25

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.