HoneyLabs

Akin HTTP request fingerprint

b11cuq040_00040812_cfad16f7

Seen 2026-02-16 to 2026-09-28 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS14061 sends an email when it next hits a sensor.

24

Source IPs

3

Networks

3

Countries

2

Ports hit

93

Events

8

IPs / network

This fingerprint is concentrated: many addresses on very few networks, which is what a single coordinated operation tends to look like.

Top networks

Countries

US 22CA 1ID 1

Ports targeted

What it requests

POST/23
POST/_stats23
POST/_nodes23

User agents claimed

python-urllib3/2.7.023 IPs92
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.361 IPs1
Source IPCCNetwork Last seenEvents
45.33.125.204USAS63949 Akamai Connected Cloud2026-09-074
50.116.43.241USAS63949 Akamai Connected Cloud2026-09-144
157.245.167.139USAS14061 DigitalOcean, LLC2026-09-244
170.187.145.131USAS63949 Akamai Connected Cloud2026-09-214
45.56.69.26USAS63949 Akamai Connected Cloud2026-09-014
192.155.95.176USAS63949 Akamai Connected Cloud2026-09-244
157.230.4.3USAS14061 DigitalOcean, LLC2026-09-144
165.22.11.28USAS14061 DigitalOcean, LLC2026-09-014
157.245.94.43USAS14061 DigitalOcean, LLC2026-09-074
159.65.65.69USAS14061 DigitalOcean, LLC2026-09-284
198.211.99.18USAS14061 DigitalOcean, LLC2026-09-074
64.227.55.171USAS14061 DigitalOcean, LLC2026-09-214
167.172.205.210USAS14061 DigitalOcean, LLC2026-09-244
159.65.67.95USAS14061 DigitalOcean, LLC2026-09-074
173.255.192.58USAS63949 Akamai Connected Cloud2026-09-014
64.227.1.15USAS14061 DigitalOcean, LLC2026-09-214
138.197.137.57CAAS14061 DigitalOcean, LLC2026-09-014
206.189.203.70USAS14061 DigitalOcean, LLC2026-09-144
50.116.46.114USAS63949 Akamai Connected Cloud2026-09-284
194.195.208.236USAS63949 Akamai Connected Cloud2026-09-244

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun030_00040012_13ee3d341 header apart5.1K IPs226.0Kb11cun030_00040012_f6d8d7971 header apart62 IPs2.5Kb11cuq050_00050812_107c8b821 header apart97 IPs628b11cun030_00040012_a6735d471 header apart2 IPs504b11cuq030_00040810_e62b6d851 header apart19 IPs496b11cuq050_00040813_2619b3ac1 header apart21 IPs113b11cuq050_00050812_48bb8ee91 header apart2 IPs48b11cuq050_08040812_107c8b821 header apart1 IPs19

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.