HoneyLabs

Akin HTTP request fingerprint

b11cuq040_00050801_2daa70d6

Seen 2026-02-17 to 2026-09-30 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS213412 sends an email when it next hits a sensor.

93

Source IPs

17

Networks

10

Countries

18

Ports hit

659

Events

5

IPs / network

Top networks

Countries

US 57FR 24IN 3CN 2RU 2TW 1NL 1CO 1SG 1IR 1

Ports targeted

What it requests

POST/wsman82
POST/22
Source IPCCNetwork Last seenEvents
121.205.66.220CNAS4134 Chinanet2026-09-25266
188.191.165.8RUAS50577 Intelsc Ltd.2026-09-08131
218.26.96.58CNAS4837 CHINA UNICOM China169 Backbone2026-09-1180
1.34.2.110TWAS3462 Data Communication Business Group2026-09-0228
31.56.209.64NLAS209373 Swissnet LLC2026-09-2723
34.145.9.43USAS396982 Google LLC2026-09-2813
190.159.36.43COAS14080 Telmex Colombia S.A.2026-09-209
95.154.84.123RUAS44724 Octopusnet LTD2026-09-098
64.62.194.196USAS6939 Hurricane Electric LLC2026-09-054
103.125.162.173INAS18229 CtrlS2026-09-213
49.207.15.17INAS55577 Atria Convergence Technologies Ltd.,2026-09-053
103.239.38.106INAS150008 Pioneer Elabs Ltd.2026-09-033
195.184.76.162USAS213412 ONYPHE SAS2026-09-182
178.128.18.214SGAS14061 DigitalOcean, LLC2026-09-192
31.57.63.143USAS56971 Cgi Global Limited2026-09-042
91.230.168.68USAS213412 ONYPHE SAS2026-09-032
195.184.76.219USAS213412 ONYPHE SAS2026-09-272
64.62.194.197USAS6939 Hurricane Electric LLC2026-09-102
195.184.76.168USAS213412 ONYPHE SAS2026-09-112
195.184.76.132USAS213412 ONYPHE SAS2026-09-021

Fingerprint family: 2 shapes, 93 IPs, 670 events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 4 headers, Content-Length body: connection, content-length, content-type, host

asks for/cgi-bin/bip.cgi · /wsman · / · /SDK/webLanguage (POST / PUT)
ports8089 · 8085 · 8087 · 8082
fromCN · RU · US · TW · Chinanet · Intelsc Ltd. · CHINA UNICOM China169 Backbone
b11cuq040_00050801_2daa70d6 this one/cgi-bin/bip.cgi93 IPs659b11cuq050_00850801_985b9497+/- soapaction · /ctrlt/DeviceUpgrade_13 IPs11

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cuq040_00050801_0e54e4f4same header set1 IPs144b11cuq040_00050801_bf8a4cbbsame header set8 IPs10b11cuq030_00050800_e62b6d851 header apart197 IPs552b11cuq050_00050805_650ae0b21 header apart123 IPs161b11cuq050_00050811_9b8c433a1 header apart7 IPs153b11cuq050_00450801_985b94971 header apart1 IPs107b11cuq050_00050811_985b94971 header apart7 IPs66b11cuq050_00050805_df66fe0f1 header apart1 IPs38

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.