HoneyLabs

Akin HTTP request fingerprint

b11cuq040_00440810_a31e7c35

Seen 2026-06-28 to 2026-09-24 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS8075 sends an email when it next hits a sensor.

399

Source IPs

149

Networks

54

Countries

4

Ports hit

560

Events

3

IPs / network

Top networks

Countries

CN 124US 57IN 48HK 17BR 9NL 9ID 8VN 7GB 7SC 7

Ports targeted

What it requests

User agents claimed

Microsoft WinRM Client399 IPs560
Source IPCCNetwork Last seenEvents
78.109.237.210IQAS50710 Earthlink Telecommunications Equipment Trading & Services DMCC2026-09-238
27.49.234.82PHAS17639 Converge ICT Solutions Inc.2026-09-236
186.4.234.165ECAS27947 Telconet S.A2026-09-235
111.68.108.84PKAS45773 PERN AS Content Servie Provider, Islamabad, Pakistan2026-09-235
103.168.40.36PKAS142421 SKIF Enterprises Private Limited2026-09-234
51.79.77.114CAAS16276 OVH SAS2026-09-234
95.155.36.66MEAS8585 Crnogorski Telekom a.d.Podgorica2026-09-234
59.45.124.62CNAS4134 Chinanet2026-09-234
45.180.180.226PYAS269725 ACAS TECNOLOGIAS S.A.2026-09-234
188.212.158.107THAS142299 CLOUDFOREST CO., LTD.2026-09-234
201.148.65.18MXAS18734 Operbes, S.A. de C.V.2026-09-234
20.106.174.48USAS8075 Microsoft Corporation2026-09-233
36.94.9.51IDAS7713 PT Telekomunikasi Indonesia2026-09-233
138.252.181.250BDAS142577 Maher International2026-09-233
103.143.168.98INAS139490 Aspt Networks Pvt Ltd2026-09-233
5.40.184.143ESAS6739 Vodafone Ono, S.A.2026-09-233
112.196.54.182INAS17917 Quadrant Televentures Limited2026-09-233
113.95.147.88CNAS4134 Chinanet2026-09-233
117.220.10.166INAS9829 National Internet Backbone2026-09-233
60.52.77.204MYAS4788 TM TECHNOLOGY SERVICES SDN. BHD.2026-09-233

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cuq030_00040810_e62b6d851 header apart19 IPs496b11cun020_00040010_724c10fb2 headers apart1.4K IPs70.2Kb11cuq040_00040811_2daa70d62 headers apart237 IPs6.4Kb10cun020_00040010_724c10fb2 headers apart14 IPs1.9Kb11cuq040_00040812_cfad16f72 headers apart24 IPs93b11cuq040_00440801_bf8a4cbb2 headers apart29 IPs29b11cuq040_00050810_a31e7c352 headers apart6 IPs20b11cuq040_00040814_6e8c246c2 headers apart2 IPs12

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.