Akin HTTP request fingerprint
b11cuq050_00040813_2619b3ac
Seen 2026-02-19 to 2026-09-30 across the retained window.
The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked.
Or watch the top network: AS14061 sends an email when it next hits a sensor.
Countries
US 15GB 3BG 1CH 1DE 1
User agents claimed
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.159 Safari/537.3619 IPs19
Mozilla/5.0 (Windows NT 10.0; Win64; x64)1 IPs3
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/85.0.4183.83 Safari/537.361 IPs2
Mozilla/5.0 (Windows NT 10.0; rv:139.0) Gecko/20100101 Firefox/139.01 IPs2
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.0.1 Mobile/15E148 Safari/604.11 IPs2
Source IPCCNetwork
Last seenEvents
93.123.109.214BGAS48090 Techoff Srv Limited2026-09-3091 46.19.142.226CHAS51852 Private Layer INC2026-09-043 192.155.89.192USAS63949 Akamai Connected Cloud2026-09-161 157.245.239.90USAS14061 DigitalOcean, LLC2026-09-091 138.68.255.12USAS14061 DigitalOcean, LLC2026-09-081 97.107.136.223USAS63949 Akamai Connected Cloud2026-09-161 143.110.142.175USAS14061 DigitalOcean, LLC2026-09-161 178.62.97.205GBAS14061 DigitalOcean, LLC2026-09-041 178.79.184.209GBAS63949 Akamai Connected Cloud2026-09-161 69.164.203.138USAS63949 Akamai Connected Cloud2026-09-101 45.33.64.166USAS63949 Akamai Connected Cloud2026-09-161 165.22.168.143USAS14061 DigitalOcean, LLC2026-09-041 164.92.252.245DEAS14061 DigitalOcean, LLC2026-09-111 134.122.117.129USAS14061 DigitalOcean, LLC2026-09-271 45.79.192.205USAS63949 Akamai Connected Cloud2026-09-161 165.227.30.51USAS14061 DigitalOcean, LLC2026-09-261 198.199.91.162USAS14061 DigitalOcean, LLC2026-09-161 137.184.30.153USAS14061 DigitalOcean, LLC2026-09-271 45.56.82.163USAS63949 Akamai Connected Cloud2026-09-081 178.62.38.96GBAS14061 DigitalOcean, LLC2026-09-261
Fingerprint family: 2 shapes, 21 IPs, 118 events in 30 days
Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.
HTTP/1.1, 5 headers, Content-Length body: connection, accept-encoding, user-agent, content-length, host
asks for/wsman · /GponForm/diag_Form?images/ · /tmui/locallb/workspace/tmshCmd.jsp · /apply_sec.cgi (POST / PUT)
asMozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like · Mozilla/5.0 (Windows NT 10.0; Win64; x64) · Mozilla/5.0 (Debian; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/1 and 89 more
ports443 · 5985 · 5986 · 2087
fromBG · US · CH · GB · Techoff Srv Limited · DigitalOcean, LLC · Akamai Connected Cloud
b11cuq050_00040813_2619b3ac this oneMozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like · /wsman21 IPs113b11cuq060_00440813_95cc9d02+/- authorization · Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, lik · /WEB_VMS/LEVEL15/2 IPs5
About this fingerprint
Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.