HoneyLabs

Akin HTTP request fingerprint

b11cuq050_00040815_df66fe0f

Seen 2026-09-14 to 2026-10-01 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS14061 sends an email when it next hits a sensor.

18

Source IPs

11

Networks

11

Countries

5

Ports hit

27

Events

2

IPs / network

This fingerprint is spread thinly across many networks, which is the shape of a common, widely-used client.

Top networks

Countries

FR 5US 3CN 2ET 1IN 1GB 1HK 1DE 1ID 1SG 1

Ports targeted

What it requests

User agents claimed

Mozilla/5.018 IPs27
Source IPCCNetwork Last seenEvents
213.55.79.194ETAS24757 Ethio Telecom2026-09-203
51.195.101.2DEAS16276 OVH SAS2026-09-192
165.227.237.63GBAS14061 DigitalOcean, LLC2026-09-182
111.228.13.86CNAS141679 China Telecom Beijing Tianjin Hebei Big Data Industry Park Branch2026-09-152
146.59.110.97FRAS16276 OVH SAS2026-09-182
94.250.203.79FRAS51167 Contabo GmbH2026-09-272
58.152.117.250HKAS4760 HKT Limited2026-09-142
165.232.189.20INAS14061 DigitalOcean, LLC2026-09-162
103.226.250.98VNAS135905 VIETNAM POSTS AND TELECOMMUNICATIONS GROUP2026-09-191
45.14.194.87FRAS51167 Contabo GmbH2026-10-011
42.236.73.143CNAS4837 CHINA UNICOM China169 Backbone2026-09-261
207.180.210.142FRAS51167 Contabo GmbH2026-09-301
207.180.198.70FRAS51167 Contabo GmbH2026-09-191
103.165.32.70IDAS17995 PT iForte Global Internet2026-09-161
159.89.179.45USAS14061 DigitalOcean, LLC2026-09-241
159.223.62.140SGAS14061 DigitalOcean, LLC2026-09-201
83.229.35.246USAS396949 Kamatera, Inc.2026-09-181
212.28.188.41USAS40021 Contabo Inc.2026-09-211

Fingerprint family: 5 shapes, 25 IPs, 113 events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 6 headers, Content-Length body: connection, accept, user-agent, content-length, content-type, host

asks for/xmlrpc/2/common · /web/database/list · /web/login · /__parcel_code_frame (POST / GET)
asMozilla/5.0 · CryptoHunter-Vite-2026/1.0 · Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 and 6 more
ports443 · 80 · 5173 · 8069
fromUS · FR · NL · DE · Contabo GmbH · DigitalOcean, LLC · Latitude.sh
b11cuq060_00050815_30319a11Mozilla/5.0 · /xmlrpc/2/common25 IPs65b11cuq050_00040815_df66fe0f this one+/- content-type · Mozilla/5.0 · /web/login18 IPs27b11cuq070_00850815_e3e6784f+/- soapaction · Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:153.0) Gecko/20100101 Firefox/153.0 · /UD/act?13 IPs6b11cuq060_00050815_c343dda9CryptoHunter-Vite-2026/1.0 · /_next/mcp2 IPs11b11cuq070_08050815_e3e6784f+/- cookie · Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:153.0) Gecko/20100101 Firefox/153.0 · /goform/set_LimitClient_cfg2 IPs4

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cun040_00040015_4c87b06e1 header apart1.5K IPs150.7Kb11cuq040_00040811_2daa70d61 header apart247 IPs6.2Kb11cun040_00040015_00b09b791 header apart4 IPs3.1Kb10cun040_00040015_4c87b06e1 header apart16 IPs1.4Kb11cun040_00040015_a4cdfabf1 header apart31 IPs587b11cuq060_00050815_9e42e2331 header apart14 IPs490b11cun040_00040015_5cd6f7441 header apart2 IPs340b11cun040_00040015_ba1829311 header apart6 IPs152

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.