HoneyLabs

Akin HTTP request fingerprint

b11cuq050_00050814_6eb31df9

Seen 2026-03-02 to 2026-09-26 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS14987 sends an email when it next hits a sensor.

52

Source IPs

6

Networks

4

Countries

66

Ports hit

74

Events

9

IPs / network

Top networks

Countries

US 44SG 5CN 2VN 1

Ports targeted

What it requests

POST/65

User agents claimed

curl/7.61.143 IPs63
curl/7.68.05 IPs5
Mozilla/5.02 IPs3
curl/7.88.11 IPs2
curl/8.14.11 IPs1
Source IPCCNetwork Last seenEvents
104.152.52.138USAS14987 Rethem Hosting LLC2026-09-264
104.152.52.136USAS14987 Rethem Hosting LLC2026-09-263
104.152.52.139USAS14987 Rethem Hosting LLC2026-09-263
104.152.52.110USAS14987 Rethem Hosting LLC2026-09-263
104.152.52.128USAS14987 Rethem Hosting LLC2026-09-262
104.152.52.111USAS14987 Rethem Hosting LLC2026-09-252
104.152.52.208USAS14987 Rethem Hosting LLC2026-09-252
104.152.52.142USAS14987 Rethem Hosting LLC2026-09-252
104.152.52.211USAS14987 Rethem Hosting LLC2026-09-242
104.152.52.123USAS14987 Rethem Hosting LLC2026-09-252
104.152.52.140USAS14987 Rethem Hosting LLC2026-09-262
198.23.196.175USAS36352 HostPapa2026-09-262
104.152.52.201USAS14987 Rethem Hosting LLC2026-09-132
180.184.29.195CNAS137718 Beijing Volcano Engine Technology Co., Ltd.2026-09-222
104.152.52.109USAS14987 Rethem Hosting LLC2026-09-252
104.152.52.135USAS14987 Rethem Hosting LLC2026-09-262
104.152.52.214USAS14987 Rethem Hosting LLC2026-09-252
104.152.52.134USAS14987 Rethem Hosting LLC2026-09-261
104.152.52.105USAS14987 Rethem Hosting LLC2026-09-241
104.152.52.149USAS14987 Rethem Hosting LLC2026-09-251

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cuq050_00050814_206820d3same header set1 IPs1b11cuq060_00050816_84d4cebf1 header apart324 IPs554b11cuq060_00050815_9e42e2331 header apart14 IPs490b11cuq060_00050815_a38e1c5d1 header apart1 IPs336b11cuq060_00050816_8092f7131 header apart4 IPs125b11cuq060_00050816_9898e8b51 header apart1 IPs65b11cuq060_00050815_30319a111 header apart23 IPs61b11cuq060_00050816_5ad15e381 header apart4 IPs52

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.