HoneyLabs

Akin HTTP request fingerprint

b11cuq050_00850810_800b4567

Seen 2026-02-21 to 2026-09-28 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS9541 sends an email when it next hits a sensor.

46

Source IPs

26

Networks

13

Countries

3

Ports hit

47

Events

2

IPs / network

This fingerprint is spread thinly across many networks, which is the shape of a common, widely-used client.

Top networks

Countries

PK 23CN 7AR 3ID 2PH 2RU 2FR 1IN 1HK 1ZA 1

Ports targeted

What it requests

POST/UD/act?147

User agents claimed

Hello, world44 IPs44
r00ts3c-owned-you2 IPs3
Source IPCCNetwork Last seenEvents
205.237.105.190FRAS61254 ESTOXY OU2026-09-262
103.104.215.10PKAS131471 Login.Me (Pvt) Ltd2026-09-211
105.184.7.6ZAAS37457 Telkom SA Ltd.2026-09-181
113.255.196.148HKAS9304 HGC Global Communications Limited2026-09-041
153.117.27.129PKAS9541 Cyber Internet Services (Pvt) Ltd.2026-09-111
103.66.148.82PKAS142647 Nasstec Airnet Networks Private Limited2026-09-201
36.27.76.223CNAS4134 Chinanet2026-09-151
36.107.81.92CNAS4134 Chinanet2026-09-271
103.122.67.53IDAS138064 PT. Jinom Network Indonesia2026-09-241
190.196.253.59ARAS266702 MEGALINK S.R.L.2026-09-111
94.243.11.97RUAS8359 MTS PJSC2026-09-251
180.252.82.152IDAS7713 PT Telekomunikasi Indonesia2026-09-281
223.123.41.70PKAS138423 CMPak Limited2026-09-161
160.30.142.218PKAS142647 Nasstec Airnet Networks Private Limited2026-09-021
42.7.119.110CNAS4837 CHINA UNICOM China169 Backbone2026-09-171
190.196.253.46ARAS266702 MEGALINK S.R.L.2026-09-221
120.28.201.138PHAS132199 Globe Telecom Inc.2026-09-071
36.255.33.132PKAS9541 Cyber Internet Services (Pvt) Ltd.2026-09-211
223.123.73.89PKAS59257 CMPak Limited2026-09-121
190.196.253.72ARAS266702 MEGALINK S.R.L.2026-09-091

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b10cuq050_00850810_bb92d238same header set6 IPs6b10cuq040_00850800_a31e7c351 header apart28 IPs28b11cuq040_00050810_a31e7c351 header apart6 IPs20b11cuq060_00850811_ffe601071 header apart5 IPs6b11cuq060_00850812_0421ce221 header apart2 IPs4b11cuq060_00850814_98e92db81 header apart1 IPs1b11cuq050_00050812_107c8b822 headers apart96 IPs626b11cuq030_00050800_e62b6d852 headers apart197 IPs552

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.