HoneyLabs

Akin HTTP request fingerprint

b11cuq060_00040817_a9482ae2

Seen 2026-02-16 to 2026-09-30 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS9541 sends an email when it next hits a sensor.

69

Source IPs

30

Networks

11

Countries

5

Ports hit

77

Events

2

IPs / network

Top networks

Countries

PK 35CN 11US 10IN 4AR 3DE 1MA 1NL 1HR 1VN 1

Ports targeted

What it requests

POST/wsman10

User agents claimed

Hello, World56 IPs56
python-requests/2.27.110 IPs10
python-requests/2.22.01 IPs5
python-requests/2.25.11 IPs4
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.361 IPs2
Source IPCCNetwork Last seenEvents
176.65.139.131DEAS219502 Storm Industries LLC2026-09-175
36.255.97.72PKAS205759 Ghosty Networks LLC2026-09-014
104.28.238.128MAAS13335 Cloudflare, Inc.2026-09-182
103.244.172.87PKAS9541 Cyber Internet Services (Pvt) Ltd.2026-09-251
223.149.250.139CNAS4134 Chinanet2026-09-191
119.140.112.101CNAS4134 Chinanet2026-09-251
117.89.249.214CNAS4134 Chinanet2026-09-151
182.235.148.10TWAS9416 Hoshin Multimedia Center Inc.2026-09-141
44.220.185.160USAS14618 Amazon.com, Inc.2026-09-211
190.196.253.47ARAS266702 MEGALINK S.R.L.2026-09-231
103.213.112.141PKAS9541 Cyber Internet Services (Pvt) Ltd.2026-09-091
153.117.13.231PKAS9541 Cyber Internet Services (Pvt) Ltd.2026-09-111
153.117.40.177PKAS9541 Cyber Internet Services (Pvt) Ltd.2026-09-181
124.29.251.97PKAS9541 Cyber Internet Services (Pvt) Ltd.2026-09-081
203.99.56.136PKAS23674 Nayatel (Pvt) Ltd2026-09-241
103.179.240.24PKAS151330 PLAY BROADBAND (PRIVATE) LIMITED2026-09-191
72.255.15.106PKAS9541 Cyber Internet Services (Pvt) Ltd.2026-09-081
103.26.81.79PKAS9541 Cyber Internet Services (Pvt) Ltd.2026-09-071
103.176.16.73INAS135687 Qwistel Network Service Private Limited2026-09-171
115.56.150.243CNAS4837 CHINA UNICOM China169 Backbone2026-09-051

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cuq060_00040817_8e5e346csame header set4 IPs19b11cuq060_00040817_1d464540same header set2 IPs9b11cuq060_00040817_6f9878d6same header set1 IPs3b11cuq060_00040817_d95592f1same header set1 IPs1b11cuq060_00040817_229ec904same header set1 IPs1b11cun050_00040017_976354f01 header apart1.3K IPs18.7Kb11cun050_00040017_6b90553b1 header apart1.3K IPs9.3Kb11cun050_00040017_e873236c1 header apart680 IPs6.1K

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.