HoneyLabs

Akin HTTP request fingerprint

b11cuq060_00050813_95cc9d02

Seen 2026-02-18 to 2026-09-30 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS14061 sends an email when it next hits a sensor.

55

Source IPs

32

Networks

17

Countries

21

Ports hit

3.1K

Events

2

IPs / network

This fingerprint is spread thinly across many networks, which is the shape of a common, widely-used client.

Top networks

Countries

US 19DE 7NL 7IN 4GB 3CN 3BG 2PL 1FR 1TR 1

Ports targeted

What it requests

POST/124
POST/_session32

User agents claimed

Mozilla/5.08 IPs787
Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.361 IPs609
Go-http-client/1.133 IPs94
Python-urllib/3.132 IPs9
Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 Chrome/153.0.0.0 Safari/537.361 IPs8
Source IPCCNetwork Last seenEvents
93.123.109.214BGAS48090 Techoff Srv Limited2026-09-301.6K
52.24.112.111USAS16509 Amazon.com, Inc.2026-09-02609
87.106.118.51DEAS8560 IONOS SE2026-09-03294
57.128.237.218PLAS16276 OVH SAS2026-09-19192
46.105.77.141FRAS16276 OVH SAS2026-09-17144
130.61.131.237DEAS31898 Oracle Corporation2026-09-18144
47.251.42.6USAS45102 Alibaba (US) Technology Co., Ltd.2026-09-2818
13.72.110.24USAS8075 Microsoft Corporation2026-09-2614
195.178.110.50BGAS48090 Techoff Srv Limited2026-09-2814
212.18.108.190TRAS57497 Faraso Samaneh Pasargad Ltd.2026-09-2910
52.146.20.92USAS8075 Microsoft Corporation2026-09-169
16.5.0.236USAS401661 EMBNEX, LLC2026-09-088
91.92.47.116NLAS197170 TechTies Inc.2026-09-067
95.180.49.191RSAS31042 Yettel d.o.o.2026-09-026
2.26.172.97DEAS215703 Freakhosting Ltd2026-09-034
104.28.192.66GBAS13335 Cloudflare, Inc.2026-09-044
103.119.2.158CNAS55933 Cloudie Limited2026-09-114
147.124.211.67USAS396073 Majestic Hosting Solutions, LLC2026-09-153
104.28.224.66GBAS13335 Cloudflare, Inc.2026-09-053
91.92.47.58NLAS197170 TechTies Inc.2026-09-182

Fingerprint family: 9 shapes, 55 IPs, 3.3K events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 6 headers, Content-Length body: connection, accept-encoding, user-agent, content-length, content-type, host

asks for/api/v1/security/login · / · /wp-admin/admin-ajax.php · /login/?login_only=1 (POST / PUT)
asMozilla/5.0 · Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 · Go-http-client/1.1 and 929 more
ports443 · 3000 · 8888 · 8443
fromBG · US · DE · PL · Techoff Srv Limited · Amazon.com, Inc. · OVH SAS
b11cuq060_00050813_95cc9d02 this oneMozilla/5.0 · /api/v1/security/login55 IPs3.1Kb11cuq070_00850813_aee6d12e+/- soapaction · Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like · /3 IPs35b11cuq071_00050813_aee6d12e_xff63+/- x-requested-with · Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:132.0) Gecko/20100101 Firefox/1 · /wp-admin/admin-ajax.php2 IPs52b11cuq070_00050c13_aee6d12e+/- referer · Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) · /remote/logincheck2 IPs40b11cuq070_08050813_aee6d12e+/- cookie · Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/605.1.15 (KHTML, lik · /vendor/htmlawed/htmlawed/htmLawedTest.php2 IPs30b11cuq070_00050817_ae8383eb+/- accept · eth-rpc-scanner/1.0 · /_ignition/execute-solution2 IPs29b11cuq093_00050813_e9212bf4_x8e84d668e7f3+/- next-action, x-nextjs-html-request-id, x-nextjs-request-id · Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) · /2 IPs14b11cuq081_00050817_735c1356_xff63+/- accept, x-requested-with · Mozilla/5.0 · /SDK/webLanguage2 IPs7b11cuq070_00050817_9a724d68+/- accept · mcp-sweep/1.0 · /mcp2 IPs3

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cuq060_00050813_8587a3e3same header set4 IPs107b11cuq060_00050813_ce171241same header set1 IPs8b11cuq060_00050813_c5985540same header set1 IPs6b11cdq070_00050813_29ad8489same header set1 IPs6b11cuq060_00050813_d714950csame header set1 IPs4b11cuq060_00050813_650beed2same header set1 IPs3b11cuq071_00050813_aee6d12e_xe7f31 header apart51 IPs349b11cuq071_00050813_aee6d12e_xff631 header apart2 IPs52

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.