HoneyLabs

Akin HTTP request fingerprint

b11cuq060_00440813_95cc9d02

Seen 2026-04-18 to 2026-09-30 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS48090 sends an email when it next hits a sensor.

2

Source IPs

2

Networks

2

Countries

1

Ports hit

5

Events

1

IPs / network

This fingerprint is spread thinly across many networks, which is the shape of a common, widely-used client.

Top networks

Countries

BG 1NL 1

Ports targeted

What it requests

User agents claimed

Go-http-client/1.11 IPs1
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.3.1 Safari/605.1.151 IPs1
Mozilla/5.0 (Fedora; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.361 IPs1
Mozilla/5.0 (Macintosh, Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Safari/605.1.151 IPs1
Mozilla/5.0 (X11; Linux i686; rv:1.9.5.20) Gecko/ Firefox/3.6.191 IPs1
Source IPCCNetwork Last seenEvents
93.123.109.214BGAS48090 Techoff Srv Limited2026-09-304
91.92.47.116NLAS197170 TechTies Inc.2026-09-061

Fingerprint family: 2 shapes, 21 IPs, 118 events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 5 headers, Content-Length body: connection, accept-encoding, user-agent, content-length, host

asks for/wsman · /GponForm/diag_Form?images/ · /tmui/locallb/workspace/tmshCmd.jsp · /apply_sec.cgi (POST / PUT)
asMozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like · Mozilla/5.0 (Windows NT 10.0; Win64; x64) · Mozilla/5.0 (Macintosh; Intel Mac OS X 10_6_8) AppleWebKit/534.59.10 (KHTML, lik and 89 more
ports443 · 5985 · 5986 · 2087
fromBG · US · GB · CH · Techoff Srv Limited · DigitalOcean, LLC · Akamai Connected Cloud
b11cuq050_00040813_2619b3acMozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like · /wsman21 IPs113b11cuq060_00440813_95cc9d02 this one+/- authorization · Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, lik · /WEB_VMS/LEVEL15/2 IPs5

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cuq050_00040813_2619b3ac1 header apart21 IPs113b11cun050_00440013_2619b3ac1 header apart13 IPs63b11cuq070_00450813_aee6d12e1 header apart1 IPs25b11cuq070_00440817_81cd65141 header apart10 IPs11b11cuq050_00040813_ca60424e1 header apart1 IPs2b11cun040_00040013_608dab682 headers apart4.3K IPs243.4Kb11cuq040_00040811_2daa70d62 headers apart237 IPs6.3Kb11cuq060_00050813_95cc9d022 headers apart55 IPs3.1K

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.