HoneyLabs

Akin HTTP request fingerprint

b11cuq060_00800817_b095d5d8

Seen 2026-02-19 to 2026-09-29 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS9541 sends an email when it next hits a sensor.

26

Source IPs

10

Networks

4

Countries

1

Ports hit

26

Events

3

IPs / network

Top networks

Countries

PK 21CN 3TH 1AR 1

Ports targeted

What it requests

User agents claimed

Hello-World26 IPs26
Source IPCCNetwork Last seenEvents
153.117.68.124PKAS9541 Cyber Internet Services (Pvt) Ltd.2026-09-111
72.255.26.49PKAS9541 Cyber Internet Services (Pvt) Ltd.2026-09-021
103.186.77.81PKAS142647 Nasstec Airnet Networks Private Limited2026-09-231
223.123.35.122PKAS138423 CMPak Limited2026-09-031
139.135.46.35PKAS9541 Cyber Internet Services (Pvt) Ltd.2026-09-181
153.117.9.176PKAS9541 Cyber Internet Services (Pvt) Ltd.2026-09-021
119.152.228.80PKAS136525 Wancom (Pvt) Ltd.2026-09-241
223.123.125.32PKAS138423 CMPak Limited2026-09-051
103.31.93.153PKAS9541 Cyber Internet Services (Pvt) Ltd.2026-09-011
137.59.218.242PKAS9541 Cyber Internet Services (Pvt) Ltd.2026-09-021
153.117.1.177PKAS9541 Cyber Internet Services (Pvt) Ltd.2026-09-211
36.255.33.120PKAS9541 Cyber Internet Services (Pvt) Ltd.2026-09-151
183.253.69.180CNAS9808 China Mobile Communications Group Co., Ltd.2026-09-231
42.237.35.35CNAS4837 CHINA UNICOM China169 Backbone2026-09-111
160.30.142.204PKAS142647 Nasstec Airnet Networks Private Limited2026-09-291
123.161.90.221CNAS4134 Chinanet2026-09-041
153.117.69.115PKAS9541 Cyber Internet Services (Pvt) Ltd.2026-09-141
103.82.120.170PKAS141342 FIBERISH (PVT) LTD2026-09-261
101.108.97.215THAS23969 TOT Public Company Limited2026-09-281
190.196.253.67ARAS266702 MEGALINK S.R.L.2026-09-281

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cuq070_00840817_81cd65141 header apart57 IPs280b11cuq060_00040817_a9482ae22 headers apart69 IPs77b11cuq060_00040817_8e5e346c2 headers apart4 IPs19b11cuq060_00040817_1d4645402 headers apart2 IPs9b11cuq080_00850817_735c13562 headers apart1 IPs8b11cuq080_00850817_a38779032 headers apart1 IPs5b11cuq060_00040817_6f9878d62 headers apart1 IPs3b11cuq060_00040817_d95592f12 headers apart1 IPs1

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.