HoneyLabs

Akin HTTP request fingerprint

b11cuq070_00050817_81cd6514

Seen 2026-02-17 to 2026-09-30 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS14061 sends an email when it next hits a sensor.

300

Source IPs

169

Networks

55

Countries

13

Ports hit

1.2K

Events

2

IPs / network

This fingerprint is spread thinly across many networks, which is the shape of a common, widely-used client.

Top networks

Countries

IN 43CN 34US 29HK 19SG 14BD 9IR 9ID 8PK 8FR 8

Ports targeted

What it requests

POST/wsman506
POST/389
POST/login92
POST/json_rpc10

User agents claimed

Python WinRM client254 IPs506
Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.03 IPs155
Mozilla/5.02 IPs92
Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.3622 IPs51
Mozilla/5.0 (iPad; CPU OS 17_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.3 Mobile/15E148 Safari/604.11 IPs44
Source IPCCNetwork Last seenEvents
147.139.204.195IDAS45102 Alibaba (US) Technology Co., Ltd.2026-09-10281
134.199.238.38USAS14061 DigitalOcean, LLC2026-09-3065
51.89.199.106GBAS16276 OVH SAS2026-09-2962
51.89.255.207GBAS16276 OVH SAS2026-09-2162
91.124.17.36USAS174 Cogent Communications, LLC2026-09-0736
143.105.152.117CMAS14593 Space Exploration Technologies Corporation2026-09-2331
64.23.217.254USAS14061 DigitalOcean, LLC2026-09-0927
124.106.67.118PHAS9299 Philippine Long Distance Telephone Company2026-09-2412
115.187.59.168INAS23860 Alliance Broadband Services Pvt. Ltd.2026-09-1312
66.240.192.138USAS10439 CariNet, Inc.2026-09-1410
20.106.228.98USAS8075 Microsoft Corporation2026-09-1510
36.255.97.72PKAS205759 Ghosty Networks LLC2026-09-018
109.205.176.10FRAS51167 Contabo GmbH2026-09-308
45.204.10.125SCAS132813 HK AISI CLOUD COMPUTING LIMITED2026-09-128
86.54.31.32GBAS12989 Black HOST Ltd2026-09-277
45.42.40.106USAS212238 Datacamp Limited2026-09-267
178.135.49.180LBAS42003 OGERO2026-09-267
136.228.165.138MMAS9988 Myanma Posts and Telecommunications2026-09-056
203.145.63.139IDAS46023 PT Quantum Tera Network2026-09-296
103.233.10.108HKAS133201 ABCDE GROUP2026-09-126

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cuq070_00050817_3826af57same header set1 IPs538b11cuq070_00050817_68b419c1same header set1 IPs480b11cuq070_00050817_9c017ed9same header set13 IPs238b11cuq070_00050817_9f8bde3dsame header set11 IPs51b11cuq070_00050817_bad9ef97same header set18 IPs36b11cuq070_00050817_ae8383ebsame header set2 IPs29b11cuq070_00050817_af581401same header set1 IPs28b11cuq070_00050817_fdd8f8c3same header set7 IPs21

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.