HoneyLabs

Akin HTTP request fingerprint

b11cuq070_00050817_9a724d68

Seen 2026-09-28 to 2026-09-30 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS48090 sends an email when it next hits a sensor.

2

Source IPs

2

Networks

2

Countries

2

Ports hit

3

Events

1

IPs / network

This fingerprint is spread thinly across many networks, which is the shape of a common, widely-used client.

Top networks

Countries

BG 1NL 1

Ports targeted

What it requests

POST/mcp3

User agents claimed

mcp-sweep/1.01 IPs1
Mozilla/5.0 (Macintosh; Intel Mac OS X 14_3) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.2 Safari/605.1.151 IPs1
Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/112.01 IPs1
Source IPCCNetwork Last seenEvents
93.123.109.214BGAS48090 Techoff Srv Limited2026-09-302
87.199.202.66NLAS216071 Servers Tech Fzco2026-09-291

Fingerprint family: 8 shapes, 55 IPs, 3.3K events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 6 headers, Content-Length body: connection, accept-encoding, user-agent, content-length, content-type, host

asks for/api/v1/security/login · /wp-admin/admin-ajax.php · /login/?login_only=1 · /index.php (POST / PUT)
asMozilla/5.0 · Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 · Go-http-client/1.1 and 905 more
ports443 · 3000 · 8888 · 8443
fromBG · US · DE · PL · Techoff Srv Limited · Amazon.com, Inc. · OVH SAS
b11cuq060_00050813_95cc9d02Mozilla/5.0 · /api/v1/security/login55 IPs3.1Kb11cuq070_00850813_aee6d12e+/- soapaction · Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_5) AppleWebKit/537.78.2 (KHTML, like · /3 IPs35b11cuq071_00050813_aee6d12e_xff63+/- x-requested-with · Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:132.0) Gecko/20100101 Firefox/1 · /wp-admin/admin-ajax.php2 IPs52b11cuq070_00050c13_aee6d12e+/- referer · Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) · /remote/logincheck2 IPs40b11cuq070_08050813_aee6d12e+/- cookie · Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, lik · /vendor/htmlawed/htmlawed/htmLawedTest.php2 IPs30b11cuq093_00050813_e9212bf4_x8e84d668e7f3+/- next-action, x-nextjs-html-request-id, x-nextjs-request-id · Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) · /2 IPs14b11cuq081_00050817_735c1356_xff63+/- accept, x-requested-with · Mozilla/5.0 · /SDK/webLanguage2 IPs7b11cuq070_00050817_9a724d68 this one+/- accept · Mozilla/5.0 (Macintosh; Intel Mac OS X 14_3) AppleWebKit/605.1.15 (KHTML, like G · /mcp2 IPs3

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cuq070_00050817_81cd6514same header set304 IPs1.2Kb11cuq070_00050817_9c017ed9same header set12 IPs231b11cuq070_00050817_9f8bde3dsame header set11 IPs51b11cuq070_00050817_bad9ef97same header set18 IPs36b11cuq070_00050817_ae8383ebsame header set3 IPs34b11cuq070_00050817_fdd8f8c3same header set7 IPs21b11cuq070_00050817_c5c151c1same header set2 IPs13b11cuq070_00050817_44096d2bsame header set3 IPs9

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.