Akin HTTP request fingerprint
b11cuq070_00850813_aee6d12e
Seen 2026-02-27 to 2026-09-30 across the retained window.
The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked.
Or watch the top network: AS48090 sends an email when it next hits a sensor.
This fingerprint is spread thinly across many networks, which is the shape of a common, widely-used client.
User agents claimed
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like Gecko) Version/9.1.2 Safari/601.7.71 IPs2
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_5) AppleWebKit/537.78.2 (KHTML, like Gecko) Version/7.0.6 Safari/537.78.21 IPs2
Mozilla/5.01 IPs1
Mozilla/5.0 (Debian; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.361 IPs1
Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:133.0) Gecko/20100101 Firefox/133.01 IPs1
Fingerprint family: 9 shapes, 55 IPs, 3.3K events in 30 days
Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.
HTTP/1.1, 6 headers, Content-Length body: connection, accept-encoding, user-agent, content-length, content-type, host
asks for/api/v1/security/login · / · /wp-admin/admin-ajax.php · /login/?login_only=1 (POST / PUT)
asMozilla/5.0 · Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 · Go-http-client/1.1 and 929 more
ports443 · 3000 · 8888 · 8443
fromBG · US · DE · PL · Techoff Srv Limited · Amazon.com, Inc. · OVH SAS
b11cuq060_00050813_95cc9d02Mozilla/5.0 · /api/v1/security/login55 IPs3.1Kb11cuq070_00850813_aee6d12e this one+/- soapaction · Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like · /3 IPs35b11cuq071_00050813_aee6d12e_xff63+/- x-requested-with · Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:132.0) Gecko/20100101 Firefox/1 · /wp-admin/admin-ajax.php2 IPs52b11cuq070_00050c13_aee6d12e+/- referer · Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) · /remote/logincheck2 IPs40b11cuq070_08050813_aee6d12e+/- cookie · Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/605.1.15 (KHTML, lik · /vendor/htmlawed/htmlawed/htmLawedTest.php2 IPs30b11cuq070_00050817_ae8383eb+/- accept · eth-rpc-scanner/1.0 · /_ignition/execute-solution2 IPs29b11cuq093_00050813_e9212bf4_x8e84d668e7f3+/- next-action, x-nextjs-html-request-id, x-nextjs-request-id · Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) · /2 IPs14b11cuq081_00050817_735c1356_xff63+/- accept, x-requested-with · Mozilla/5.0 · /SDK/webLanguage2 IPs7b11cuq070_00050817_9a724d68+/- accept · mcp-sweep/1.0 · /mcp2 IPs3
About this fingerprint
Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.