HoneyLabs

Akin HTTP request fingerprint

b11cuq081_00050817_735c1356_xff63

Seen 2026-04-17 to 2026-09-30 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS48090 sends an email when it next hits a sensor.

2

Source IPs

1

Networks

2

Countries

3

Ports hit

7

Events

2

IPs / network

Top networks

Countries

NL 1BG 1

Ports targeted

What it requests

User agents claimed

Mozilla/5.01 IPs4
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/106.0.0.0 Safari/537.361 IPs1
Mozilla/5.0 (SS; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/141.0.0.0 Safari/537.361 IPs1
Mozilla/5.0 (Debian; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.361 IPs1
Source IPCCNetwork Last seenEvents
45.148.10.175NLAS48090 Techoff Srv Limited2026-09-164
93.123.109.214BGAS48090 Techoff Srv Limited2026-09-303

Fingerprint family: 8 shapes, 54 IPs, 3.3K events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 6 headers, Content-Length body: connection, accept-encoding, user-agent, content-length, content-type, host

asks for/api/v1/security/login · / · /login/?login_only=1 · /wp-admin/admin-ajax.php (POST / PUT)
asMozilla/5.0 · Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 · Go-http-client/1.1 and 905 more
ports443 · 3000 · 8888 · 8443
fromBG · US · DE · PL · Techoff Srv Limited · Amazon.com, Inc. · OVH SAS
b11cuq060_00050813_95cc9d02Mozilla/5.0 · /api/v1/security/login54 IPs3.1Kb11cuq070_00850813_aee6d12e+/- soapaction · Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/601.7.7 (KHTML, like · /3 IPs36b11cuq071_00050813_aee6d12e_xff63+/- x-requested-with · Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:132.0) Gecko/20100101 Firefox/1 · /wp-admin/admin-ajax.php2 IPs52b11cuq070_00050c13_aee6d12e+/- referer · Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) · /remote/logincheck2 IPs40b11cuq070_08050813_aee6d12e+/- cookie · Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/605.1.15 (KHTML, lik · /vendor/htmlawed/htmlawed/htmLawedTest.php2 IPs30b11cuq093_00050813_e9212bf4_x8e84d668e7f3+/- next-action, x-nextjs-html-request-id, x-nextjs-request-id · Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) · /2 IPs14b11cuq081_00050817_735c1356_xff63 this one+/- accept, x-requested-with · Mozilla/5.0 · /SDK/webLanguage2 IPs7b11cuq070_00050817_9a724d68+/- accept · mcp-sweep/1.0 · /mcp2 IPs3

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cuq092_00050817_0d7eec78_xd368ff631 header apart2 IPs2.0Kb11cuq070_00050817_81cd65141 header apart306 IPs1.2Kb11cuq070_00050817_9c017ed91 header apart12 IPs231b11cuq071_00050813_aee6d12e_xff631 header apart2 IPs52b11cuq070_00050817_9f8bde3d1 header apart11 IPs51b11cuq070_00050817_ae8383eb1 header apart4 IPs39b11cuq070_00050817_bad9ef971 header apart17 IPs34b11cuq070_00050817_fdd8f8c31 header apart7 IPs21

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.