HoneyLabs

Akin HTTP request fingerprint

b11cuq090_0005085f_0df56ff0

Seen 2026-02-16 to 2026-09-30 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS21859 sends an email when it next hits a sensor.

50

Source IPs

2

Networks

1

Countries

787

Ports hit

3.7K

Events

25

IPs / network

This fingerprint is concentrated: many addresses on very few networks, which is what a single coordinated operation tends to look like.

Top networks

Countries

PT 50

Ports targeted

What it requests

POST/mcp3.7K

User agents claimed

python-httpx/0.28.150 IPs3.7K
Source IPCCNetwork Last seenEvents
185.226.197.117PTAS21859 Zenlayer Inc2026-09-30167
185.180.141.100PTAS21859 Zenlayer Inc2026-09-30125
185.180.141.80PTAS21859 Zenlayer Inc2026-09-30114
185.180.141.90PTAS21859 Zenlayer Inc2026-09-30111
185.180.141.85PTAS21859 Zenlayer Inc2026-09-30110
185.180.141.95PTAS21859 Zenlayer Inc2026-09-3098
45.156.129.187PTAS211680 Sistemas Informaticos, S.A.2026-09-2496
45.156.129.54PTAS211680 Sistemas Informaticos, S.A.2026-09-2491
109.105.210.102PTAS21859 Zenlayer Inc2026-09-2488
109.105.210.72PTAS21859 Zenlayer Inc2026-09-2982
185.180.141.47PTAS21859 Zenlayer Inc2026-09-2982
45.156.129.95PTAS211680 Sistemas Informaticos, S.A.2026-09-2579
45.156.129.186PTAS211680 Sistemas Informaticos, S.A.2026-09-2479
185.180.141.7PTAS21859 Zenlayer Inc2026-09-3078
45.156.128.10PTAS211680 Sistemas Informaticos, S.A.2026-09-2478
185.180.141.115PTAS21859 Zenlayer Inc2026-09-3077
45.156.129.85PTAS211680 Sistemas Informaticos, S.A.2026-09-2576
45.156.129.80PTAS211680 Sistemas Informaticos, S.A.2026-09-3075
45.156.128.76PTAS211680 Sistemas Informaticos, S.A.2026-09-2475
185.226.197.27PTAS21859 Zenlayer Inc2026-09-2573

Fingerprint family: 2 shapes, 50 IPs, 7.4K events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 9 headers, Content-Length body: connection, accept-encoding, accept, accept-language, user-agent, sec-fetch-mode, content-length, content-type, host

asks for/mcp · /sse (POST / GET)
aspython-httpx/0.28.1 and 1 more
ports53 · 1599 · 3310 · 7548
fromPT · Zenlayer Inc · Sistemas Informaticos, S.A.
b11cuq090_0005085f_0df56ff0 this onepython-httpx/0.28.1 · /mcp50 IPs3.7Kb11cun080_0005005f_384a0c90+/- content-length · python-httpx/0.28.1 · /sse50 IPs3.7K

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cuq090_0005085f_959e607dsame header set1 IPs1b11cun080_0005005f_384a0c901 header apart50 IPs3.7Kb11cuq080_0005081f_76504ff61 header apart2 IPs150b11cuq080_0005081f_7db7b5821 header apart1 IPs22b11cuq080_0005081f_7d1d67701 header apart1 IPs8b11cuq080_0005081f_4ef26b0e1 header apart1 IPs2b11cuq080_0005081f_7bb249fe1 header apart1 IPs2b11cuq070_00050817_81cd65142 headers apart297 IPs1.2K

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.