HoneyLabs

Akin HTTP request fingerprint

b11cuq093_00050813_e9212bf4_x8e84d668e7f3

Seen 2026-02-17 to 2026-09-30 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS197170 sends an email when it next hits a sensor.

2

Source IPs

2

Networks

2

Countries

2

Ports hit

14

Events

1

IPs / network

This fingerprint is spread thinly across many networks, which is the shape of a common, widely-used client.

Top networks

Countries

NL 1BG 1

Ports targeted

What it requests

POST/14

User agents claimed

Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36 Assetnote/1.0.01 IPs10
Mozilla/5.0 (Macintosh; Intel Mac OS X 14_4_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4.1 Safari/605.1.151 IPs1
Mozilla/5.0 (Windows NT 6.1; rv:38.0) Gecko/20100101 Firefox/38.01 IPs1
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.11 Mobile/15E148 Safari/604.11 IPs1
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 Version/16.3 Safari/605.1.151 IPs1
Source IPCCNetwork Last seenEvents
91.92.40.236NLAS197170 TechTies Inc.2026-09-1510
93.123.109.214BGAS48090 Techoff Srv Limited2026-09-304

Fingerprint family: 9 shapes, 55 IPs, 3.3K events in 30 days

Every shape here is within one request header of the family's largest shape and comes from the same source addresses. One tool, several request shapes; a hashed fingerprint shows these as unrelated.

HTTP/1.1, 6 headers, Content-Length body: connection, accept-encoding, user-agent, content-length, content-type, host

asks for/api/v1/security/login · / · /wp-admin/admin-ajax.php · /login/?login_only=1 (POST / PUT)
asMozilla/5.0 · Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 · Go-http-client/1.1 and 929 more
ports443 · 3000 · 8888 · 8443
fromBG · US · DE · PL · Techoff Srv Limited · Amazon.com, Inc. · OVH SAS
b11cuq060_00050813_95cc9d02Mozilla/5.0 · /api/v1/security/login55 IPs3.1Kb11cuq070_00850813_aee6d12e+/- soapaction · Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_5) AppleWebKit/537.78.2 (KHTML, like · /3 IPs35b11cuq071_00050813_aee6d12e_xff63+/- x-requested-with · Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:132.0) Gecko/20100101 Firefox/1 · /wp-admin/admin-ajax.php2 IPs52b11cuq070_00050c13_aee6d12e+/- referer · Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) · /remote/logincheck2 IPs40b11cuq070_08050813_aee6d12e+/- cookie · Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/605.1.15 (KHTML, lik · /vendor/htmlawed/htmlawed/htmLawedTest.php2 IPs30b11cuq070_00050817_ae8383eb+/- accept · eth-rpc-scanner/1.0 · /_ignition/execute-solution2 IPs29b11cuq093_00050813_e9212bf4_x8e84d668e7f3 this one+/- next-action, x-nextjs-html-request-id, x-nextjs-request-id · Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) · /2 IPs14b11cuq081_00050817_735c1356_xff63+/- accept, x-requested-with · Mozilla/5.0 · /SDK/webLanguage2 IPs7b11cuq070_00050817_9a724d68+/- accept · mcp-sweep/1.0 · /mcp2 IPs3

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cuq093_00050813_59548195_x8e84d668e7f3same header set1 IPs2.9Kb11cuq071_00050813_aee6d12e_xe7f32 headers apart51 IPs349

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.