HoneyLabs

Akin HTTP request fingerprint

b11cuq100_0015083f_6d3912e0

Seen 2026-05-13 to 2026-09-30 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS8075 sends an email when it next hits a sensor.

6

Source IPs

3

Networks

5

Countries

2

Ports hit

87

Events

2

IPs / network

Top networks

Countries

US 2SG 1NL 1JP 1FR 1

Ports targeted

What it requests

POST/87

User agents claimed

Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.366 IPs16
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.362 IPs11
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.2 Safari/605.1.152 IPs11
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 Edg/131.0.0.02 IPs10
Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.362 IPs10
Source IPCCNetwork Last seenEvents
188.166.248.40SGAS14061 DigitalOcean, LLC2026-09-1254
45.148.10.238NLAS48090 Techoff Srv Limited2026-09-3027
40.81.186.168JPAS8075 Microsoft Corporation2026-09-173
20.106.209.149USAS8075 Microsoft Corporation2026-09-141
20.19.48.9FRAS8075 Microsoft Corporation2026-09-251
74.235.187.110USAS8075 Microsoft Corporation2026-09-221

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cuq111_0015083f_197d06bc_xe7f31 header apart3 IPs4b11cuq111_0015083f_52658904_xe7f31 header apart2 IPs2b11cun080_0014003f_c4330fcc2 headers apart6 IPs3.8Kb11cun080_0014003f_335d21ef2 headers apart2 IPs193b11cuq080_0005081f_76504ff62 headers apart2 IPs150b11cun101_0015003f_b575bc6f_x7d4c2 headers apart4 IPs20b11cuq080_0015081d_40a2ef4e2 headers apart6 IPs7b11cuq101_0015081f_e78ad784_xe7f32 headers apart3 IPs4

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.