What hits a public IP echo service?
Analysis of request logs from ipthing.net — a small service that shows clients their IP, headers, and TLS details. This is not a census of the internet; it is a long-running sample of who probes (or uses) such an endpoint.
Dataset at a glance
GET /, but scanners leave fingerprints
in query-parameter names, odd Host/SNI pairs, and rare spoofed
forwarding headers. See Probe behaviour below.
Did they know the name?
We classify each request from the HTTP Host header and TLS SNI
(tls_server_name):
- named —
ipthing.net(or a subdomain) appears in Host and/or SNI. Strong signal the client resolved or was given the DNS name. - raw IP — Host is a literal IPv4 address (often
159.203.159.64or an older droplet IP). Typical of address-space scanners and tools that never looked up the name. - other Host — some other hostname (CDN leftovers, random/spoofed names). Often opportunistic TLS or misdirected probes.
- unknown — Host was empty; common on older rows before that field was logged.
| Access mode | Requests | Distinct IPs |
|---|---|---|
| unknown (Host unset) | 176,653 | 17,839 |
| named (ipthing.net) | 137,779 | 4,320 |
| raw IP (Host is address) | 16,249 | 4,688 |
| other Host (wrong/spoofed name) | 433 | 287 |
Top Host values (including empty) show the same split in raw form —
named traffic clusters on ipthing.net; raw-IP traffic on the server addresses.
| Host header | Requests |
|---|---|
(empty) | 176,653 |
ipthing.net | 136,642 |
67.205.178.64:80 | 4,502 |
159.203.159.64:80 | 4,388 |
159.203.159.64 | 3,879 |
67.205.178.64 | 3,469 |
www.ipthing.net | 986 |
edge-d.estage.com | 150 |
IPTHING.NET | 140 |
67-205-178-64.cprapid.com | 119 |
origin-d.estage.com | 109 |
quirky-chaum.67-205-178-64.plesk.page | 10 |
example.com | 9 |
ipthing.net:80 | 5 |
test.ipthing.net | 5 |
103.3.60.134 | 4 |
bs2tor.at | 4 |
81.174.155.2:80 | 3 |
tokenid.rouwowu.ru | 3 |
pica-a-display.diwodiwo.xyz | 2 |
Probe behaviour
Security-oriented shape of the traffic: verbs and paths, query-parameter
names scanners inject, whether clients send spoofed forwarding headers, and
whether HTTP Host matches TLS SNI. Counts only — no raw header
dumps or query values.
X-Forwarded-For / CF-Connecting-IP that
disagree with the peer are classic spoof attempts (or traffic that really
did pass a proxy). Both are rare here — rarity is the finding.
| Method | Requests | Distinct IPs |
|---|---|---|
GET |
331,114 | 24,021 |
| Path | Requests | Distinct IPs |
|---|---|---|
/ |
331,114 | 24,021 |
Query parameter names (not values) are a cheap fingerprint of
vulnerability scanners: phpinfo, rest_route,
file, Xdebug session starters, and similar show up even when
the path is still /.
| Query param name | Requests |
|---|---|
_ |
2,292 |
v |
2,290 |
phpinfo |
532 |
XDEBUG_SESSION_START |
446 |
url |
239 |
rest_route |
210 |
file |
204 |
page |
169 |
path |
122 |
load |
110 |
read |
104 |
doc |
101 |
source |
94 |
template |
91 |
document |
90 |
include |
87 |
data |
86 |
lang |
85 |
folder |
84 |
module |
83 |
content |
82 |
action |
78 |
layout |
78 |
view |
77 |
dir |
74 |
Host vs SNI: agreement usually means a normal TLS client. Empty SNI with a Host set is common on plain HTTP or incomplete older rows. A mismatch (when both are set) is a stronger opportunistic / misdirected probe signal.
| Host / SNI relation | Requests | Distinct IPs |
|---|---|---|
| both empty | 176,653 | 17,839 |
| Host and SNI agree | 134,392 | 2,865 |
| Host set, SNI empty | 20,069 | 6,406 |
Volume over time
Spikes often align with internet-wide scanning and cloud automation, not only human “what’s my IP?” visits. Quiet days and noisy days are both informative.
Where clients appear to be
Country and org come from a geolocation cache (ipinfo-style fields) keyed by IP. Cloud and CDN ASNs dominate because scanners, health checks, and hosted tools live there — not because “most humans” do.
| Country | Distinct IPs |
|---|---|
| US | 9,760 |
| (unknown) | 2,604 |
| NL | 1,444 |
| DE | 1,335 |
| GB | 1,168 |
| BE | 951 |
| SG | 914 |
| CA | 748 |
| CN | 715 |
| FR | 625 |
| HK | 387 |
| IN | 362 |
| BR | 304 |
| JP | 303 |
| RU | 295 |
| SE | 235 |
| ID | 167 |
| TW | 151 |
| AU | 144 |
| KR | 142 |
Which networks show up most
High ranks for DigitalOcean, Google, Cloudflare, Amazon, Microsoft, and Censys are expected for a reachable reflector: research scanners, bots, and cloud VMs check such hosts continuously.
| Org / ASN label | Distinct IPs |
|---|---|
| AS14061 DigitalOcean, LLC | 2,690 |
| (unknown) | 2,616 |
| AS396982 Google LLC | 2,493 |
| AS13335 Cloudflare, Inc. | 2,258 |
| AS14618 Amazon.com, Inc. | 1,184 |
| AS16509 Amazon.com, Inc. | 1,032 |
| AS8075 Microsoft Corporation | 891 |
| AS132203 Tencent Building, Kejizhongyi Avenue | 634 |
| AS16276 OVH SAS | 632 |
| AS45102 Alibaba (US) Technology Co., Ltd. | 615 |
| AS25369 Hydra Communications Ltd | 557 |
| AS398324 Censys, Inc. | 478 |
| AS63949 Akamai Connected Cloud | 427 |
| AS135377 UCLOUD INFORMATION TECHNOLOGY (HK) LIMITED | 349 |
| AS211298 Driftnet Ltd | 271 |
| AS213412 ONYPHE SAS | 248 |
| AS4837 CHINA UNICOM China169 Backbone | 143 |
| AS211680 NSEC - Sistemas Informaticos, S.A. | 135 |
| AS51396 Pfcloud UG | 130 |
| AS9009 M247 Europe SRL | 129 |
TLS and HTTP versions
Modern stacks prefer TLS 1.3 and HTTP/2. Older protocols still appear from legacy clients and some scanners. Empty protocol fields usually mean older log rows before those columns were populated.
Client flavour (User-Agent heuristics)
Buckets are coarse string heuristics, not a security product. They separate casual browser-like traffic from curl/scripts and explicit bot UAs so the report can talk about mix without claiming perfect classification.
How to read this responsibly
- Selection bias: only hosts that chose (or were pointed at) ipthing.
- Geo/ASN labels are best-effort and can lag or mis-attribute shared IPs.
- Public pages should stay aggregated; raw headers, cookies, and query values are out of scope here (param names only).