And those are just the headers! Just taking a cursory look at [4], I can see it is claiming to be a ASP.net server being served by a TP-Link device on one port, all the while also being a QNAP device on another, and also another PHP application served through thttpd. All the while running on AWS...
[1] https://www.shodan.io/host/44.204.245.187
[2] https://www.shodan.io/host/13.246.35.40
If nothing else, it's fun to see who pokes you, even if I don't actually follow up on it.
I wouldn't conclude that to be a honeypot. If anything, BIG-IP and Confluence are frequently used by the same kinds of companies, so I would expect the majority of that first query to be real Confluence servers. Queries 2-4 probably did a better job filtering out real honeypots.
In reality, there might be about as many honeypots as there are real Confluence servers, which is still far too many, but not quite as extreme a disparity as suggested by the numbers in this article.