HoneyLabs

Akin HTTP request fingerprint

b11cuq040_02050800_f46b29fb

Seen 2026-02-16 to 2026-09-30 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS396982 sends an email when it next hits a sensor.

178

Source IPs

1

Networks

1

Countries

2

Ports hit

228

Events

178

IPs / network

This fingerprint is concentrated: many addresses on very few networks, which is what a single coordinated operation tends to look like.

Top networks

Countries

US 178

Ports targeted

What it requests

POST/wsman228
Source IPCCNetwork Last seenEvents
198.235.24.51USAS396982 Google LLC2026-09-123
205.210.31.174USAS396982 Google LLC2026-09-263
205.210.31.162USAS396982 Google LLC2026-09-283
205.210.31.223USAS396982 Google LLC2026-09-273
147.185.132.105USAS396982 Google LLC2026-09-123
205.210.31.245USAS396982 Google LLC2026-09-243
147.185.132.198USAS396982 Google LLC2026-09-122
205.210.31.74USAS396982 Google LLC2026-09-142
198.235.24.52USAS396982 Google LLC2026-09-182
205.210.31.84USAS396982 Google LLC2026-09-292
147.185.132.73USAS396982 Google LLC2026-09-242
205.210.31.224USAS396982 Google LLC2026-09-292
205.210.31.170USAS396982 Google LLC2026-09-302
198.235.24.185USAS396982 Google LLC2026-09-262
198.235.24.40USAS396982 Google LLC2026-09-172
205.210.31.220USAS396982 Google LLC2026-09-212
205.210.31.70USAS396982 Google LLC2026-09-232
147.185.132.112USAS396982 Google LLC2026-09-102
205.210.31.98USAS396982 Google LLC2026-09-272
147.185.132.75USAS396982 Google LLC2026-09-302

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cuq030_00050800_e62b6d851 header apart197 IPs552b11cuq060_02050811_e545b78f2 headers apart114 IPs5.7Kb11cuq040_00050801_2daa70d62 headers apart93 IPs659b11cuq040_00050801_0e54e4f42 headers apart1 IPs144b11cuq040_00050802_cfad16f72 headers apart1 IPs68b10cuq040_00850800_a31e7c352 headers apart28 IPs28b11cuq040_00050810_a31e7c352 headers apart6 IPs20b11cuq040_00050801_bf8a4cbb2 headers apart8 IPs10

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.