HoneyLabs

Akin HTTP request fingerprint

b11cuq050_00050805_650ae0b2

Seen 2026-02-16 to 2026-09-30 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS398324 sends an email when it next hits a sensor.

123

Source IPs

3

Networks

1

Countries

2

Ports hit

161

Events

41

IPs / network

This fingerprint is concentrated: many addresses on very few networks, which is what a single coordinated operation tends to look like.

Top networks

Countries

US 123

Ports targeted

What it requests

POST/wsman161
Source IPCCNetwork Last seenEvents
167.94.146.55USAS398705 Censys, Inc.2026-09-276
167.94.146.56USAS398705 Censys, Inc.2026-09-306
167.94.146.50USAS398705 Censys, Inc.2026-09-284
167.94.146.49USAS398705 Censys, Inc.2026-09-133
66.132.195.56USAS398324 Censys, Inc.2026-09-233
167.94.146.59USAS398705 Censys, Inc.2026-09-123
199.45.154.74USAS398722 Censys, Inc.2026-09-253
167.94.146.53USAS398705 Censys, Inc.2026-09-293
167.94.146.57USAS398705 Censys, Inc.2026-09-043
66.132.172.197USAS398324 Censys, Inc.2026-09-082
167.94.146.51USAS398705 Censys, Inc.2026-09-212
199.45.155.23USAS398722 Censys, Inc.2026-09-212
66.132.172.44USAS398324 Censys, Inc.2026-09-282
66.132.186.179USAS398324 Censys, Inc.2026-09-122
167.94.146.63USAS398705 Censys, Inc.2026-09-252
66.132.172.186USAS398324 Censys, Inc.2026-09-132
66.132.224.92USAS398324 Censys, Inc.2026-09-282
199.45.155.51USAS398722 Censys, Inc.2026-09-222
66.132.224.234USAS398324 Censys, Inc.2026-09-232
66.132.172.143USAS398324 Censys, Inc.2026-09-292

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cuq050_00050805_df66fe0fsame header set1 IPs39b11cuq050_00050805_b56b526esame header set33 IPs33b11cuq040_00050801_2daa70d61 header apart93 IPs659b11cuq060_00050815_9e42e2331 header apart14 IPs490b11cuq060_00050815_a38e1c5d1 header apart1 IPs336b11cuq040_00050801_0e54e4f41 header apart1 IPs144b11cuq060_00050815_30319a111 header apart23 IPs61b11cuq060_00050815_c1fcf7351 header apart1 IPs21

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.