HoneyLabs

Akin HTTP request fingerprint

b10cuq040_00850800_a31e7c35

Seen 2026-02-18 to 2026-09-30 across the retained window.

The feed is a URL your firewall, MISP or SIEM polls; it needs a free account so it can be revoked. Or watch the top network: AS9541 sends an email when it next hits a sensor.

28

Source IPs

16

Networks

9

Countries

1

Ports hit

28

Events

2

IPs / network

This fingerprint is spread thinly across many networks, which is the shape of a common, widely-used client.

Top networks

Countries

PK 11CN 5AR 3PH 2RU 2VN 2UZ 1ID 1GE 1

Ports targeted

What it requests

POST/HNAP1/28
Source IPCCNetwork Last seenEvents
103.244.172.119PKAS9541 Cyber Internet Services (Pvt) Ltd.2026-09-211
180.249.37.145IDAS7713 PT Telekomunikasi Indonesia2026-09-301
171.233.35.114VNAS7552 Viettel Group2026-09-041
103.82.120.214PKAS141342 FIBERISH (PVT) LTD2026-09-061
31.148.197.63UZAS210519 ToshTeleQabul MChJ2026-09-011
223.123.35.168PKAS138423 CMPak Limited2026-09-111
222.127.158.71PHAS132199 Globe Telecom Inc.2026-09-021
195.191.130.218RUAS50536 JSC Sigma-KTV2026-09-281
180.191.22.170PHAS132199 Globe Telecom Inc.2026-09-071
175.147.253.125CNAS4837 CHINA UNICOM China169 Backbone2026-09-241
190.196.253.85ARAS266702 MEGALINK S.R.L.2026-09-181
188.129.211.113GEAS16010 Magticom Ltd.2026-09-011
139.100.247.6RUAS61436 INTEX ltd.2026-09-261
27.215.126.48CNAS4837 CHINA UNICOM China169 Backbone2026-09-191
203.99.56.133PKAS23674 Nayatel (Pvt) Ltd2026-09-241
190.196.253.122ARAS266702 MEGALINK S.R.L.2026-09-081
223.123.73.182PKAS59257 CMPak Limited2026-09-181
171.239.147.32VNAS7552 Viettel Group2026-09-091
190.196.253.51ARAS266702 MEGALINK S.R.L.2026-09-041
223.123.73.157PKAS59257 CMPak Limited2026-09-241

Related fingerprints

Clients whose header set is within two of this one, measured from the tokens themselves.

b11cuq030_00050800_e62b6d851 header apart197 IPs552b11cuq030_00810800_7e369cbb1 header apart75 IPs99b11cuq050_00850810_800b45671 header apart46 IPs47b11cuq050_00850801_985b94971 header apart3 IPs11b10cuq050_00850810_bb92d2381 header apart6 IPs6b10cuq030_00810800_e62b6d851 header apart2 IPs4b10cuq030_00810800_7e369cbb1 header apart1 IPs1b11cuq040_00050801_2daa70d62 headers apart93 IPs659

About this fingerprint

Akin fingerprints an HTTP client from the request head alone: the protocol version, line endings, body framing, which headers are present, and the grammar of the negotiation header values. The User-Agent string and the request path are deliberately excluded, because both are trivially changed and both were measured varying within a single operator, so a scanner that rotates either keeps one fingerprint. The middle section is a presence bitmap rather than a hash, so two tokens can be compared directly to see how many headers the clients differ by.