DigitalOcean Referral Badge
cloud1
cloud2
cloud3
cloud4
cloud5
cloud6
← Back

ASN REPORT — AS1221 · Telstra Limited

First sighted: June 1, 2023, 3 a.m. · Last sighted: Dec. 29, 2025, 1:59 a.m.

Risk
5 (low)
Total hits
3303
Total errors
155
Observed IPs
206
Top country
N/A
Top city
N/A

Risk

Model: v1 Computed: 2026-01-18 11:55:22
Risk score
5
Low
Risk gradient
Key drivers are enriched against the published annotator catalog when available; otherwise sensible defaults are used.
Key drivers
Command injection attempts
Request content resembles attempts to execute OS commands via an application.
cmdi
Hits 3
Points 64.84
Request size anomaly
Requests are unusually large or shaped in a way that suggests abuse or automation.
request_size
Hits 344
Points 45.18
Credential brute forcing
Repeated authentication attempts consistent with password guessing or credential stuffing.
cred
Hits 3
Points 8.80
User-Agent anomaly
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
ua
Hits 90
Points 7.91
Sensitive file probing
Requests target commonly sensitive files, configs, backups, or administrative resources.
sfp
Hits 1
Points 6.81
Automated client behavior
Traffic patterns strongly suggest automation rather than a human-operated browser.
bot
Hits 6
Points 2.85
Scan velocity
High request rate and broad endpoint coverage suggest scanning or automated enumeration.
scan_velocity
Hits 4
Points 2.52

Traffic

Rollup

Daily activity (hits per day) and basic HTTP rollup counters for this ASN.

Loading activity…
Daily activity (hits per day). Total in window: .
Traffic rollup
HTTP status classes, URL diversity, and totals.
2xx
2544
3xx
64
4xx
104
5xx
51
Unique URLs
1554
Total hits
3303
First seen
June 1, 2023, 3 a.m.
Last seen
Dec. 29, 2025, 1:59 a.m.

Annotators (All-time)

Heatmap of annotator × severity. Darker cells mean more volume in that band. Tip: switch to Weighted points to see what drives impact (not just noise).

Severity →
Low High
Request content resembles attempts to execute OS commands via an application.
hits 3 pts 64.84
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
28 2 1 41.89 June 1, 2023, 5:09 a.m. April 22, 2024, 2:47 p.m.
cmdi 2
30 1 1 22.95 April 22, 2024, 2:47 p.m. April 22, 2024, 2:47 p.m.
cmdi 1
Requests are unusually large or shaped in a way that suggests abuse or automation.
hits 344 pts 45.18
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
12 89 1 41.65 Dec. 30, 2024, 11:08 a.m. Sept. 5, 2025, 11:28 p.m.
request_size 89
14 6 1 3.53 July 26, 2025, 7:32 p.m. Nov. 6, 2025, 8:27 a.m.
request_size 6
0 249 1 0.00 Dec. 28, 2024, 11:31 p.m. Oct. 28, 2025, 11:27 a.m.
request_size 249
Repeated authentication attempts consistent with password guessing or credential stuffing.
hits 3 pts 8.80
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
12 1 1 4.95 Dec. 5, 2024, 5:44 a.m. Dec. 5, 2024, 5:44 a.m.
cred 1
10 1 1 3.85 Dec. 5, 2024, 5:44 a.m. Dec. 5, 2024, 5:44 a.m.
cred 1
0 1 1 0.00 Dec. 5, 2024, 5:44 a.m. Dec. 5, 2024, 5:44 a.m.
cred 1
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
hits 90 pts 7.91
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
6 79 1 5.69 June 1, 2023, 5:09 a.m. Sept. 6, 2025, 9:25 p.m.
ua 79
14 9 1 2.02 Jan. 5, 2025, 8:43 p.m. April 3, 2025, 12:22 p.m.
ua 9
8 2 1 0.21 April 22, 2024, 2:47 p.m. Oct. 8, 2025, 3:42 a.m.
ua 2
Requests target commonly sensitive files, configs, backups, or administrative resources.
hits 1 pts 6.81
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
36 1 1 6.81 April 22, 2024, 2:47 p.m. April 22, 2024, 2:47 p.m.
sensitive_file 1
Traffic patterns strongly suggest automation rather than a human-operated browser.
hits 6 pts 2.85
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 6 1 2.85 Sept. 12, 2024, 9:18 a.m. Sept. 5, 2025, 11:28 p.m.
bot 6
Scan velocity scan_velocity
High request rate and broad endpoint coverage suggest scanning or automated enumeration.
hits 4 pts 2.52
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 2 1 2.52 Dec. 4, 2024, 2:57 a.m. Dec. 4, 2024, 2:57 a.m.
scan_velocity 2
0 2 1 0.00 Dec. 4, 2024, 2:57 a.m. Dec. 4, 2024, 2:57 a.m.
scan_velocity 2

HTTP Status Breakdown

Response mix grouped by status class (2xx/3xx/4xx/5xx). Auto-loads a single aggregation and renders a donut.

Loading status mix…
Running one aggregation and rendering the chart.

Geolocation

Live geolocation and map tiles auto-load for this ASN snapshot (peer IPs with coordinates).

Loading map…

SUBNETS HELD BY THIS ISP

Derived from ISP snapshot peers (Option A). Grouped into IPv4 /24 and IPv6 /48 by default.
IPv4
IPv6
Limit
Loading subnets…

Interesting IPs

Top risky peers inside this ASN (latest snapshot). Sorted by risk score, then hits.

No peer rows available for this ASN snapshot.