DigitalOcean Referral Badge
cloud1
cloud2
cloud3
cloud4
cloud5
cloud6
← Back

ASN REPORT — AS12989 · Black HOST Ltd

First sighted: May 1, 2023, 3 a.m. · Last sighted: Sept. 17, 2025, 2:59 a.m.

Risk
8 (low)
Total hits
1498
Total errors
254
Observed IPs
114
Top country
N/A
Top city
N/A

Risk

Model: v1 Computed: 2026-01-18 11:55:27
Risk score
8
Low
Risk gradient
Key drivers are enriched against the published annotator catalog when available; otherwise sensible defaults are used.
Key drivers
Sensitive file probing
Requests target commonly sensitive files, configs, backups, or administrative resources.
sfp
Hits 15
Points 121.44
User-Agent anomaly
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
ua
Hits 552
Points 60.42
Automated client behavior
Traffic patterns strongly suggest automation rather than a human-operated browser.
bot
Hits 52
Points 24.70
Request size anomaly
Requests are unusually large or shaped in a way that suggests abuse or automation.
request_size
Hits 24
Points 13.71

Traffic

Rollup

Daily activity (hits per day) and basic HTTP rollup counters for this ASN.

Loading activity…
Daily activity (hits per day). Total in window: .
Traffic rollup
HTTP status classes, URL diversity, and totals.
2xx
622
3xx
530
4xx
248
5xx
6
Unique URLs
550
Total hits
1498
First seen
May 1, 2023, 3 a.m.
Last seen
Sept. 17, 2025, 2:59 a.m.

Annotators (All-time)

Heatmap of annotator × severity. Darker cells mean more volume in that band. Tip: switch to Weighted points to see what drives impact (not just noise).

Severity →
Low High
Requests target commonly sensitive files, configs, backups, or administrative resources.
hits 15 pts 121.44
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
40 15 1 121.44 March 6, 2025, 11:21 p.m. March 6, 2025, 11:21 p.m.
sensitive_file 15
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
hits 552 pts 60.42
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
8 453 1 47.23 July 5, 2023, 10:32 p.m. Sept. 16, 2025, 12:17 p.m.
ua 453
12 52 1 9.73 Nov. 2, 2023, 12:06 a.m. April 15, 2024, 9:12 p.m.
ua 52
6 46 1 3.31 May 1, 2023, 6:05 p.m. April 6, 2025, 12:36 p.m.
ua 46
10 1 1 0.14 July 6, 2023, 2:34 p.m. July 6, 2023, 2:34 p.m.
ua 1
Traffic patterns strongly suggest automation rather than a human-operated browser.
hits 52 pts 24.70
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 52 1 24.70 Nov. 2, 2023, 12:06 a.m. April 15, 2024, 9:12 p.m.
bot 52
Requests are unusually large or shaped in a way that suggests abuse or automation.
hits 24 pts 13.71
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
14 24 1 13.71 Sept. 7, 2024, 8:54 p.m. Feb. 22, 2025, 9:07 a.m.
request_size 24

HTTP Status Breakdown

Response mix grouped by status class (2xx/3xx/4xx/5xx). Auto-loads a single aggregation and renders a donut.

Loading status mix…
Running one aggregation and rendering the chart.

Geolocation

Live geolocation and map tiles auto-load for this ASN snapshot (peer IPs with coordinates).

Loading map…

SUBNETS HELD BY THIS ISP

Derived from ISP snapshot peers (Option A). Grouped into IPv4 /24 and IPv6 /48 by default.
IPv4
IPv6
Limit
Loading subnets…

Interesting IPs

Top risky peers inside this ASN (latest snapshot). Sorted by risk score, then hits.

No peer rows available for this ASN snapshot.