DigitalOcean Referral Badge
cloud1
cloud2
cloud3
cloud4
cloud5
cloud6
← Back

ASN REPORT — AS132203 · Tencent Building, Kejizhongyi Avenue

First sighted: July 6, 2023, 3 a.m. · Last sighted: Jan. 26, 2026, 1:59 a.m.

Risk
100 (high)
Total hits
67625
Total errors
10572
Observed IPs
18392
Top country
N/A
Top city
N/A

Risk

Model: v1 Computed: 2026-01-29 10:18:33
Risk score
100
High
Risk gradient
Key drivers are enriched against the published annotator catalog when available; otherwise sensible defaults are used.
Key drivers
Sensitive file probing
Requests target commonly sensitive files, configs, backups, or administrative resources.
sfp
Hits 5147
Points 39773.92
Path traversal attempts
Request paths/parameters resemble attempts to access files outside intended directories.
trav
Hits 449
Points 3131.61
Scan velocity
High request rate and broad endpoint coverage suggest scanning or automated enumeration.
scan_velocity
Hits 1098
Points 2019.01
Credential brute forcing
Repeated authentication attempts consistent with password guessing or credential stuffing.
cred
Hits 791
Points 1841.62
Request size anomaly
Requests are unusually large or shaped in a way that suggests abuse or automation.
request_size
Hits 909
Points 529.16
Command injection attempts
Request content resembles attempts to execute OS commands via an application.
cmdi
Hits 29
Points 512.52
User-Agent anomaly
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
ua
Hits 3140
Points 428.31
Automated client behavior
Traffic patterns strongly suggest automation rather than a human-operated browser.
bot
Hits 368
Points 174.80
Protocol anomaly
Request structure or protocol-level signals deviate from typical browser HTTP traffic.
proto
Hits 105
Points 59.69
Firewall probing
Traffic behavior suggests probing of access controls and protected surfaces.
fwprobe
Hits 5
Points 44.10

Traffic

Rollup

Daily activity (hits per day) and basic HTTP rollup counters for this ASN.

Loading activity…
Daily activity (hits per day). Total in window: .
Traffic rollup
HTTP status classes, URL diversity, and totals.
2xx
27976
3xx
28446
4xx
10264
5xx
308
Unique URLs
21568
Total hits
67625
First seen
July 6, 2023, 3 a.m.
Last seen
Jan. 26, 2026, 1:59 a.m.

Annotators (All-time)

Heatmap of annotator × severity. Darker cells mean more volume in that band. Tip: switch to Weighted points to see what drives impact (not just noise).

Severity →
Low High
Requests target commonly sensitive files, configs, backups, or administrative resources.
hits 5147 pts 39773.92
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
40 4598 1 37225.41 Aug. 10, 2023, 4:49 p.m. Nov. 29, 2025, 7:55 a.m.
sensitive_file 4598
34 139 1 894.16 June 5, 2024, 9:33 a.m. Oct. 2, 2025, 8:14 a.m.
sensitive_file 139
16 222 1 547.01 May 25, 2024, 3:12 a.m. Sept. 10, 2025, 3:12 a.m.
sensitive_file 222
36 54 1 376.36 May 28, 2024, 2:03 a.m. April 20, 2025, 10:56 a.m.
sensitive_file 54
30 33 1 185.13 June 5, 2024, 9:48 p.m. March 28, 2025, 12:56 p.m.
sensitive_file 33
22 45 1 169.88 Feb. 11, 2024, 3:27 p.m. March 28, 2025, 12:57 p.m.
sensitive_file 45
42 16 1 136.01 March 14, 2025, 11:56 p.m. March 27, 2025, 8:48 p.m.
sensitive_file 16
44 14 1 127.39 June 8, 2024, 6:36 a.m. March 14, 2025, 11:56 p.m.
sensitive_file 14
24 26 1 112.57 May 25, 2024, 3:12 a.m. March 28, 2025, 12:56 p.m.
sensitive_file 26
Request paths/parameters resemble attempts to access files outside intended directories.
hits 449 pts 3131.61
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
28 139 1 930.97 June 5, 2024, 9:33 a.m. Oct. 2, 2025, 8:14 a.m.
trav 139
26 139 1 845.68 June 5, 2024, 9:33 a.m. Oct. 2, 2025, 8:14 a.m.
trav 139
34 98 1 823.00 May 28, 2024, 2:03 a.m. April 3, 2025, 11:52 a.m.
trav 98
30 73 1 531.96 June 6, 2024, 1:02 p.m. Sept. 28, 2025, 6:13 a.m.
trav 73
Scan velocity scan_velocity
High request rate and broad endpoint coverage suggest scanning or automated enumeration.
hits 1098 pts 2019.01
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
36 58 1 319.46 March 14, 2025, 11:51 p.m. March 15, 2025, midnight
scan_velocity 58
20 82 1 254.16 Aug. 6, 2023, 3:24 p.m. May 11, 2025, 1:23 a.m.
scan_velocity 82
10 189 1 242.46 Aug. 4, 2023, 12:44 a.m. April 3, 2025, 11:56 a.m.
scan_velocity 189
22 62 1 207.90 Aug. 6, 2023, 3:24 p.m. May 11, 2025, 1:23 a.m.
scan_velocity 62
32 43 1 179.42 June 5, 2024, 9:49 p.m. March 27, 2025, 8:34 a.m.
scan_velocity 43
24 52 1 166.97 May 29, 2024, 6:18 a.m. March 27, 2025, 8:52 p.m.
scan_velocity 52
18 58 1 156.98 Aug. 6, 2023, 3:24 p.m. March 27, 2025, 8:45 p.m.
scan_velocity 58
16 41 1 95.18 Sept. 6, 2023, 1 a.m. March 27, 2025, 8:45 p.m.
scan_velocity 41
12 51 1 86.29 Aug. 26, 2023, 11:26 p.m. March 27, 2025, 8:45 p.m.
scan_velocity 51
34 13 1 67.63 March 14, 2025, 11:51 p.m. March 14, 2025, 11:59 p.m.
scan_velocity 13
30 17 1 66.69 May 29, 2024, 6:18 a.m. March 27, 2025, 8:33 a.m.
scan_velocity 17
28 17 1 62.24 May 29, 2024, 6:18 a.m. March 27, 2025, 8:33 a.m.
scan_velocity 17
26 17 1 57.80 May 29, 2024, 6:18 a.m. March 27, 2025, 8:33 a.m.
scan_velocity 17
14 29 1 55.82 Aug. 20, 2023, 1:56 p.m. March 27, 2025, 8:45 p.m.
scan_velocity 29
0 369 1 0.00 Aug. 4, 2023, 12:44 a.m. May 11, 2025, 1:23 a.m.
scan_velocity 369
Repeated authentication attempts consistent with password guessing or credential stuffing.
hits 791 pts 1841.62
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 409 1 1590.38 Aug. 4, 2023, 12:44 a.m. Dec. 1, 2025, 7:33 p.m.
cred 409
8 39 1 117.26 Oct. 20, 2023, 7:18 a.m. Dec. 1, 2025, 7:33 p.m.
cred 39
12 14 1 74.58 Oct. 20, 2023, 7:18 a.m. April 18, 2024, 5:44 a.m.
cred 14
6 30 1 59.40 Oct. 20, 2023, 7:18 a.m. Nov. 1, 2024, 12:13 a.m.
cred 30
0 299 1 0.00 Aug. 4, 2023, 12:44 a.m. Dec. 1, 2025, 7:33 p.m.
cred 299
Requests are unusually large or shaped in a way that suggests abuse or automation.
hits 909 pts 529.16
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
14 899 1 528.26 Nov. 23, 2025, 9:31 p.m. Jan. 25, 2026, 1:49 a.m.
request_size 899
20 1 1 0.90 Jan. 20, 2026, 12:25 a.m. Jan. 20, 2026, 12:25 a.m.
request_size 1
0 9 1 0.00 Oct. 28, 2025, 12:45 p.m. Dec. 14, 2025, 9:28 p.m.
request_size 9
Request content resembles attempts to execute OS commands via an application.
hits 29 pts 512.52
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
28 14 1 293.22 June 6, 2024, 1:04 p.m. March 27, 2025, 12:50 p.m.
cmdi 14
22 14 1 196.35 June 6, 2024, 1:04 p.m. March 27, 2025, 12:50 p.m.
cmdi 14
30 1 1 22.95 March 4, 2025, 7:52 a.m. March 4, 2025, 7:52 a.m.
cmdi 1
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
hits 3140 pts 428.31
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 2391 1 344.30 Aug. 10, 2023, 4:49 p.m. Oct. 19, 2025, 8:38 a.m.
ua 2391
8 446 1 46.38 July 15, 2023, 12:49 a.m. Nov. 29, 2025, 7:55 a.m.
ua 446
14 104 1 23.30 July 6, 2023, 8:05 p.m. March 6, 2025, 10:14 a.m.
ua 104
6 199 1 14.33 Sept. 26, 2023, 10:45 p.m. Dec. 31, 2025, 2:30 p.m.
ua 199
Traffic patterns strongly suggest automation rather than a human-operated browser.
hits 368 pts 174.80
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 368 1 174.80 Feb. 22, 2024, 9:52 p.m. Jan. 25, 2026, 1:06 a.m.
bot 368
Request structure or protocol-level signals deviate from typical browser HTTP traffic.
hits 105 pts 59.69
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
12 43 1 29.72 June 6, 2024, 1:02 p.m. Sept. 28, 2025, 6:11 a.m.
proto 43
11 45 1 27.72 Feb. 11, 2024, 3:27 p.m. Feb. 11, 2024, 3:28 p.m.
proto 45
3 17 1 2.24 June 6, 2024, 1:02 p.m. Sept. 28, 2025, 12:25 a.m.
proto 17
Traffic behavior suggests probing of access controls and protected surfaces.
hits 5 pts 44.10
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
22 4 1 31.68 March 4, 2025, 7:49 a.m. March 28, 2025, 12:48 p.m.
fwprobe 4
30 1 1 12.42 Feb. 23, 2025, 1:56 a.m. Feb. 23, 2025, 1:56 a.m.
fwprobe 1
Unusual or unexpected HTTP methods observed for the target endpoints.
hits 31 pts 16.68
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 28 1 15.46 July 15, 2023, 12:49 a.m. Sept. 10, 2025, 3:12 a.m.
method 28
8 3 1 1.22 March 31, 2025, 12:15 p.m. Oct. 28, 2025, 2:30 a.m.
method 3
Referrer patterns look manipulated, irrelevant, or inconsistent with normal navigation.
hits 112 pts 14.11
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
6 112 1 14.11 Aug. 5, 2023, 6:21 p.m. Dec. 1, 2025, 7:33 p.m.
ref 112

HTTP Status Breakdown

Response mix grouped by status class (2xx/3xx/4xx/5xx). Auto-loads a single aggregation and renders a donut.

Loading status mix…
Running one aggregation and rendering the chart.

Geolocation

Live geolocation and map tiles auto-load for this ASN snapshot (peer IPs with coordinates).

Loading map…

SUBNETS HELD BY THIS ISP

Derived from ISP snapshot peers (Option A). Grouped into IPv4 /24 and IPv6 /48 by default.
IPv4
IPv6
Limit
Loading subnets…

Interesting IPs

Top risky peers inside this ASN (latest snapshot). Sorted by risk score, then hits.

No peer rows available for this ASN snapshot.