DigitalOcean Referral Badge
cloud1
cloud2
cloud3
cloud4
cloud5
cloud6
← Back

ASN REPORT — AS136958 · China Unicom Guangdong IP network

First sighted: May 16, 2023, 3 a.m. · Last sighted: Oct. 9, 2025, 2:59 a.m.

Risk
23 (low)
Total hits
845
Total errors
303
Observed IPs
147
Top country
N/A
Top city
N/A

Risk

Model: v1 Computed: 2026-01-18 11:55:25
Risk score
23
Low
Risk gradient
Key drivers are enriched against the published annotator catalog when available; otherwise sensible defaults are used.
Key drivers
Sensitive file probing
Requests target commonly sensitive files, configs, backups, or administrative resources.
sfp
Hits 62
Points 302.09
Path traversal attempts
Request paths/parameters resemble attempts to access files outside intended directories.
trav
Hits 45
Points 299.20
User-Agent anomaly
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
ua
Hits 155
Points 19.99
Scan velocity
High request rate and broad endpoint coverage suggest scanning or automated enumeration.
scan_velocity
Hits 6
Points 11.02
Protocol anomaly
Request structure or protocol-level signals deviate from typical browser HTTP traffic.
proto
Hits 12
Points 6.06
HTTP method anomaly
Unusual or unexpected HTTP methods observed for the target endpoints.
method
Hits 2
Points 0.96

Traffic

Rollup

Daily activity (hits per day) and basic HTTP rollup counters for this ASN.

Loading activity…
Daily activity (hits per day). Total in window: .
Traffic rollup
HTTP status classes, URL diversity, and totals.
2xx
234
3xx
223
4xx
302
5xx
1
Unique URLs
270
Total hits
845
First seen
May 16, 2023, 3 a.m.
Last seen
Oct. 9, 2025, 2:59 a.m.

Annotators (All-time)

Heatmap of annotator × severity. Darker cells mean more volume in that band. Tip: switch to Weighted points to see what drives impact (not just noise).

Severity →
Low High
Requests target commonly sensitive files, configs, backups, or administrative resources.
hits 62 pts 302.09
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
24 46 1 199.16 Oct. 17, 2023, 8:35 p.m. June 14, 2024, 1:53 p.m.
sensitive_file 46
34 16 1 102.92 Sept. 20, 2024, 4:18 p.m. July 19, 2025, 4:59 p.m.
sensitive_file 16
Request paths/parameters resemble attempts to access files outside intended directories.
hits 45 pts 299.20
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
28 16 1 107.16 Sept. 20, 2024, 4:18 p.m. July 19, 2025, 4:59 p.m.
trav 16
26 16 1 97.34 Sept. 20, 2024, 4:18 p.m. July 19, 2025, 4:59 p.m.
trav 16
30 13 1 94.69 Sept. 20, 2024, 4:18 p.m. July 19, 2025, 4:59 p.m.
trav 13
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
hits 155 pts 19.99
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 116 1 16.70 Oct. 17, 2023, 8:35 p.m. Aug. 10, 2025, 8:09 a.m.
ua 116
6 24 1 1.73 May 16, 2023, 4:20 a.m. July 19, 2025, 4:59 p.m.
ua 24
8 15 1 1.56 Dec. 2, 2023, 12:18 a.m. July 19, 2025, 4:59 p.m.
ua 15
Scan velocity scan_velocity
High request rate and broad endpoint coverage suggest scanning or automated enumeration.
hits 6 pts 11.02
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
18 2 1 5.83 Sept. 28, 2024, 6:40 p.m. Sept. 28, 2024, 6:40 p.m.
scan_velocity 2
16 2 1 5.18 Sept. 28, 2024, 6:40 p.m. Sept. 28, 2024, 6:40 p.m.
scan_velocity 2
0 2 1 0.00 Sept. 28, 2024, 6:40 p.m. Sept. 28, 2024, 6:40 p.m.
scan_velocity 2
Request structure or protocol-level signals deviate from typical browser HTTP traffic.
hits 12 pts 6.06
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
12 8 1 5.53 Sept. 20, 2024, 4:18 p.m. July 19, 2025, 4:59 p.m.
proto 8
3 4 1 0.53 Sept. 20, 2024, 4:18 p.m. July 19, 2025, 4:59 p.m.
proto 4
Unusual or unexpected HTTP methods observed for the target endpoints.
hits 2 pts 0.96
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 1 1 0.55 Jan. 12, 2024, 10:42 a.m. Jan. 12, 2024, 10:42 a.m.
method 1
8 1 1 0.41 May 19, 2023, 2:47 a.m. May 19, 2023, 2:47 a.m.
method 1

HTTP Status Breakdown

Response mix grouped by status class (2xx/3xx/4xx/5xx). Auto-loads a single aggregation and renders a donut.

Loading status mix…
Running one aggregation and rendering the chart.

Geolocation

Live geolocation and map tiles auto-load for this ASN snapshot (peer IPs with coordinates).

Loading map…

SUBNETS HELD BY THIS ISP

Derived from ISP snapshot peers (Option A). Grouped into IPv4 /24 and IPv6 /48 by default.
IPv4
IPv6
Limit
Loading subnets…

Interesting IPs

Top risky peers inside this ASN (latest snapshot). Sorted by risk score, then hits.

No peer rows available for this ASN snapshot.