DigitalOcean Referral Badge
cloud1
cloud2
cloud3
cloud4
cloud5
cloud6
← Back

ASN REPORT — AS153656 · OWGELS INTERNATIONAL CO., LIMITED

First sighted: April 9, 2025, 3 a.m. · Last sighted: Nov. 26, 2025, 1:59 a.m.

Risk
9 (low)
Total hits
177
Total errors
105
Observed IPs
32
Top country
N/A
Top city
N/A

Risk

Model: v1 Computed: 2026-01-18 11:53:14
Risk score
9
Low
Risk gradient
Key drivers are enriched against the published annotator catalog when available; otherwise sensible defaults are used.
Key drivers
Path traversal attempts
Request paths/parameters resemble attempts to access files outside intended directories.
trav
Hits 15
Points 98.61
Sensitive file probing
Requests target commonly sensitive files, configs, backups, or administrative resources.
sfp
Hits 6
Points 38.60
Command injection attempts
Request content resembles attempts to execute OS commands via an application.
cmdi
Hits 2
Points 34.97
Scan velocity
High request rate and broad endpoint coverage suggest scanning or automated enumeration.
scan_velocity
Hits 14
Points 32.72
Credential brute forcing
Repeated authentication attempts consistent with password guessing or credential stuffing.
cred
Hits 7
Points 20.57
User-Agent anomaly
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
ua
Hits 10
Points 0.78
Protocol anomaly
Request structure or protocol-level signals deviate from typical browser HTTP traffic.
proto
Hits 1
Points 0.69

Traffic

Rollup

Daily activity (hits per day) and basic HTTP rollup counters for this ASN.

Loading activity…
Daily activity (hits per day). Total in window: .
Traffic rollup
HTTP status classes, URL diversity, and totals.
2xx
1
3xx
55
4xx
103
5xx
2
Unique URLs
83
Total hits
177
First seen
April 9, 2025, 3 a.m.
Last seen
Nov. 26, 2025, 1:59 a.m.

Annotators (All-time)

Heatmap of annotator × severity. Darker cells mean more volume in that band. Tip: switch to Weighted points to see what drives impact (not just noise).

Severity →
Low High
Request paths/parameters resemble attempts to access files outside intended directories.
hits 15 pts 98.61
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
28 6 1 40.19 April 9, 2025, 10:06 p.m. Nov. 25, 2025, 11:47 a.m.
trav 6
26 6 1 36.50 April 9, 2025, 10:06 p.m. Nov. 25, 2025, 11:47 a.m.
trav 6
30 3 1 21.92 April 9, 2025, 10:06 p.m. April 9, 2025, 10:07 p.m.
trav 3
Requests target commonly sensitive files, configs, backups, or administrative resources.
hits 6 pts 38.60
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
34 6 1 38.60 April 9, 2025, 10:06 p.m. Nov. 25, 2025, 11:47 a.m.
sensitive_file 6
Request content resembles attempts to execute OS commands via an application.
hits 2 pts 34.97
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
28 1 1 20.94 April 9, 2025, 10:08 p.m. April 9, 2025, 10:08 p.m.
cmdi 1
22 1 1 14.02 April 9, 2025, 10:08 p.m. April 9, 2025, 10:08 p.m.
cmdi 1
Scan velocity scan_velocity
High request rate and broad endpoint coverage suggest scanning or automated enumeration.
hits 14 pts 32.72
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
20 5 1 16.20 April 9, 2025, 10:07 p.m. April 9, 2025, 10:08 p.m.
scan_velocity 5
22 3 1 10.69 April 9, 2025, 10:08 p.m. April 9, 2025, 10:08 p.m.
scan_velocity 3
18 2 1 5.83 April 9, 2025, 10:07 p.m. April 9, 2025, 10:07 p.m.
scan_velocity 2
0 4 1 0.00 April 9, 2025, 10:07 p.m. April 9, 2025, 10:08 p.m.
scan_velocity 4
Repeated authentication attempts consistent with password guessing or credential stuffing.
hits 7 pts 20.57
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 4 1 15.62 Aug. 21, 2025, 1:52 p.m. Sept. 15, 2025, 11:46 p.m.
cred 4
12 1 1 4.95 Aug. 21, 2025, 1:52 p.m. Aug. 21, 2025, 1:52 p.m.
cred 1
0 2 1 0.00 Aug. 21, 2025, 1:52 p.m. Sept. 15, 2025, 11:46 p.m.
cred 2
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
hits 10 pts 0.78
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
6 8 1 0.58 April 9, 2025, 10:07 p.m. Sept. 10, 2025, 11:59 p.m.
ua 8
8 2 1 0.21 April 9, 2025, 10:06 p.m. April 9, 2025, 10:06 p.m.
ua 2
Request structure or protocol-level signals deviate from typical browser HTTP traffic.
hits 1 pts 0.69
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
12 1 1 0.69 April 9, 2025, 10:06 p.m. April 9, 2025, 10:06 p.m.
proto 1

HTTP Status Breakdown

Response mix grouped by status class (2xx/3xx/4xx/5xx). Auto-loads a single aggregation and renders a donut.

Loading status mix…
Running one aggregation and rendering the chart.

Geolocation

Live geolocation and map tiles auto-load for this ASN snapshot (peer IPs with coordinates).

Loading map…

SUBNETS HELD BY THIS ISP

Derived from ISP snapshot peers (Option A). Grouped into IPv4 /24 and IPv6 /48 by default.
IPv4
IPv6
Limit
Loading subnets…

Interesting IPs

Top risky peers inside this ASN (latest snapshot). Sorted by risk score, then hits.

No peer rows available for this ASN snapshot.