DigitalOcean Referral Badge
cloud1
cloud2
cloud3
cloud4
cloud5
cloud6
← Back

ASN REPORT — AS17621 · China Unicom Shanghai network

First sighted: May 16, 2023, 3 a.m. · Last sighted: Jan. 10, 2026, 1:59 a.m.

Risk
1 (low)
Total hits
948
Total errors
154
Observed IPs
349
Top country
N/A
Top city
N/A

Risk

Model: v1 Computed: 2026-01-18 11:55:25
Risk score
1
Low
Risk gradient
Key drivers are enriched against the published annotator catalog when available; otherwise sensible defaults are used.
Key drivers
Sensitive file probing
Requests target commonly sensitive files, configs, backups, or administrative resources.
sfp
Hits 2
Points 12.87
User-Agent anomaly
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
ua
Hits 97
Points 9.11
HTTP method anomaly
Unusual or unexpected HTTP methods observed for the target endpoints.
method
Hits 4
Points 2.21
Request size anomaly
Requests are unusually large or shaped in a way that suggests abuse or automation.
request_size
Hits 2
Points 1.18

Traffic

Rollup

Daily activity (hits per day) and basic HTTP rollup counters for this ASN.

Loading activity…
Daily activity (hits per day). Total in window: .
Traffic rollup
HTTP status classes, URL diversity, and totals.
2xx
524
3xx
182
4xx
153
5xx
1
Unique URLs
532
Total hits
948
First seen
May 16, 2023, 3 a.m.
Last seen
Jan. 10, 2026, 1:59 a.m.

Annotators (All-time)

Heatmap of annotator × severity. Darker cells mean more volume in that band. Tip: switch to Weighted points to see what drives impact (not just noise).

Severity →
Low High
Requests target commonly sensitive files, configs, backups, or administrative resources.
hits 2 pts 12.87
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
34 2 1 12.87 July 24, 2025, 5:31 a.m. July 24, 2025, 5:31 a.m.
sensitive_file 2
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
hits 97 pts 9.11
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
8 53 1 5.51 Aug. 8, 2023, 2:16 a.m. Oct. 2, 2025, 4:31 p.m.
ua 53
6 38 1 2.74 May 17, 2023, 12:29 a.m. July 22, 2025, 10:26 a.m.
ua 38
10 6 1 0.86 Dec. 24, 2024, 12:22 a.m. March 1, 2025, 2:02 p.m.
ua 6
Unusual or unexpected HTTP methods observed for the target endpoints.
hits 4 pts 2.21
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 4 1 2.21 July 24, 2025, 5:31 a.m. Oct. 2, 2025, 4:31 p.m.
method 4
Requests are unusually large or shaped in a way that suggests abuse or automation.
hits 2 pts 1.18
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
14 2 1 1.18 July 21, 2025, 11:07 a.m. July 22, 2025, 10:26 a.m.
request_size 2

HTTP Status Breakdown

Response mix grouped by status class (2xx/3xx/4xx/5xx). Auto-loads a single aggregation and renders a donut.

Loading status mix…
Running one aggregation and rendering the chart.

Geolocation

Live geolocation and map tiles auto-load for this ASN snapshot (peer IPs with coordinates).

Loading map…

SUBNETS HELD BY THIS ISP

Derived from ISP snapshot peers (Option A). Grouped into IPv4 /24 and IPv6 /48 by default.
IPv4
IPv6
Limit
Loading subnets…

Interesting IPs

Top risky peers inside this ASN (latest snapshot). Sorted by risk score, then hits.

No peer rows available for this ASN snapshot.