DigitalOcean Referral Badge
cloud1
cloud2
cloud3
cloud4
cloud5
cloud6
← Back

ASN REPORT — AS20001 · Charter Communications Inc

First sighted: July 11, 2023, 3 a.m. · Last sighted: Jan. 11, 2026, 1:59 a.m.

Risk
26 (low)
Total hits
45259
Total errors
1573
Observed IPs
999
Top country
N/A
Top city
N/A

Risk

Model: v1 Computed: 2026-01-18 11:55:14
Risk score
26
Low
Risk gradient
Key drivers are enriched against the published annotator catalog when available; otherwise sensible defaults are used.
Key drivers
Scan velocity
High request rate and broad endpoint coverage suggest scanning or automated enumeration.
scan_velocity
Hits 540
Points 341.93
Request size anomaly
Requests are unusually large or shaped in a way that suggests abuse or automation.
request_size
Hits 668
Points 109.06
User-Agent anomaly
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
ua
Hits 1271
Points 94.84
Path traversal attempts
Request paths/parameters resemble attempts to access files outside intended directories.
trav
Hits 12
Points 80.30
Sensitive file probing
Requests target commonly sensitive files, configs, backups, or administrative resources.
sfp
Hits 6
Points 41.92
Command injection attempts
Request content resembles attempts to execute OS commands via an application.
cmdi
Hits 2
Points 41.89
Automated client behavior
Traffic patterns strongly suggest automation rather than a human-operated browser.
bot
Hits 37
Points 17.58
Credential brute forcing
Repeated authentication attempts consistent with password guessing or credential stuffing.
cred
Hits 6
Points 13.86
Protocol anomaly
Request structure or protocol-level signals deviate from typical browser HTTP traffic.
proto
Hits 3
Points 1.51
Referrer abuse
Referrer patterns look manipulated, irrelevant, or inconsistent with normal navigation.
ref
Hits 1
Points 0.13

Traffic

Rollup

Daily activity (hits per day) and basic HTTP rollup counters for this ASN.

Loading activity…
Daily activity (hits per day). Total in window: .
Traffic rollup
HTTP status classes, URL diversity, and totals.
2xx
5525
3xx
29655
4xx
297
5xx
1276
Unique URLs
2987
Total hits
45259
First seen
July 11, 2023, 3 a.m.
Last seen
Jan. 11, 2026, 1:59 a.m.

Annotators (All-time)

Heatmap of annotator × severity. Darker cells mean more volume in that band. Tip: switch to Weighted points to see what drives impact (not just noise).

Severity →
Low High
Scan velocity scan_velocity
High request rate and broad endpoint coverage suggest scanning or automated enumeration.
hits 540 pts 341.93
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 267 1 336.42 Feb. 25, 2024, 12:01 a.m. Sept. 23, 2025, 9:34 p.m.
scan_velocity 267
12 3 1 5.51 Feb. 11, 2024, 7:44 p.m. Feb. 11, 2024, 7:52 p.m.
scan_velocity 3
0 270 1 0.00 Feb. 11, 2024, 7:44 p.m. Sept. 23, 2025, 9:34 p.m.
scan_velocity 270
Requests are unusually large or shaped in a way that suggests abuse or automation.
hits 668 pts 109.06
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
12 228 1 106.70 July 24, 2023, 11:01 a.m. Aug. 1, 2025, 4:28 a.m.
request_size 228
14 4 1 2.35 July 26, 2025, 7:58 p.m. Dec. 14, 2025, 9:57 p.m.
request_size 4
0 436 1 0.00 Dec. 28, 2024, 10:48 p.m. Jan. 10, 2026, 12:57 a.m.
request_size 436
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
hits 1271 pts 94.84
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
6 1242 1 89.42 July 17, 2023, 12:25 a.m. Oct. 20, 2025, 1:09 a.m.
ua 1242
14 19 1 4.26 Feb. 11, 2024, 7:44 p.m. April 25, 2025, 7:08 a.m.
ua 19
8 7 1 0.73 Jan. 25, 2024, 10:06 a.m. March 22, 2025, 8:14 a.m.
ua 7
10 3 1 0.43 July 15, 2025, 8:42 a.m. Aug. 20, 2025, 9:31 a.m.
ua 3
Request paths/parameters resemble attempts to access files outside intended directories.
hits 12 pts 80.30
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
30 4 1 29.17 Nov. 12, 2024, 7:36 a.m. Nov. 12, 2024, 7:37 a.m.
trav 4
28 4 1 26.79 Nov. 12, 2024, 7:36 a.m. Nov. 12, 2024, 7:36 a.m.
trav 4
26 4 1 24.34 Nov. 12, 2024, 7:36 a.m. Nov. 12, 2024, 7:36 a.m.
trav 4
Requests target commonly sensitive files, configs, backups, or administrative resources.
hits 6 pts 41.92
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
34 4 1 25.73 Nov. 12, 2024, 7:36 a.m. Nov. 12, 2024, 7:36 a.m.
sensitive_file 4
40 2 1 16.19 July 15, 2025, 8:42 a.m. July 15, 2025, 8:42 a.m.
sensitive_file 2
Request content resembles attempts to execute OS commands via an application.
hits 2 pts 41.89
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
28 2 1 41.89 July 17, 2023, 12:25 a.m. Jan. 20, 2024, 8:31 p.m.
cmdi 2
Traffic patterns strongly suggest automation rather than a human-operated browser.
hits 37 pts 17.58
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 37 1 17.58 Feb. 8, 2025, 8:24 a.m. May 23, 2025, 1:10 p.m.
bot 37
Repeated authentication attempts consistent with password guessing or credential stuffing.
hits 6 pts 13.86
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 2 1 7.70 Dec. 26, 2023, 9:34 a.m. May 8, 2024, 6:50 p.m.
cred 2
8 2 1 6.16 Dec. 26, 2023, 9:34 a.m. May 8, 2024, 6:50 p.m.
cred 2
0 2 1 0.00 Dec. 26, 2023, 9:34 a.m. May 8, 2024, 6:50 p.m.
cred 2
Request structure or protocol-level signals deviate from typical browser HTTP traffic.
hits 3 pts 1.51
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
12 2 1 1.38 Nov. 12, 2024, 7:36 a.m. Nov. 12, 2024, 7:36 a.m.
proto 2
3 1 1 0.13 Nov. 12, 2024, 7:36 a.m. Nov. 12, 2024, 7:36 a.m.
proto 1
Referrer patterns look manipulated, irrelevant, or inconsistent with normal navigation.
hits 1 pts 0.13
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
6 1 1 0.13 Dec. 26, 2023, 9:34 a.m. Dec. 26, 2023, 9:34 a.m.
ref 1

HTTP Status Breakdown

Response mix grouped by status class (2xx/3xx/4xx/5xx). Auto-loads a single aggregation and renders a donut.

Loading status mix…
Running one aggregation and rendering the chart.

Geolocation

Live geolocation and map tiles auto-load for this ASN snapshot (peer IPs with coordinates).

Loading map…

SUBNETS HELD BY THIS ISP

Derived from ISP snapshot peers (Option A). Grouped into IPv4 /24 and IPv6 /48 by default.
IPv4
IPv6
Limit
Loading subnets…

Interesting IPs

Top risky peers inside this ASN (latest snapshot). Sorted by risk score, then hits.

No peer rows available for this ASN snapshot.