DigitalOcean Referral Badge
cloud1
cloud2
cloud3
cloud4
cloud5
cloud6
← Back

ASN REPORT — AS20473 · The Constant Company, LLC

First sighted: May 16, 2023, 3 a.m. · Last sighted: Jan. 11, 2026, 1:59 a.m.

Risk
100 (high)
Total hits
19779
Total errors
6511
Observed IPs
2208
Top country
N/A
Top city
N/A

Risk

Model: v1 Computed: 2026-01-18 11:55:25
Risk score
100
High
Risk gradient
Key drivers are enriched against the published annotator catalog when available; otherwise sensible defaults are used.
Key drivers
Sensitive file probing
Requests target commonly sensitive files, configs, backups, or administrative resources.
sfp
Hits 1847
Points 14236.55
Path traversal attempts
Request paths/parameters resemble attempts to access files outside intended directories.
trav
Hits 385
Points 2584.20
Command injection attempts
Request content resembles attempts to execute OS commands via an application.
cmdi
Hits 54
Points 1073.04
Scan velocity
High request rate and broad endpoint coverage suggest scanning or automated enumeration.
scan_velocity
Hits 391
Points 819.22
User-Agent anomaly
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
ua
Hits 2391
Points 364.16
Credential brute forcing
Repeated authentication attempts consistent with password guessing or credential stuffing.
cred
Hits 112
Points 286.49
SQL injection attempts
Input patterns resemble attempts to manipulate SQL queries via application parameters.
sqli
Hits 14
Points 249.76
Header injection attempts
Input patterns suggest attempts to manipulate headers or downstream header parsing.
hdrinj
Hits 10
Points 179.90
HTTP method anomaly
Unusual or unexpected HTTP methods observed for the target endpoints.
method
Hits 556
Points 169.77
Automated client behavior
Traffic patterns strongly suggest automation rather than a human-operated browser.
bot
Hits 376
Points 145.06

Traffic

Rollup

Daily activity (hits per day) and basic HTTP rollup counters for this ASN.

Loading activity…
Daily activity (hits per day). Total in window: .
Traffic rollup
HTTP status classes, URL diversity, and totals.
2xx
2995
3xx
9844
4xx
6497
5xx
14
Unique URLs
4892
Total hits
19779
First seen
May 16, 2023, 3 a.m.
Last seen
Jan. 11, 2026, 1:59 a.m.

Annotators (All-time)

Heatmap of annotator × severity. Darker cells mean more volume in that band. Tip: switch to Weighted points to see what drives impact (not just noise).

Severity →
Low High
Requests target commonly sensitive files, configs, backups, or administrative resources.
hits 1847 pts 14236.55
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
40 1409 1 11407.26 Aug. 28, 2023, 6:06 p.m. Aug. 17, 2025, 9:35 p.m.
sensitive_file 1409
44 139 1 1264.79 Oct. 15, 2023, 2:56 a.m. Oct. 3, 2024, 9:46 p.m.
sensitive_file 139
34 159 1 1022.82 Oct. 15, 2023, 2:56 a.m. Nov. 6, 2025, 7:26 p.m.
sensitive_file 159
36 40 1 277.04 Oct. 15, 2023, 2:56 a.m. Sept. 30, 2025, 4:35 p.m.
sensitive_file 40
16 56 1 137.98 Oct. 24, 2023, 6:27 p.m. Sept. 7, 2024, 5:50 a.m.
sensitive_file 56
24 17 1 73.60 July 26, 2023, 11:13 p.m. June 3, 2024, 8:01 a.m.
sensitive_file 17
8 20 1 21.12 Oct. 15, 2023, 2:56 a.m. Oct. 16, 2023, 8:46 p.m.
sensitive_file 20
30 3 1 16.83 Oct. 24, 2023, 6:29 p.m. Oct. 25, 2023, 1:08 p.m.
sensitive_file 3
22 4 1 15.10 Oct. 24, 2023, 6:28 p.m. Sept. 7, 2024, 3:59 a.m.
sensitive_file 4
Request paths/parameters resemble attempts to access files outside intended directories.
hits 385 pts 2584.20
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
28 150 1 1004.64 Oct. 15, 2023, 2:56 a.m. Nov. 6, 2025, 7:26 p.m.
trav 150
26 157 1 955.19 Oct. 15, 2023, 2:56 a.m. Nov. 6, 2025, 7:26 p.m.
trav 157
34 44 1 369.51 Oct. 15, 2023, 2:56 a.m. Oct. 3, 2024, 9:46 p.m.
trav 44
30 21 1 153.19 Oct. 15, 2023, 9:53 a.m. Nov. 6, 2025, 7:25 p.m.
trav 21
32 13 1 101.67 Oct. 15, 2023, 9:56 a.m. Oct. 3, 2024, 9:46 p.m.
trav 13
Request content resembles attempts to execute OS commands via an application.
hits 54 pts 1073.04
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
28 30 1 628.32 Oct. 15, 2023, 4:51 p.m. Nov. 6, 2025, 7:26 p.m.
cmdi 30
30 12 1 276.42 Oct. 15, 2023, 4:47 p.m. Oct. 3, 2024, 7:27 p.m.
cmdi 12
22 12 1 168.30 Oct. 15, 2023, 11:26 p.m. Nov. 6, 2025, 7:26 p.m.
cmdi 12
Scan velocity scan_velocity
High request rate and broad endpoint coverage suggest scanning or automated enumeration.
hits 391 pts 819.22
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
22 48 1 164.93 Oct. 15, 2023, 2:56 a.m. Nov. 6, 2025, 7:26 p.m.
scan_velocity 48
36 17 1 96.23 Oct. 25, 2023, 4:39 a.m. Oct. 25, 2023, 4:41 a.m.
scan_velocity 17
26 25 1 96.17 Oct. 24, 2023, 6:28 p.m. Jan. 28, 2024, 1:35 a.m.
scan_velocity 25
32 18 1 77.18 Oct. 24, 2023, 6:28 p.m. Oct. 25, 2023, 1:09 p.m.
scan_velocity 18
24 18 1 62.86 Oct. 24, 2023, 6:28 p.m. Jan. 28, 2024, 1:35 a.m.
scan_velocity 18
10 44 1 55.62 Sept. 26, 2023, 5:06 p.m. Sept. 7, 2024, 5:50 a.m.
scan_velocity 44
20 17 1 50.22 Oct. 15, 2023, 2:56 a.m. Nov. 6, 2025, 7:25 p.m.
scan_velocity 17
18 17 1 45.20 Oct. 24, 2023, 6:28 p.m. Nov. 6, 2025, 7:25 p.m.
scan_velocity 17
30 10 1 42.12 Oct. 24, 2023, 6:28 p.m. Oct. 25, 2023, 1:08 p.m.
scan_velocity 10
16 17 1 40.18 Oct. 24, 2023, 6:28 p.m. Nov. 6, 2025, 7:25 p.m.
scan_velocity 17
28 10 1 39.31 Oct. 24, 2023, 6:28 p.m. Oct. 25, 2023, 1:08 p.m.
scan_velocity 10
12 16 1 27.65 Oct. 24, 2023, 6:28 p.m. Oct. 3, 2024, 9:31 p.m.
scan_velocity 16
14 11 1 21.55 Oct. 24, 2023, 6:28 p.m. Oct. 3, 2024, 9:31 p.m.
scan_velocity 11
0 123 1 0.00 Sept. 26, 2023, 5:06 p.m. Nov. 6, 2025, 7:26 p.m.
scan_velocity 123
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
hits 2391 pts 364.16
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
14 766 1 171.58 May 4, 2025, 6:31 p.m. May 17, 2025, 2:42 p.m.
ua 766
8 1045 1 108.70 July 25, 2023, 2:16 p.m. Nov. 6, 2025, 7:25 p.m.
ua 1045
12 220 1 41.18 Dec. 25, 2023, 5:39 p.m. Aug. 28, 2025, 9:01 a.m.
ua 220
10 233 1 33.55 July 25, 2023, 7:22 a.m. May 6, 2025, 6:34 p.m.
ua 233
6 127 1 9.14 May 16, 2023, 4:43 a.m. Nov. 23, 2025, 12:33 a.m.
ua 127
Repeated authentication attempts consistent with password guessing or credential stuffing.
hits 112 pts 286.49
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 55 1 213.40 July 12, 2023, 8:31 a.m. May 20, 2025, 3:29 p.m.
cred 55
12 10 1 49.50 July 12, 2023, 8:31 a.m. May 20, 2025, 3:29 p.m.
cred 10
14 3 1 19.64 Oct. 25, 2023, 4:40 a.m. Oct. 3, 2024, 11:12 p.m.
cred 3
6 2 1 3.96 Oct. 15, 2023, 4:41 p.m. Oct. 15, 2023, 4:41 p.m.
cred 2
0 42 1 0.00 July 12, 2023, 8:31 a.m. May 20, 2025, 3:29 p.m.
cred 42
Input patterns resemble attempts to manipulate SQL queries via application parameters.
hits 14 pts 249.76
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
32 4 1 117.76 Oct. 15, 2023, 9:59 a.m. Oct. 3, 2024, 9:07 p.m.
sqli 4
18 5 1 64.80 Oct. 15, 2023, 9:59 a.m. May 16, 2025, 10:13 p.m.
sqli 5
30 2 1 54.00 Oct. 15, 2023, 4:39 p.m. Oct. 3, 2024, 7:27 p.m.
sqli 2
8 3 1 13.20 Oct. 15, 2023, 7:53 p.m. Oct. 3, 2024, 9:07 p.m.
sqli 3
Input patterns suggest attempts to manipulate headers or downstream header parsing.
hits 10 pts 179.90
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
24 8 1 138.24 Oct. 16, 2023, 6:22 a.m. Oct. 3, 2024, 9:31 p.m.
hdrinj 8
28 2 1 41.66 Nov. 7, 2023, 11:13 p.m. Nov. 7, 2023, 11:13 p.m.
hdrinj 2
Unusual or unexpected HTTP methods observed for the target endpoints.
hits 556 pts 169.77
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
6 496 1 146.42 April 4, 2025, 12:26 a.m. April 27, 2025, 9:28 a.m.
method 496
8 56 1 22.85 May 18, 2023, 11:10 p.m. Oct. 22, 2025, 8:28 p.m.
method 56
3 4 1 0.50 May 16, 2023, 4:43 a.m. May 16, 2023, 5:37 a.m.
method 4
Traffic patterns strongly suggest automation rather than a human-operated browser.
hits 376 pts 145.06
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 220 1 104.50 Dec. 25, 2023, 5:39 p.m. Aug. 28, 2025, 9:01 a.m.
bot 220
8 156 1 40.56 April 26, 2025, 12:45 a.m. Nov. 23, 2025, 2:39 a.m.
bot 156
Request structure or protocol-level signals deviate from typical browser HTTP traffic.
hits 102 pts 116.60
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
24 49 1 86.55 Oct. 15, 2023, 2:56 a.m. Nov. 7, 2023, 11:12 p.m.
proto 49
11 43 1 26.49 July 25, 2023, 7:22 a.m. Oct. 22, 2025, 8:28 p.m.
proto 43
12 4 1 2.76 Oct. 8, 2024, 1:48 a.m. Nov. 6, 2025, 7:25 p.m.
proto 4
3 6 1 0.79 July 25, 2023, 7:22 a.m. Nov. 6, 2025, 7:25 p.m.
proto 6
Traffic behavior suggests probing of access controls and protected surfaces.
hits 1 pts 11.34
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
28 1 1 11.34 Oct. 16, 2023, 6:42 a.m. Oct. 16, 2023, 6:42 a.m.
fwprobe 1
Referrer patterns look manipulated, irrelevant, or inconsistent with normal navigation.
hits 6 pts 1.13
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
9 3 1 0.69 Oct. 15, 2023, 4:53 p.m. Oct. 15, 2023, 11:37 p.m.
ref 3
6 2 1 0.25 Oct. 15, 2023, 9:59 a.m. Oct. 3, 2024, 7:27 p.m.
ref 2
8 1 1 0.19 Oct. 15, 2023, 11:37 p.m. Oct. 15, 2023, 11:37 p.m.
ref 1
Requests are unusually large or shaped in a way that suggests abuse or automation.
hits 13 pts 0.59
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
14 1 1 0.59 Oct. 2, 2025, 6:18 p.m. Oct. 2, 2025, 6:18 p.m.
request_size 1
0 12 1 0.00 Jan. 2, 2025, 5:06 p.m. Feb. 2, 2025, 4:59 p.m.
request_size 12

HTTP Status Breakdown

Response mix grouped by status class (2xx/3xx/4xx/5xx). Auto-loads a single aggregation and renders a donut.

Loading status mix…
Running one aggregation and rendering the chart.

Geolocation

Live geolocation and map tiles auto-load for this ASN snapshot (peer IPs with coordinates).

Loading map…

SUBNETS HELD BY THIS ISP

Derived from ISP snapshot peers (Option A). Grouped into IPv4 /24 and IPv6 /48 by default.
IPv4
IPv6
Limit
Loading subnets…

Interesting IPs

Top risky peers inside this ASN (latest snapshot). Sorted by risk score, then hits.

No peer rows available for this ASN snapshot.