DigitalOcean Referral Badge
cloud1
cloud2
cloud3
cloud4
cloud5
cloud6
← Back

ASN REPORT — AS208949 · HBING LIMITED

First sighted: Dec. 22, 2023, 2 a.m. · Last sighted: May 12, 2025, 3 a.m.

Risk
73 (high)
Total hits
732
Total errors
297
Observed IPs
10
Top country
United States
Top city
Seattle
Top region
Washington

Risk

Model: v1 Computed: 2026-02-27 17:09:49
Risk score
73
High
Risk gradient
Key drivers are enriched against the published annotator catalog when available; otherwise sensible defaults are used.
Key drivers
Sensitive file probing
Requests target commonly sensitive files, configs, backups, or administrative resources.
sfp
Hits 414
Points 2949.76
Path traversal attempts
Request paths/parameters resemble attempts to access files outside intended directories.
trav
Hits 32
Points 260.00
Scan velocity
High request rate and broad endpoint coverage suggest scanning or automated enumeration.
scan_velocity
Hits 20
Points 18.00
User-Agent anomaly
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
ua
Hits 36
Points 7.44
Automated client behavior
Traffic patterns strongly suggest automation rather than a human-operated browser.
bot
Hits 3
Points 1.50

Traffic

Rollup

Daily activity (hits per day) and basic HTTP rollup counters for this ASN.

Loading activity…
Daily activity (hits per day). Total in window: .
Traffic rollup
HTTP status classes, URL diversity, and totals.
2xx
435
3xx
0
4xx
297
5xx
0
Unique URLs
0
Total hits
732
First seen
Dec. 22, 2023, 2 a.m.
Last seen
May 12, 2025, 3 a.m.

Annotators (All-time)

Heatmap of annotator × severity. Darker cells mean more volume in that band. Tip: switch to Weighted points to see what drives impact (not just noise).

Severity →
Low High
Requests target commonly sensitive files, configs, backups, or administrative resources.
hits 414 pts 2949.76
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
40 211 50 1856.80 Dec. 22, 2023, 2:35 a.m. May 11, 2025, 5:17 p.m.
24 181 41 955.68 March 20, 2025, 1:50 p.m. May 10, 2025, 9:58 p.m.
36 8 1 63.36 Feb. 21, 2025, 3:05 p.m. Feb. 21, 2025, 3:05 p.m.
34 8 1 59.84 Feb. 21, 2025, 3:05 p.m. Feb. 21, 2025, 3:05 p.m.
8 4 1 7.04 Feb. 21, 2025, 3:05 p.m. Feb. 21, 2025, 3:05 p.m.
16 2 1 7.04 May 11, 2025, 12:08 p.m. May 11, 2025, 5:17 p.m.
Request paths/parameters resemble attempts to access files outside intended directories.
hits 32 pts 260.00
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
34 20 7 176.80 Feb. 21, 2025, 3:05 p.m. May 11, 2025, 4:30 a.m.
26 8 1 54.08 Feb. 21, 2025, 3:05 p.m. Feb. 21, 2025, 3:05 p.m.
28 4 1 29.12 Feb. 21, 2025, 3:05 p.m. Feb. 21, 2025, 3:05 p.m.
Scan velocity scan_velocity
High request rate and broad endpoint coverage suggest scanning or automated enumeration.
hits 20 pts 18.00
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 10 7 18.00 Feb. 21, 2025, 3:05 p.m. May 11, 2025, 4:30 a.m.
0 10 7 0.00 Feb. 21, 2025, 3:05 p.m. May 11, 2025, 4:30 a.m.
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
hits 36 pts 7.44
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 30 15 6.00 Dec. 22, 2023, 2:35 a.m. April 5, 2025, 8:17 p.m.
12 6 6 1.44 March 25, 2025, 2:46 a.m. April 29, 2025, 12:04 p.m.
Traffic patterns strongly suggest automation rather than a human-operated browser.
hits 3 pts 1.50
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 3 3 1.50 March 24, 2025, 6:01 p.m. May 9, 2025, 12:57 a.m.

HTTP Status Breakdown

Response mix grouped by status class (2xx/3xx/4xx/5xx). Auto-loads a single aggregation and renders a donut.

Loading status mix…
Running one aggregation and rendering the chart.

Geolocation

Live geolocation and map tiles auto-load for this ASN snapshot (peer IPs with coordinates).

Loading map…

SUBNETS HELD BY THIS ISP

Derived from ISP snapshot peers (Option A). Grouped into IPv4 /24 and IPv6 /48 by default.
IPv4
IPv6
Limit
Loading subnets…

Interesting IPs

Top risky peers inside this ASN (latest snapshot). Sorted by risk score, then hits.

195.211.191.76 high
99 /100
Last seen 2025-05-12 03:00
Hits
202
Errors
153
Country
Germany
ASN
AS208949
AS Org
HBING LIMITED
195.211.191.170 med
67 /100
Last seen 2025-05-12 03:00
Hits
269
Errors
92
Country
Germany
ASN
AS208949
AS Org
HBING LIMITED
195.211.191.127 med
44 /100
Last seen 2025-04-23 03:00
Hits
93
Errors
32
Country
Germany
ASN
AS208949
AS Org
HBING LIMITED
195.211.191.110 low
30 /100
Last seen 2025-02-22 02:00
Hits
136
Errors
8
Country
Germany
ASN
AS208949
AS Org
HBING LIMITED
195.211.191.166 low
18 /100
Last seen 2025-02-11 02:00
Hits
14
Errors
0
Country
Germany
ASN
AS208949
AS Org
HBING LIMITED
195.211.191.109 low
1 /100
Last seen 2025-02-25 02:00
Hits
4
Errors
1
Country
Germany
ASN
AS208949
AS Org
HBING LIMITED
192.101.68.19 low
1 /100
Last seen 2024-01-22 02:00
Hits
2
Errors
1
Country
United States
ASN
AS208949
AS Org
HBING LIMITED
192.101.68.73 low
1 /100
Last seen 2024-01-10 02:00
Hits
2
Errors
1
Country
United States
ASN
AS208949
AS Org
HBING LIMITED
192.101.68.175 low
1 /100
Last seen 2023-12-31 02:00
Hits
2
Errors
1
Country
United States
ASN
AS208949
AS Org
HBING LIMITED
195.211.191.2 low
0 /100
Last seen 2025-03-11 02:00
Hits
8
Errors
8
Country
Germany
ASN
AS208949
AS Org
HBING LIMITED