DigitalOcean Referral Badge
cloud1
cloud2
cloud3
cloud4
cloud5
cloud6
← Back

ASN REPORT — AS209366 · SEMrush CY LTD

First sighted: April 30, 2023, 3 a.m. · Last sighted: Jan. 11, 2026, 1:59 a.m.

Risk
100 (high)
Total hits
4136195
Total errors
126889
Observed IPs
19302
Top country
N/A
Top city
N/A

Risk

Model: v1 Computed: 2026-01-18 11:55:27
Risk score
100
High
Risk gradient
Key drivers are enriched against the published annotator catalog when available; otherwise sensible defaults are used.
Key drivers
Automated client behavior
Traffic patterns strongly suggest automation rather than a human-operated browser.
bot
Hits 2067275
Points 981955.62
Credential brute forcing
Repeated authentication attempts consistent with password guessing or credential stuffing.
cred
Hits 72
Points 166.32
User-Agent anomaly
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
ua
Hits 759
Points 54.65
Command injection attempts
Request content resembles attempts to execute OS commands via an application.
cmdi
Hits 1
Points 14.59

Traffic

Rollup

Daily activity (hits per day) and basic HTTP rollup counters for this ASN.

Loading activity…
Daily activity (hits per day). Total in window: .
Traffic rollup
HTTP status classes, URL diversity, and totals.
2xx
3468818
3xx
538970
4xx
119848
5xx
7041
Unique URLs
1649623
Total hits
4136195
First seen
April 30, 2023, 3 a.m.
Last seen
Jan. 11, 2026, 1:59 a.m.

Annotators (All-time)

Heatmap of annotator × severity. Darker cells mean more volume in that band. Tip: switch to Weighted points to see what drives impact (not just noise).

Severity →
Low High
Traffic patterns strongly suggest automation rather than a human-operated browser.
hits 2067275 pts 981955.62
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 2067275 1 981955.62 April 30, 2023, 5:53 a.m. Jan. 10, 2026, 5:01 a.m.
bot 2067275
Repeated authentication attempts consistent with password guessing or credential stuffing.
hits 72 pts 166.32
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 24 1 92.40 Sept. 13, 2023, 1:56 a.m. Sept. 9, 2025, 4:05 a.m.
cred 24
8 24 1 73.92 Sept. 13, 2023, 1:56 a.m. Sept. 9, 2025, 4:05 a.m.
cred 24
0 24 1 0.00 Sept. 13, 2023, 1:56 a.m. Sept. 9, 2025, 4:05 a.m.
cred 24
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
hits 759 pts 54.65
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
6 759 1 54.65 April 30, 2023, 1:01 p.m. Dec. 31, 2025, 2:30 p.m.
ua 759
Request content resembles attempts to execute OS commands via an application.
hits 1 pts 14.59
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
22 1 1 14.59 April 14, 2025, 8:54 a.m. April 14, 2025, 8:54 a.m.
cmdi 1

HTTP Status Breakdown

Response mix grouped by status class (2xx/3xx/4xx/5xx). Auto-loads a single aggregation and renders a donut.

Loading status mix…
Running one aggregation and rendering the chart.

Geolocation

Live geolocation and map tiles auto-load for this ASN snapshot (peer IPs with coordinates).

Loading map…

SUBNETS HELD BY THIS ISP

Derived from ISP snapshot peers (Option A). Grouped into IPv4 /24 and IPv6 /48 by default.
IPv4
IPv6
Limit
Loading subnets…

Interesting IPs

Top risky peers inside this ASN (latest snapshot). Sorted by risk score, then hits.

No peer rows available for this ASN snapshot.