DigitalOcean Referral Badge
cloud1
cloud2
cloud3
cloud4
cloud5
cloud6
← Back

ASN REPORT — AS39251 · NETGUARD LLC

First sighted: Nov. 16, 2023, 2 a.m. · Last sighted: Dec. 18, 2025, 1:59 a.m.

Risk
3 (low)
Total hits
711
Total errors
11
Observed IPs
8
Top country
N/A
Top city
N/A

Risk

Model: v1 Computed: 2026-01-18 11:54:50
Risk score
3
Low
Risk gradient
Key drivers are enriched against the published annotator catalog when available; otherwise sensible defaults are used.
Key drivers
Request size anomaly
Requests are unusually large or shaped in a way that suggests abuse or automation.
request_size
Hits 95
Points 28.85
Command injection attempts
Request content resembles attempts to execute OS commands via an application.
cmdi
Hits 1
Points 20.94
Scan velocity
High request rate and broad endpoint coverage suggest scanning or automated enumeration.
scan_velocity
Hits 32
Points 20.16
User-Agent anomaly
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
ua
Hits 2
Points 0.14

Traffic

Rollup

Daily activity (hits per day) and basic HTTP rollup counters for this ASN.

Loading activity…
Daily activity (hits per day). Total in window: .
Traffic rollup
HTTP status classes, URL diversity, and totals.
2xx
571
3xx
45
4xx
10
5xx
1
Unique URLs
205
Total hits
711
First seen
Nov. 16, 2023, 2 a.m.
Last seen
Dec. 18, 2025, 1:59 a.m.

Annotators (All-time)

Heatmap of annotator × severity. Darker cells mean more volume in that band. Tip: switch to Weighted points to see what drives impact (not just noise).

Severity →
Low High
Requests are unusually large or shaped in a way that suggests abuse or automation.
hits 95 pts 28.85
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
12 34 1 15.91 Aug. 23, 2025, 8:58 p.m. Aug. 24, 2025, 10:40 a.m.
request_size 34
14 22 1 12.94 Aug. 23, 2025, 8:58 p.m. Aug. 24, 2025, 10:40 a.m.
request_size 22
0 39 1 0.00 Aug. 23, 2025, 8:58 p.m. Aug. 24, 2025, 7:56 a.m.
request_size 39
Request content resembles attempts to execute OS commands via an application.
hits 1 pts 20.94
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
28 1 1 20.94 Jan. 24, 2024, 12:01 a.m. Jan. 24, 2024, 12:01 a.m.
cmdi 1
Scan velocity scan_velocity
High request rate and broad endpoint coverage suggest scanning or automated enumeration.
hits 32 pts 20.16
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 16 1 20.16 Aug. 23, 2025, 8:58 p.m. Aug. 23, 2025, 10:30 p.m.
scan_velocity 16
0 16 1 0.00 Aug. 23, 2025, 8:58 p.m. Aug. 23, 2025, 10:30 p.m.
scan_velocity 16
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
hits 2 pts 0.14
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
6 2 1 0.14 Jan. 24, 2024, 12:01 a.m. Aug. 24, 2025, 7:55 a.m.
ua 2

HTTP Status Breakdown

Response mix grouped by status class (2xx/3xx/4xx/5xx). Auto-loads a single aggregation and renders a donut.

Loading status mix…
Running one aggregation and rendering the chart.

Geolocation

Live geolocation and map tiles auto-load for this ASN snapshot (peer IPs with coordinates).

Loading map…

SUBNETS HELD BY THIS ISP

Derived from ISP snapshot peers (Option A). Grouped into IPv4 /24 and IPv6 /48 by default.
IPv4
IPv6
Limit
Loading subnets…

Interesting IPs

Top risky peers inside this ASN (latest snapshot). Sorted by risk score, then hits.

No peer rows available for this ASN snapshot.