DigitalOcean Referral Badge
cloud1
cloud2
cloud3
cloud4
cloud5
cloud6
← Back

ASN REPORT — AS39351 · 31173 Services AB

First sighted: June 15, 2023, 3 a.m. · Last sighted: Dec. 18, 2025, 1:59 a.m.

Risk
24 (low)
Total hits
800
Total errors
73
Observed IPs
83
Top country
N/A
Top city
N/A

Risk

Model: v1 Computed: 2026-01-18 11:55:20
Risk score
24
Low
Risk gradient
Key drivers are enriched against the published annotator catalog when available; otherwise sensible defaults are used.
Key drivers
Sensitive file probing
Requests target commonly sensitive files, configs, backups, or administrative resources.
sfp
Hits 61
Points 473.02
Path traversal attempts
Request paths/parameters resemble attempts to access files outside intended directories.
trav
Hits 25
Points 168.68
Automated client behavior
Traffic patterns strongly suggest automation rather than a human-operated browser.
bot
Hits 21
Points 9.11
Request size anomaly
Requests are unusually large or shaped in a way that suggests abuse or automation.
request_size
Hits 63
Points 7.96
User-Agent anomaly
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
ua
Hits 65
Points 7.15
Credential brute forcing
Repeated authentication attempts consistent with password guessing or credential stuffing.
cred
Hits 3
Points 6.93
HTTP method anomaly
Unusual or unexpected HTTP methods observed for the target endpoints.
method
Hits 14
Points 5.71
Protocol anomaly
Request structure or protocol-level signals deviate from typical browser HTTP traffic.
proto
Hits 8
Points 3.29
Scan velocity
High request rate and broad endpoint coverage suggest scanning or automated enumeration.
scan_velocity
Hits 4
Points 2.52
Referrer abuse
Referrer patterns look manipulated, irrelevant, or inconsistent with normal navigation.
ref
Hits 1
Points 0.13

Traffic

Rollup

Daily activity (hits per day) and basic HTTP rollup counters for this ASN.

Loading activity…
Daily activity (hits per day). Total in window: .
Traffic rollup
HTTP status classes, URL diversity, and totals.
2xx
379
3xx
143
4xx
42
5xx
31
Unique URLs
256
Total hits
800
First seen
June 15, 2023, 3 a.m.
Last seen
Dec. 18, 2025, 1:59 a.m.

Annotators (All-time)

Heatmap of annotator × severity. Darker cells mean more volume in that band. Tip: switch to Weighted points to see what drives impact (not just noise).

Severity →
Low High
Requests target commonly sensitive files, configs, backups, or administrative resources.
hits 61 pts 473.02
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
40 51 1 412.90 Sept. 23, 2024, 11:08 a.m. Oct. 11, 2025, 9:56 p.m.
sensitive_file 51
34 8 1 51.46 June 15, 2023, 8:48 a.m. June 15, 2023, 8:48 a.m.
sensitive_file 8
24 2 1 8.66 Jan. 29, 2024, 1:23 p.m. Jan. 29, 2024, 2:33 p.m.
sensitive_file 2
Request paths/parameters resemble attempts to access files outside intended directories.
hits 25 pts 168.68
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
30 8 1 58.03 June 15, 2023, 8:48 a.m. June 15, 2023, 8:48 a.m.
trav 8
28 8 1 53.58 June 15, 2023, 8:48 a.m. June 15, 2023, 8:48 a.m.
trav 8
26 8 1 48.67 June 15, 2023, 8:48 a.m. June 15, 2023, 8:48 a.m.
trav 8
34 1 1 8.40 Dec. 7, 2024, 12:08 a.m. Dec. 7, 2024, 12:08 a.m.
trav 1
Traffic patterns strongly suggest automation rather than a human-operated browser.
hits 21 pts 9.11
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 17 1 8.08 Nov. 12, 2023, 2:28 p.m. Nov. 12, 2023, 2:28 p.m.
bot 17
8 4 1 1.04 Nov. 4, 2024, 8:09 p.m. Feb. 7, 2025, 12:19 a.m.
bot 4
Requests are unusually large or shaped in a way that suggests abuse or automation.
hits 63 pts 7.96
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
12 17 1 7.96 Feb. 24, 2025, 6:37 p.m. Aug. 1, 2025, 4:03 p.m.
request_size 17
0 46 1 0.00 Feb. 24, 2025, 6:37 p.m. Aug. 1, 2025, 4:02 p.m.
request_size 46
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
hits 65 pts 7.15
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
12 17 1 3.18 Nov. 12, 2023, 2:28 p.m. Nov. 12, 2023, 2:28 p.m.
ua 17
6 37 1 2.66 June 15, 2023, 8:48 a.m. Jan. 18, 2025, 12:01 a.m.
ua 37
8 7 1 0.73 Nov. 21, 2023, 12:32 a.m. Nov. 22, 2023, 4:22 p.m.
ua 7
10 4 1 0.58 May 19, 2024, 10:25 p.m. May 31, 2025, 3:56 a.m.
ua 4
Repeated authentication attempts consistent with password guessing or credential stuffing.
hits 3 pts 6.93
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 1 1 3.85 Nov. 13, 2023, 12:51 a.m. Nov. 13, 2023, 12:51 a.m.
cred 1
8 1 1 3.08 Nov. 13, 2023, 12:51 a.m. Nov. 13, 2023, 12:51 a.m.
cred 1
0 1 1 0.00 Nov. 13, 2023, 12:51 a.m. Nov. 13, 2023, 12:51 a.m.
cred 1
Unusual or unexpected HTTP methods observed for the target endpoints.
hits 14 pts 5.71
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
8 14 1 5.71 Nov. 21, 2023, 12:32 a.m. Nov. 22, 2023, 4:22 p.m.
method 14
Request structure or protocol-level signals deviate from typical browser HTTP traffic.
hits 8 pts 3.29
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
12 4 1 2.76 June 15, 2023, 8:48 a.m. June 15, 2023, 8:48 a.m.
proto 4
3 4 1 0.53 June 15, 2023, 8:48 a.m. June 15, 2023, 8:48 a.m.
proto 4
Scan velocity scan_velocity
High request rate and broad endpoint coverage suggest scanning or automated enumeration.
hits 4 pts 2.52
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 2 1 2.52 May 25, 2025, 4:01 p.m. May 25, 2025, 4:02 p.m.
scan_velocity 2
0 2 1 0.00 May 25, 2025, 4:01 p.m. May 25, 2025, 4:02 p.m.
scan_velocity 2
Referrer patterns look manipulated, irrelevant, or inconsistent with normal navigation.
hits 1 pts 0.13
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
6 1 1 0.13 Nov. 13, 2023, 12:51 a.m. Nov. 13, 2023, 12:51 a.m.
ref 1

HTTP Status Breakdown

Response mix grouped by status class (2xx/3xx/4xx/5xx). Auto-loads a single aggregation and renders a donut.

Loading status mix…
Running one aggregation and rendering the chart.

Geolocation

Live geolocation and map tiles auto-load for this ASN snapshot (peer IPs with coordinates).

Loading map…

SUBNETS HELD BY THIS ISP

Derived from ISP snapshot peers (Option A). Grouped into IPv4 /24 and IPv6 /48 by default.
IPv4
IPv6
Limit
Loading subnets…

Interesting IPs

Top risky peers inside this ASN (latest snapshot). Sorted by risk score, then hits.

No peer rows available for this ASN snapshot.