DigitalOcean Referral Badge
cloud1
cloud2
cloud3
cloud4
cloud5
cloud6
← Back

ASN REPORT — AS4134 · CHINANET-BACKBONE

First sighted: April 30, 2023, 3 a.m. · Last sighted: Jan. 26, 2026, 1:59 a.m.

Risk
100 (high)
Total hits
86733
Total errors
7174
Observed IPs
8441
Top country
N/A
Top city
N/A

Risk

Model: v1 Computed: 2026-01-29 10:18:33
Risk score
100
High
Risk gradient
Key drivers are enriched against the published annotator catalog when available; otherwise sensible defaults are used.
Key drivers
Scan velocity
High request rate and broad endpoint coverage suggest scanning or automated enumeration.
scan_velocity
Hits 3634
Points 5164.63
Credential brute forcing
Repeated authentication attempts consistent with password guessing or credential stuffing.
cred
Hits 1314
Points 3064.49
User-Agent anomaly
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
ua
Hits 11996
Points 1587.08
Command injection attempts
Request content resembles attempts to execute OS commands via an application.
cmdi
Hits 77
Points 1580.30
Path traversal attempts
Request paths/parameters resemble attempts to access files outside intended directories.
trav
Hits 184
Points 1212.59
Sensitive file probing
Requests target commonly sensitive files, configs, backups, or administrative resources.
sfp
Hits 91
Points 586.63
Protocol anomaly
Request structure or protocol-level signals deviate from typical browser HTTP traffic.
proto
Hits 109
Points 60.39
General injection attempts
Suspicious input patterns consistent with injection-like probing across multiple families.
injg
Hits 2
Points 47.88
Automated client behavior
Traffic patterns strongly suggest automation rather than a human-operated browser.
bot
Hits 98
Points 45.91
Request size anomaly
Requests are unusually large or shaped in a way that suggests abuse or automation.
request_size
Hits 240
Points 37.00

Traffic

Rollup

Daily activity (hits per day) and basic HTTP rollup counters for this ASN.

Loading activity…
Daily activity (hits per day). Total in window: .
Traffic rollup
HTTP status classes, URL diversity, and totals.
2xx
71790
3xx
4724
4xx
7062
5xx
112
Unique URLs
40602
Total hits
86733
First seen
April 30, 2023, 3 a.m.
Last seen
Jan. 26, 2026, 1:59 a.m.

Annotators (All-time)

Heatmap of annotator × severity. Darker cells mean more volume in that band. Tip: switch to Weighted points to see what drives impact (not just noise).

Severity →
Low High
Scan velocity scan_velocity
High request rate and broad endpoint coverage suggest scanning or automated enumeration.
hits 3634 pts 5164.63
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
32 222 1 905.47 Jan. 22, 2026, 6:55 a.m. Jan. 22, 2026, 12:13 p.m.
scan_velocity 222
10 617 1 780.03 Nov. 9, 2024, 3:11 p.m. Jan. 22, 2026, 9:11 p.m.
scan_velocity 617
12 365 1 625.21 April 15, 2024, 10:15 p.m. Jan. 22, 2026, 9:11 p.m.
scan_velocity 365
16 224 1 497.95 April 19, 2024, 4:29 a.m. Jan. 22, 2026, 12:14 p.m.
scan_velocity 224
14 234 1 459.65 April 19, 2024, 4:29 a.m. Jan. 22, 2026, 12:10 p.m.
scan_velocity 234
18 175 1 434.00 April 19, 2024, 4:29 a.m. Jan. 22, 2026, 12:11 p.m.
scan_velocity 175
22 128 1 378.38 May 31, 2024, 1:39 a.m. Jan. 22, 2026, 12:11 p.m.
scan_velocity 128
20 91 1 241.38 May 31, 2024, 1:39 a.m. Jan. 22, 2026, 12:11 p.m.
scan_velocity 91
24 73 1 226.58 May 31, 2024, 1:39 a.m. Jan. 22, 2026, 12:11 p.m.
scan_velocity 73
26 58 1 197.03 May 31, 2024, 1:39 a.m. Jan. 22, 2026, 12:06 p.m.
scan_velocity 58
30 49 1 192.51 Jan. 22, 2026, 6:55 a.m. Jan. 22, 2026, 12:12 p.m.
scan_velocity 49
28 40 1 145.66 Jan. 22, 2026, 6:55 a.m. Jan. 22, 2026, 12:11 p.m.
scan_velocity 40
36 9 1 49.57 Jan. 22, 2026, 11:19 a.m. Jan. 22, 2026, 12:04 p.m.
scan_velocity 9
34 6 1 31.21 Jan. 22, 2026, 11:19 a.m. Jan. 22, 2026, 11:34 a.m.
scan_velocity 6
0 1343 1 0.00 April 15, 2024, 10:15 p.m. Jan. 22, 2026, 9:11 p.m.
scan_velocity 1343
Repeated authentication attempts consistent with password guessing or credential stuffing.
hits 1314 pts 3064.49
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 442 1 1702.25 Sept. 28, 2023, 2:14 p.m. Jan. 22, 2026, 12:03 p.m.
cred 442
8 423 1 1302.84 April 15, 2024, 10:14 p.m. Jan. 22, 2026, 11:19 a.m.
cred 423
12 12 1 59.40 April 25, 2024, 1:43 a.m. Jan. 22, 2026, 12:03 p.m.
cred 12
0 437 1 0.00 Sept. 28, 2023, 2:14 p.m. Jan. 22, 2026, 12:03 p.m.
cred 437
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
hits 11996 pts 1587.08
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 9774 1 1407.46 Oct. 10, 2023, 1:54 a.m. Jan. 9, 2026, 10:07 p.m.
ua 9774
6 1731 1 124.63 April 30, 2023, 10:16 p.m. Dec. 17, 2025, 12:26 a.m.
ua 1731
8 458 1 47.66 July 7, 2023, 10:02 p.m. Dec. 17, 2025, 9:24 a.m.
ua 458
14 32 1 7.17 Aug. 9, 2023, 6:10 p.m. Jan. 10, 2026, 4:59 a.m.
ua 32
12 1 1 0.17 Dec. 31, 2024, 6:41 a.m. Dec. 31, 2024, 6:41 a.m.
ua 1
Request content resembles attempts to execute OS commands via an application.
hits 77 pts 1580.30
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
28 62 1 1298.53 June 18, 2023, 6:43 p.m. Jan. 22, 2026, 9:23 a.m.
cmdi 62
30 8 1 183.60 July 8, 2023, 9:04 a.m. April 6, 2025, 7:22 a.m.
cmdi 8
22 7 1 98.18 May 15, 2024, 5:36 p.m. Jan. 22, 2026, 9:23 a.m.
cmdi 7
Request paths/parameters resemble attempts to access files outside intended directories.
hits 184 pts 1212.59
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
28 72 1 482.23 May 15, 2024, 5:31 p.m. Jan. 22, 2026, 11:30 a.m.
trav 72
26 72 1 438.05 May 15, 2024, 5:31 p.m. Jan. 22, 2026, 11:30 a.m.
trav 72
30 39 1 283.92 May 15, 2024, 5:31 p.m. Jan. 22, 2026, 11:30 a.m.
trav 39
34 1 1 8.40 Jan. 22, 2026, 11:17 a.m. Jan. 22, 2026, 11:17 a.m.
trav 1
Requests target commonly sensitive files, configs, backups, or administrative resources.
hits 91 pts 586.63
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
34 73 1 469.59 May 15, 2024, 5:31 p.m. Jan. 22, 2026, 11:44 a.m.
sensitive_file 73
36 9 1 61.46 July 8, 2023, 9:04 a.m. Jan. 22, 2026, 11:17 a.m.
sensitive_file 9
40 5 1 40.48 Sept. 29, 2024, 11:38 p.m. Jan. 22, 2026, 11:22 a.m.
sensitive_file 5
22 4 1 15.10 Jan. 20, 2024, 4:57 p.m. Jan. 20, 2024, 5:01 p.m.
sensitive_file 4
Request structure or protocol-level signals deviate from typical browser HTTP traffic.
hits 109 pts 60.39
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
11 65 1 40.04 May 31, 2023, 11 p.m. Oct. 5, 2025, 4:17 a.m.
proto 65
12 26 1 17.97 May 15, 2024, 5:31 p.m. Jan. 22, 2026, 11:30 a.m.
proto 26
3 18 1 2.38 May 31, 2023, 11 p.m. July 16, 2025, 4:58 p.m.
proto 18
Suspicious input patterns consistent with injection-like probing across multiple families.
hits 2 pts 47.88
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
36 2 1 47.88 Oct. 4, 2023, 9:01 p.m. Feb. 15, 2025, 2:47 p.m.
injg 2
Traffic patterns strongly suggest automation rather than a human-operated browser.
hits 98 pts 45.91
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 95 1 45.13 July 8, 2023, 2:59 a.m. Jan. 11, 2025, 7:51 a.m.
bot 95
8 3 1 0.78 Dec. 7, 2024, 4:42 p.m. March 25, 2025, 5:50 a.m.
bot 3
Requests are unusually large or shaped in a way that suggests abuse or automation.
hits 240 pts 37.00
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
14 59 1 34.66 June 28, 2025, 5:56 p.m. Jan. 24, 2026, 10:47 p.m.
request_size 59
12 5 1 2.34 Dec. 26, 2024, 4:47 p.m. March 7, 2025, 2:46 p.m.
request_size 5
0 176 1 0.00 Dec. 25, 2024, 5:47 p.m. Nov. 24, 2025, 2:54 p.m.
request_size 176
Unusual or unexpected HTTP methods observed for the target endpoints.
hits 98 pts 25.21
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
8 32 1 13.06 May 31, 2023, 11 p.m. Oct. 5, 2025, 4:17 a.m.
method 32
3 57 1 7.18 June 1, 2023, 1:46 p.m. Dec. 17, 2025, 3:51 a.m.
method 57
10 9 1 4.97 Feb. 15, 2024, 7:27 a.m. Nov. 6, 2025, 5:38 a.m.
method 9
Input patterns resemble attempts to manipulate SQL queries via application parameters.
hits 1 pts 19.68
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
24 1 1 19.68 Jan. 22, 2026, 9:23 a.m. Jan. 22, 2026, 9:23 a.m.
sqli 1
Referrer patterns look manipulated, irrelevant, or inconsistent with normal navigation.
hits 2 pts 0.25
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
6 2 1 0.25 Sept. 28, 2023, 2:14 p.m. Jan. 22, 2026, 11:19 a.m.
ref 2

HTTP Status Breakdown

Response mix grouped by status class (2xx/3xx/4xx/5xx). Auto-loads a single aggregation and renders a donut.

Loading status mix…
Running one aggregation and rendering the chart.

Geolocation

Live geolocation and map tiles auto-load for this ASN snapshot (peer IPs with coordinates).

Loading map…

SUBNETS HELD BY THIS ISP

Derived from ISP snapshot peers (Option A). Grouped into IPv4 /24 and IPv6 /48 by default.
IPv4
IPv6
Limit
Loading subnets…

Interesting IPs

Top risky peers inside this ASN (latest snapshot). Sorted by risk score, then hits.

No peer rows available for this ASN snapshot.