DigitalOcean Referral Badge
cloud1
cloud2
cloud3
cloud4
cloud5
cloud6
← Back

ASN REPORT — AS4134 · CHINANET-BACKBONE

First sighted: April 30, 2023, 3 a.m. · Last sighted: Jan. 11, 2026, 1:59 a.m.

Risk
98 (high)
Total hits
51591
Total errors
5353
Observed IPs
8067
Top country
N/A
Top city
N/A

Risk

Model: v1 Computed: 2026-01-18 11:55:27
Risk score
98
High
Risk gradient
Key drivers are enriched against the published annotator catalog when available; otherwise sensible defaults are used.
Key drivers
Credential brute forcing
Repeated authentication attempts consistent with password guessing or credential stuffing.
cred
Hits 1302
Points 3031.16
User-Agent anomaly
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
ua
Hits 11996
Points 1587.08
Command injection attempts
Request content resembles attempts to execute OS commands via an application.
cmdi
Hits 75
Points 1545.33
Scan velocity
High request rate and broad endpoint coverage suggest scanning or automated enumeration.
scan_velocity
Hits 1205
Points 1467.77
Path traversal attempts
Request paths/parameters resemble attempts to access files outside intended directories.
trav
Hits 178
Points 1171.38
Sensitive file probing
Requests target commonly sensitive files, configs, backups, or administrative resources.
sfp
Hits 83
Points 527.98
Protocol anomaly
Request structure or protocol-level signals deviate from typical browser HTTP traffic.
proto
Hits 108
Points 59.70
General injection attempts
Suspicious input patterns consistent with injection-like probing across multiple families.
injg
Hits 2
Points 47.88
Automated client behavior
Traffic patterns strongly suggest automation rather than a human-operated browser.
bot
Hits 98
Points 45.91
HTTP method anomaly
Unusual or unexpected HTTP methods observed for the target endpoints.
method
Hits 98
Points 25.21

Traffic

Rollup

Daily activity (hits per day) and basic HTTP rollup counters for this ASN.

Loading activity…
Daily activity (hits per day). Total in window: .
Traffic rollup
HTTP status classes, URL diversity, and totals.
2xx
40516
3xx
2677
4xx
5273
5xx
80
Unique URLs
8488
Total hits
51591
First seen
April 30, 2023, 3 a.m.
Last seen
Jan. 11, 2026, 1:59 a.m.

Annotators (All-time)

Heatmap of annotator × severity. Darker cells mean more volume in that band. Tip: switch to Weighted points to see what drives impact (not just noise).

Severity →
Low High
Repeated authentication attempts consistent with password guessing or credential stuffing.
hits 1302 pts 3031.16
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 438 1 1686.85 Sept. 28, 2023, 2:14 p.m. Aug. 13, 2025, 4:36 a.m.
cred 438
8 422 1 1299.76 April 15, 2024, 10:14 p.m. Aug. 13, 2025, 4:36 a.m.
cred 422
12 9 1 44.55 April 25, 2024, 1:43 a.m. June 21, 2025, 12:10 p.m.
cred 9
0 433 1 0.00 Sept. 28, 2023, 2:14 p.m. Aug. 13, 2025, 4:36 a.m.
cred 433
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
hits 11996 pts 1587.08
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 9774 1 1407.46 Oct. 10, 2023, 1:54 a.m. Jan. 9, 2026, 10:07 p.m.
ua 9774
6 1731 1 124.63 April 30, 2023, 10:16 p.m. Dec. 17, 2025, 12:26 a.m.
ua 1731
8 458 1 47.66 July 7, 2023, 10:02 p.m. Dec. 17, 2025, 9:24 a.m.
ua 458
14 32 1 7.17 Aug. 9, 2023, 6:10 p.m. Jan. 10, 2026, 4:59 a.m.
ua 32
12 1 1 0.17 Dec. 31, 2024, 6:41 a.m. Dec. 31, 2024, 6:41 a.m.
ua 1
Request content resembles attempts to execute OS commands via an application.
hits 75 pts 1545.33
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
28 61 1 1277.58 June 18, 2023, 6:43 p.m. Sept. 21, 2025, 4:19 a.m.
cmdi 61
30 8 1 183.60 July 8, 2023, 9:04 a.m. April 6, 2025, 7:22 a.m.
cmdi 8
22 6 1 84.15 May 15, 2024, 5:36 p.m. May 8, 2025, 11:14 p.m.
cmdi 6
Scan velocity scan_velocity
High request rate and broad endpoint coverage suggest scanning or automated enumeration.
hits 1205 pts 1467.77
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
12 227 1 416.34 April 15, 2024, 10:15 p.m. Dec. 25, 2024, 5:49 p.m.
scan_velocity 227
14 124 1 265.61 April 19, 2024, 4:29 a.m. Nov. 27, 2024, 8:20 p.m.
scan_velocity 124
16 106 1 260.06 April 19, 2024, 4:29 a.m. Feb. 1, 2025, 5:19 p.m.
scan_velocity 106
18 70 1 194.40 April 19, 2024, 4:29 a.m. Feb. 1, 2025, 5:19 p.m.
scan_velocity 70
10 110 1 140.49 Nov. 9, 2024, 3:11 p.m. Dec. 17, 2025, 12:26 a.m.
scan_velocity 110
22 29 1 102.17 May 31, 2024, 1:39 a.m. May 8, 2025, 11:14 p.m.
scan_velocity 29
20 16 1 50.76 May 31, 2024, 1:39 a.m. May 8, 2025, 11:13 p.m.
scan_velocity 16
24 6 1 22.03 May 31, 2024, 1:39 a.m. Nov. 27, 2024, 8:21 p.m.
scan_velocity 6
26 4 1 15.91 May 31, 2024, 1:39 a.m. May 31, 2024, 2:28 a.m.
scan_velocity 4
0 513 1 0.00 April 15, 2024, 10:15 p.m. Dec. 17, 2025, 12:26 a.m.
scan_velocity 513
Request paths/parameters resemble attempts to access files outside intended directories.
hits 178 pts 1171.38
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
28 70 1 468.83 May 15, 2024, 5:31 p.m. July 16, 2025, 4:58 p.m.
trav 70
26 70 1 425.88 May 15, 2024, 5:31 p.m. July 16, 2025, 4:58 p.m.
trav 70
30 38 1 276.67 May 15, 2024, 5:31 p.m. July 16, 2025, 4:58 p.m.
trav 38
Requests target commonly sensitive files, configs, backups, or administrative resources.
hits 83 pts 527.98
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
34 70 1 450.30 May 15, 2024, 5:31 p.m. July 16, 2025, 4:58 p.m.
sensitive_file 70
36 8 1 54.49 July 8, 2023, 9:04 a.m. April 6, 2025, 7:22 a.m.
sensitive_file 8
22 4 1 15.10 Jan. 20, 2024, 4:57 p.m. Jan. 20, 2024, 5:01 p.m.
sensitive_file 4
40 1 1 8.10 Sept. 29, 2024, 11:38 p.m. Sept. 29, 2024, 11:38 p.m.
sensitive_file 1
Request structure or protocol-level signals deviate from typical browser HTTP traffic.
hits 108 pts 59.70
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
11 65 1 40.04 May 31, 2023, 11 p.m. Oct. 5, 2025, 4:17 a.m.
proto 65
12 25 1 17.28 May 15, 2024, 5:31 p.m. July 16, 2025, 4:58 p.m.
proto 25
3 18 1 2.38 May 31, 2023, 11 p.m. July 16, 2025, 4:58 p.m.
proto 18
Suspicious input patterns consistent with injection-like probing across multiple families.
hits 2 pts 47.88
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
36 2 1 47.88 Oct. 4, 2023, 9:01 p.m. Feb. 15, 2025, 2:47 p.m.
injg 2
Traffic patterns strongly suggest automation rather than a human-operated browser.
hits 98 pts 45.91
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 95 1 45.13 July 8, 2023, 2:59 a.m. Jan. 11, 2025, 7:51 a.m.
bot 95
8 3 1 0.78 Dec. 7, 2024, 4:42 p.m. March 25, 2025, 5:50 a.m.
bot 3
Unusual or unexpected HTTP methods observed for the target endpoints.
hits 98 pts 25.21
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
8 32 1 13.06 May 31, 2023, 11 p.m. Oct. 5, 2025, 4:17 a.m.
method 32
3 57 1 7.18 June 1, 2023, 1:46 p.m. Dec. 17, 2025, 3:51 a.m.
method 57
10 9 1 4.97 Feb. 15, 2024, 7:27 a.m. Nov. 6, 2025, 5:38 a.m.
method 9
Requests are unusually large or shaped in a way that suggests abuse or automation.
hits 185 pts 4.66
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
12 5 1 2.34 Dec. 26, 2024, 4:47 p.m. March 7, 2025, 2:46 p.m.
request_size 5
14 4 1 2.32 June 28, 2025, 5:56 p.m. Sept. 30, 2025, 10:25 p.m.
request_size 4
0 176 1 0.00 Dec. 25, 2024, 5:47 p.m. Nov. 24, 2025, 2:54 p.m.
request_size 176
Referrer patterns look manipulated, irrelevant, or inconsistent with normal navigation.
hits 1 pts 0.13
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
6 1 1 0.13 Sept. 28, 2023, 2:14 p.m. Sept. 28, 2023, 2:14 p.m.
ref 1

HTTP Status Breakdown

Response mix grouped by status class (2xx/3xx/4xx/5xx). Auto-loads a single aggregation and renders a donut.

Loading status mix…
Running one aggregation and rendering the chart.

Geolocation

Live geolocation and map tiles auto-load for this ASN snapshot (peer IPs with coordinates).

Loading map…

SUBNETS HELD BY THIS ISP

Derived from ISP snapshot peers (Option A). Grouped into IPv4 /24 and IPv6 /48 by default.
IPv4
IPv6
Limit
Loading subnets…

Interesting IPs

Top risky peers inside this ASN (latest snapshot). Sorted by risk score, then hits.

No peer rows available for this ASN snapshot.