DigitalOcean Referral Badge
cloud1
cloud2
cloud3
cloud4
cloud5
cloud6
← Back

ASN REPORT — AS56046 · China Mobile communications corporation

First sighted: July 28, 2023, 3 a.m. · Last sighted: Jan. 11, 2026, 1:59 a.m.

Risk
30 (low)
Total hits
3706
Total errors
739
Observed IPs
745
Top country
N/A
Top city
N/A

Risk

Model: v1 Computed: 2026-01-18 11:55:12
Risk score
30
Low
Risk gradient
Key drivers are enriched against the published annotator catalog when available; otherwise sensible defaults are used.
Key drivers
Automated client behavior
Traffic patterns strongly suggest automation rather than a human-operated browser.
bot
Hits 1244
Points 590.90
Path traversal attempts
Request paths/parameters resemble attempts to access files outside intended directories.
trav
Hits 23
Points 151.46
Sensitive file probing
Requests target commonly sensitive files, configs, backups, or administrative resources.
sfp
Hits 9
Points 57.90
Command injection attempts
Request content resembles attempts to execute OS commands via an application.
cmdi
Hits 2
Points 34.97
Scan velocity
High request rate and broad endpoint coverage suggest scanning or automated enumeration.
scan_velocity
Hits 23
Points 18.43
Credential brute forcing
Repeated authentication attempts consistent with password guessing or credential stuffing.
cred
Hits 12
Points 17.49
User-Agent anomaly
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
ua
Hits 127
Points 14.13
SQL injection attempts
Input patterns resemble attempts to manipulate SQL queries via application parameters.
sqli
Hits 2
Points 8.80
Protocol anomaly
Request structure or protocol-level signals deviate from typical browser HTTP traffic.
proto
Hits 5
Points 2.82
Request size anomaly
Requests are unusually large or shaped in a way that suggests abuse or automation.
request_size
Hits 5
Points 0.59

Traffic

Rollup

Daily activity (hits per day) and basic HTTP rollup counters for this ASN.

Loading activity…
Daily activity (hits per day). Total in window: .
Traffic rollup
HTTP status classes, URL diversity, and totals.
2xx
1918
3xx
909
4xx
658
5xx
81
Unique URLs
930
Total hits
3706
First seen
July 28, 2023, 3 a.m.
Last seen
Jan. 11, 2026, 1:59 a.m.

Annotators (All-time)

Heatmap of annotator × severity. Darker cells mean more volume in that band. Tip: switch to Weighted points to see what drives impact (not just noise).

Severity →
Low High
Traffic patterns strongly suggest automation rather than a human-operated browser.
hits 1244 pts 590.90
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 1244 1 590.90 Sept. 30, 2024, 8:49 a.m. Jan. 10, 2026, 4:52 a.m.
bot 1244
Request paths/parameters resemble attempts to access files outside intended directories.
hits 23 pts 151.46
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
28 9 1 60.28 Oct. 13, 2024, 1:22 p.m. April 26, 2025, 11:09 p.m.
trav 9
26 9 1 54.76 Oct. 13, 2024, 1:22 p.m. April 26, 2025, 11:09 p.m.
trav 9
30 5 1 36.43 Oct. 13, 2024, 1:22 p.m. April 26, 2025, 2:42 a.m.
trav 5
Requests target commonly sensitive files, configs, backups, or administrative resources.
hits 9 pts 57.90
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
34 9 1 57.90 Oct. 13, 2024, 1:22 p.m. April 26, 2025, 11:09 p.m.
sensitive_file 9
Request content resembles attempts to execute OS commands via an application.
hits 2 pts 34.97
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
28 1 1 20.94 Oct. 13, 2024, 1:28 p.m. Oct. 13, 2024, 1:28 p.m.
cmdi 1
22 1 1 14.02 Oct. 13, 2024, 1:28 p.m. Oct. 13, 2024, 1:28 p.m.
cmdi 1
Scan velocity scan_velocity
High request rate and broad endpoint coverage suggest scanning or automated enumeration.
hits 23 pts 18.43
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 10 1 14.76 June 6, 2024, 9:10 p.m. June 27, 2025, 4:38 a.m.
scan_velocity 10
12 2 1 3.67 June 6, 2024, 9:14 p.m. June 6, 2024, 9:14 p.m.
scan_velocity 2
0 11 1 0.00 June 6, 2024, 9:10 p.m. June 27, 2025, 4:38 a.m.
scan_velocity 11
Repeated authentication attempts consistent with password guessing or credential stuffing.
hits 12 pts 17.49
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 3 1 11.55 June 6, 2024, 9:13 p.m. June 6, 2024, 9:13 p.m.
cred 3
6 3 1 5.94 June 6, 2024, 9:13 p.m. June 6, 2024, 9:13 p.m.
cred 3
0 6 1 0.00 June 6, 2024, 9:13 p.m. June 6, 2024, 9:13 p.m.
cred 6
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
hits 127 pts 14.13
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
6 62 1 4.46 July 28, 2023, 10:14 p.m. Aug. 6, 2025, 5:53 p.m.
ua 62
14 16 1 3.58 April 20, 2024, 9:52 p.m. June 22, 2025, 8:43 p.m.
ua 16
10 23 1 3.31 April 24, 2024, 2:43 a.m. June 12, 2024, 6:55 a.m.
ua 23
8 25 1 2.60 Sept. 30, 2023, 10:29 p.m. Sept. 12, 2025, 11:03 a.m.
ua 25
12 1 1 0.17 Dec. 13, 2024, 2:45 p.m. Dec. 13, 2024, 2:45 p.m.
ua 1
Input patterns resemble attempts to manipulate SQL queries via application parameters.
hits 2 pts 8.80
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
8 2 1 8.80 Nov. 6, 2025, 7:39 a.m. Nov. 6, 2025, 3:18 p.m.
sqli 2
Request structure or protocol-level signals deviate from typical browser HTTP traffic.
hits 5 pts 2.82
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
12 3 1 2.07 Oct. 13, 2024, 1:22 p.m. April 26, 2025, 2:42 a.m.
proto 3
11 1 1 0.62 Aug. 19, 2023, 3:35 p.m. Aug. 19, 2023, 3:35 p.m.
proto 1
3 1 1 0.13 Oct. 13, 2024, 1:22 p.m. Oct. 13, 2024, 1:22 p.m.
proto 1
Requests are unusually large or shaped in a way that suggests abuse or automation.
hits 5 pts 0.59
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
14 1 1 0.59 Dec. 14, 2025, 9:12 p.m. Dec. 14, 2025, 9:12 p.m.
request_size 1
0 4 1 0.00 Oct. 14, 2025, 8:40 p.m. Dec. 14, 2025, 9:12 p.m.
request_size 4
Unusual or unexpected HTTP methods observed for the target endpoints.
hits 1 pts 0.55
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 1 1 0.55 June 22, 2025, 8:43 p.m. June 22, 2025, 8:43 p.m.
method 1
Referrer patterns look manipulated, irrelevant, or inconsistent with normal navigation.
hits 3 pts 0.38
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
6 3 1 0.38 June 6, 2024, 9:13 p.m. June 6, 2024, 9:13 p.m.
ref 3

HTTP Status Breakdown

Response mix grouped by status class (2xx/3xx/4xx/5xx). Auto-loads a single aggregation and renders a donut.

Loading status mix…
Running one aggregation and rendering the chart.

Geolocation

Live geolocation and map tiles auto-load for this ASN snapshot (peer IPs with coordinates).

Loading map…

SUBNETS HELD BY THIS ISP

Derived from ISP snapshot peers (Option A). Grouped into IPv4 /24 and IPv6 /48 by default.
IPv4
IPv6
Limit
Loading subnets…

Interesting IPs

Top risky peers inside this ASN (latest snapshot). Sorted by risk score, then hits.

No peer rows available for this ASN snapshot.