DigitalOcean Referral Badge
cloud1
cloud2
cloud3
cloud4
cloud5
cloud6
← Back

ASN REPORT — AS7922 · Comcast Cable Communications, LLC

First sighted: June 25, 2023, 3 a.m. · Last sighted: Jan. 11, 2026, 1:59 a.m.

Risk
55 (med)
Total hits
51183
Total errors
7335
Observed IPs
5371
Top country
N/A
Top city
N/A

Risk

Model: v1 Computed: 2026-01-18 11:55:17
Risk score
55
Medium
Risk gradient
Key drivers are enriched against the published annotator catalog when available; otherwise sensible defaults are used.
Key drivers
Command injection attempts
Request content resembles attempts to execute OS commands via an application.
cmdi
Hits 27
Points 567.49
Credential brute forcing
Repeated authentication attempts consistent with password guessing or credential stuffing.
cred
Hits 128
Points 371.80
User-Agent anomaly
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
ua
Hits 4651
Points 348.57
Scan velocity
High request rate and broad endpoint coverage suggest scanning or automated enumeration.
scan_velocity
Hits 484
Points 314.50
Request size anomaly
Requests are unusually large or shaped in a way that suggests abuse or automation.
request_size
Hits 3134
Points 257.21
Sensitive file probing
Requests target commonly sensitive files, configs, backups, or administrative resources.
sfp
Hits 10
Points 53.75
Automated client behavior
Traffic patterns strongly suggest automation rather than a human-operated browser.
bot
Hits 81
Points 38.26
Protocol anomaly
Request structure or protocol-level signals deviate from typical browser HTTP traffic.
proto
Hits 52
Points 32.03
SQL injection attempts
Input patterns resemble attempts to manipulate SQL queries via application parameters.
sqli
Hits 2
Points 30.00
HTTP method anomaly
Unusual or unexpected HTTP methods observed for the target endpoints.
method
Hits 3
Points 1.37

Traffic

Rollup

Daily activity (hits per day) and basic HTTP rollup counters for this ASN.

Loading activity…
Daily activity (hits per day). Total in window: .
Traffic rollup
HTTP status classes, URL diversity, and totals.
2xx
27832
3xx
1086
4xx
1811
5xx
5524
Unique URLs
12947
Total hits
51183
First seen
June 25, 2023, 3 a.m.
Last seen
Jan. 11, 2026, 1:59 a.m.

Annotators (All-time)

Heatmap of annotator × severity. Darker cells mean more volume in that band. Tip: switch to Weighted points to see what drives impact (not just noise).

Severity →
Low High
Request content resembles attempts to execute OS commands via an application.
hits 27 pts 567.49
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
28 26 1 544.54 June 25, 2023, 1:12 p.m. March 12, 2025, 8:11 p.m.
cmdi 26
30 1 1 22.95 March 12, 2025, 8:11 p.m. March 12, 2025, 8:11 p.m.
cmdi 1
Repeated authentication attempts consistent with password guessing or credential stuffing.
hits 128 pts 371.80
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 50 1 193.71 Sept. 12, 2024, 3:34 a.m. May 28, 2025, 12:47 p.m.
cred 50
12 31 1 153.45 Sept. 12, 2024, 3:34 a.m. May 28, 2025, 12:47 p.m.
cred 31
8 8 1 24.64 Dec. 3, 2024, 12:02 a.m. Dec. 3, 2024, 5:52 a.m.
cred 8
0 39 1 0.00 Sept. 12, 2024, 3:34 a.m. May 28, 2025, 12:47 p.m.
cred 39
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
hits 4651 pts 348.57
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
6 4501 1 324.07 June 25, 2023, 1:12 p.m. Jan. 2, 2026, 6:25 p.m.
ua 4501
14 69 1 15.46 Sept. 12, 2024, 8:10 p.m. May 12, 2025, 7:56 p.m.
ua 69
8 70 1 7.29 July 8, 2023, 4:18 p.m. May 22, 2025, 10:07 p.m.
ua 70
12 7 1 1.18 Oct. 7, 2024, 1:40 p.m. Jan. 28, 2025, 3:09 p.m.
ua 7
10 4 1 0.58 Aug. 5, 2023, 1:23 a.m. Sept. 20, 2025, 9:08 p.m.
ua 4
Scan velocity scan_velocity
High request rate and broad endpoint coverage suggest scanning or automated enumeration.
hits 484 pts 314.50
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 225 1 283.50 Dec. 7, 2023, 12:26 p.m. Sept. 12, 2025, 8:10 a.m.
scan_velocity 225
16 10 1 20.16 Jan. 16, 2025, 12:01 a.m. Jan. 16, 2025, 12:05 a.m.
scan_velocity 10
12 6 1 9.07 Nov. 20, 2024, 10:31 p.m. Feb. 25, 2025, 7:52 a.m.
scan_velocity 6
14 1 1 1.76 Jan. 16, 2025, 12:01 a.m. Jan. 16, 2025, 12:01 a.m.
scan_velocity 1
0 242 1 0.00 Dec. 7, 2023, 12:26 p.m. Sept. 12, 2025, 8:10 a.m.
scan_velocity 242
Requests are unusually large or shaped in a way that suggests abuse or automation.
hits 3134 pts 257.21
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
12 515 1 241.02 July 27, 2023, 6:26 p.m. Oct. 2, 2025, 11:47 p.m.
request_size 515
14 26 1 15.29 May 27, 2025, 6:51 a.m. Dec. 17, 2025, 4:30 p.m.
request_size 26
20 1 1 0.90 March 1, 2025, 7:10 p.m. March 1, 2025, 7:10 p.m.
request_size 1
0 2592 1 0.00 Dec. 25, 2024, 5:08 a.m. Dec. 17, 2025, 4:30 p.m.
request_size 2592
Requests target commonly sensitive files, configs, backups, or administrative resources.
hits 10 pts 53.75
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
40 3 1 24.29 Dec. 27, 2024, 3:24 a.m. March 8, 2025, 1:42 a.m.
sensitive_file 3
22 6 1 22.65 Dec. 7, 2023, 12:25 p.m. April 28, 2024, 3:17 a.m.
sensitive_file 6
36 1 1 6.81 March 12, 2025, 8:11 p.m. March 12, 2025, 8:11 p.m.
sensitive_file 1
Traffic patterns strongly suggest automation rather than a human-operated browser.
hits 81 pts 38.26
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 80 1 38.00 Dec. 17, 2023, 11:51 a.m. Sept. 12, 2025, 8:09 a.m.
bot 80
8 1 1 0.26 Oct. 16, 2023, 12:30 a.m. Oct. 16, 2023, 12:30 a.m.
bot 1
Request structure or protocol-level signals deviate from typical browser HTTP traffic.
hits 52 pts 32.03
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
11 52 1 32.03 Dec. 7, 2023, 12:25 p.m. Jan. 10, 2026, 12:46 a.m.
proto 52
Input patterns resemble attempts to manipulate SQL queries via application parameters.
hits 2 pts 30.00
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
20 2 1 30.00 Aug. 26, 2025, 12:11 p.m. Aug. 26, 2025, 12:11 p.m.
sqli 2
Unusual or unexpected HTTP methods observed for the target endpoints.
hits 3 pts 1.37
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
8 2 1 0.82 Dec. 14, 2024, 7:53 p.m. Dec. 14, 2024, 7:53 p.m.
method 2
10 1 1 0.55 May 6, 2025, 11 a.m. May 6, 2025, 11 a.m.
method 1

HTTP Status Breakdown

Response mix grouped by status class (2xx/3xx/4xx/5xx). Auto-loads a single aggregation and renders a donut.

Loading status mix…
Running one aggregation and rendering the chart.

Geolocation

Live geolocation and map tiles auto-load for this ASN snapshot (peer IPs with coordinates).

Loading map…

SUBNETS HELD BY THIS ISP

Derived from ISP snapshot peers (Option A). Grouped into IPv4 /24 and IPv6 /48 by default.
IPv4
IPv6
Limit
Loading subnets…

Interesting IPs

Top risky peers inside this ASN (latest snapshot). Sorted by risk score, then hits.

No peer rows available for this ASN snapshot.