DigitalOcean Referral Badge
cloud1
cloud2
cloud3
cloud4
cloud5
cloud6
← Back

CITY REPORT — Kwai Chung / Tsuen Wan District / Hong Kong · Kwai Chung / Tsuen Wan District / Hong Kong

First sighted: July 26, 2023, 3 a.m. · Last sighted: Oct. 6, 2025, 3 a.m.

Risk
30 (low)
Total hits
257
Total errors
187
Distinct IPs
10
Distinct ASNs
4
Country
Hong Kong
Region
Tsuen Wan District
City
Kwai Chung

Risk

Model: v1 Computed: 2026-01-15 09:35:10
Risk score
30
Risk gradient
Key drivers are enriched against the published annotator catalog when available; otherwise sensible defaults are used.
Key drivers
Path traversal attempts
Request paths/parameters resemble attempts to access files outside intended directories.
trav
Hits 97
Points 700.44
Command injection attempts
Request content resembles attempts to execute OS commands via an application.
cmdi
Hits 14
Points 297.50
Sensitive file probing
Requests target commonly sensitive files, configs, backups, or administrative resources.
sfp
Hits 37
Points 277.20
Scan velocity
High request rate and broad endpoint coverage suggest scanning or automated enumeration.
scan_velocity
Hits 44
Points 106.20
SQL injection attempts
Input patterns resemble attempts to manipulate SQL queries via application parameters.
sqli
Hits 6
Points 90.00
Firewall probing
Traffic behavior suggests probing of access controls and protected surfaces.
fwprobe
Hits 1
Points 15.30
Protocol anomaly
Request structure or protocol-level signals deviate from typical browser HTTP traffic.
proto
Hits 19
Points 14.64
User-Agent anomaly
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
ua
Hits 31
Points 4.60

Traffic

Rollup

Daily activity (hits per day) and basic HTTP rollup counters for this city.

Loading activity…
Daily activity (hits per day). Total in window: .
Traffic rollup
HTTP status classes, URL diversity, and totals.
2xx
2
3xx
56
4xx
187
5xx
0
Unique URLs
185
Total hits
257
First seen
July 26, 2023, 3 a.m.
Last seen
Oct. 6, 2025, 3 a.m.

Annotators (All-time)

Heatmap of annotator × severity. Darker cells mean more volume in that band. Tip: switch to Weighted points to see what drives impact (not just noise).

Severity →
Low High
Request paths/parameters resemble attempts to access files outside intended directories.
hits 97 pts 700.44
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
28 36 1 262.08 Sept. 16, 2024, 10:26 p.m. Oct. 5, 2025, 5:50 p.m.
trav 36
26 36 1 243.36 Sept. 16, 2024, 10:26 p.m. Oct. 5, 2025, 5:50 p.m.
trav 36
30 25 1 195.00 Sept. 16, 2024, 10:26 p.m. Oct. 5, 2025, 5:50 p.m.
trav 25
Request content resembles attempts to execute OS commands via an application.
hits 14 pts 297.50
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
28 7 1 166.60 Sept. 24, 2024, 4:45 p.m. April 25, 2025, 6:43 a.m.
cmdi 7
22 7 1 130.90 Sept. 24, 2024, 4:45 p.m. April 25, 2025, 6:43 a.m.
cmdi 7
Requests target commonly sensitive files, configs, backups, or administrative resources.
hits 37 pts 277.20
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
34 36 1 269.28 Sept. 16, 2024, 10:26 p.m. Oct. 5, 2025, 5:50 p.m.
sensitive_file 36
36 1 1 7.92 April 25, 2025, 6:43 a.m. April 25, 2025, 6:43 a.m.
sensitive_file 1
Scan velocity scan_velocity
High request rate and broad endpoint coverage suggest scanning or automated enumeration.
hits 44 pts 106.20
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
22 18 1 71.28 Sept. 24, 2024, 4:45 p.m. Nov. 15, 2024, 8:06 p.m.
scan_velocity 18
20 4 1 14.40 Sept. 24, 2024, 4:44 p.m. Oct. 3, 2024, 10:38 p.m.
scan_velocity 4
18 4 1 12.96 Sept. 24, 2024, 4:44 p.m. Oct. 3, 2024, 10:38 p.m.
scan_velocity 4
16 2 1 5.76 Sept. 24, 2024, 4:44 p.m. Sept. 24, 2024, 4:44 p.m.
scan_velocity 2
10 1 1 1.80 Nov. 15, 2024, 8:03 p.m. Nov. 15, 2024, 8:03 p.m.
scan_velocity 1
0 15 1 0.00 Sept. 24, 2024, 4:44 p.m. Nov. 15, 2024, 8:06 p.m.
scan_velocity 15
Input patterns resemble attempts to manipulate SQL queries via application parameters.
hits 6 pts 90.00
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
24 2 1 48.00 April 25, 2025, 6:43 a.m. April 25, 2025, 6:43 a.m.
sqli 2
8 3 1 24.00 April 25, 2025, 6:43 a.m. April 25, 2025, 6:43 a.m.
sqli 3
18 1 1 18.00 April 25, 2025, 6:43 a.m. April 25, 2025, 6:43 a.m.
sqli 1
Traffic behavior suggests probing of access controls and protected surfaces.
hits 1 pts 15.30
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
34 1 1 15.30 July 26, 2023, 4:48 a.m. July 26, 2023, 4:48 a.m.
fwprobe 1
Request structure or protocol-level signals deviate from typical browser HTTP traffic.
hits 19 pts 14.64
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
12 14 1 13.44 Sept. 16, 2024, 10:26 p.m. Oct. 5, 2025, 5:50 p.m.
proto 14
3 5 1 1.20 Sept. 16, 2024, 10:26 p.m. Nov. 15, 2024, 8:02 p.m.
proto 5
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
hits 31 pts 4.60
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
8 18 1 2.88 Sept. 16, 2024, 10:26 p.m. Oct. 5, 2025, 5:50 p.m.
ua 18
6 12 1 1.44 Sept. 16, 2024, 10:26 p.m. July 23, 2025, 1:22 p.m.
ua 12
14 1 1 0.28 July 26, 2023, 4:48 a.m. July 26, 2023, 4:48 a.m.
ua 1

HTTP Status Breakdown

Response mix grouped by status class (2xx/3xx/4xx/5xx). Uses totals aggregation and renders a donut.

Loading status mix…
Running one aggregation and rendering the chart.

Geolocation

Live geolocation and map tiles auto-load for this Org snapshot (peer IPs with coordinates).

Loading map…

Interesting IPs

Top risky peers inside this city (latest snapshot). Sorted by risk score, then hits.

39.109.126.254 low
22 /100
Last seen 2024-10-04 03:00
Hits
99
Errors
90
Country
Hong Kong
ASN
AS142403
AS Org
YISU CLOUD LTD
103.100.209.11 low
15 /100
Last seen 2024-11-16 02:00
Hits
94
Errors
88
Country
Hong Kong
ASN
AS142403
AS Org
YISU CLOUD LTD
103.241.74.172 low
9 /100
Last seen 2025-04-26 03:00
Hits
39
Errors
0
Country
Hong Kong
ASN
AS152194
AS Org
CTG Server Limited
39.109.122.51 low
7 /100
Last seen 2024-11-10 02:00
Hits
8
Errors
4
Country
Hong Kong
ASN
AS142403
AS Org
YISU CLOUD LTD
103.100.211.174 low
2 /100
Last seen 2025-10-06 03:00
Hits
3
Errors
2
Country
Hong Kong
ASN
AS142403
AS Org
YISU CLOUD LTD
39.109.114.176 low
1 /100
Last seen 2023-07-27 03:00
Hits
2
Errors
0
Country
Hong Kong
ASN
AS142403
AS Org
YISU CLOUD LTD
103.241.72.84 low
0 /100
Last seen 2025-07-24 03:00
Hits
7
Errors
3
Country
Hong Kong
ASN
AS152194
AS Org
CTG Server Limited
103.27.108.176 low
0 /100
Last seen 2023-09-02 03:00
Hits
3
Errors
0
Country
Hong Kong
ASN
AS132883
AS Org
TOPWAY GLOBAL LIMITED
183.178.173.56 low
0 /100
Last seen 2025-04-24 03:00
Hits
1
Errors
0
Country
Hong Kong
ASN
AS9269
AS Org
Hong Kong Broadband Network Ltd.
39.109.113.97 low
0 /100
Last seen 2024-11-14 02:00
Hits
1
Errors
0
Country
Hong Kong
ASN
AS142403
AS Org
YISU CLOUD LTD