DigitalOcean Referral Badge
cloud1
cloud2
cloud3
cloud4
cloud5
cloud6
← Back

ORG REPORT — AWS EC2 (ap-northeast-2) · aws ec2 (ap-northeast-2)

First sighted: April 30, 2023, 3 a.m. · Last sighted: Jan. 10, 2026, 2 a.m.

Risk
35 (med)
Total hits
656
Total errors
148
Distinct IPs
41
Distinct ASNs
1
Top country
South Korea
Top city
Seoul
Top region
Seoul

Risk

Model: v1 Computed: 2026-01-15 08:32:00
Risk score
35
Medium
Risk gradient
Key drivers are enriched against the published annotator catalog when available; otherwise sensible defaults are used.
Key drivers
Sensitive file probing
Requests target commonly sensitive files, configs, backups, or administrative resources.
sfp
Hits 126
Points 836.88
Path traversal attempts
Request paths/parameters resemble attempts to access files outside intended directories.
trav
Hits 15
Points 107.64
Scan velocity
High request rate and broad endpoint coverage suggest scanning or automated enumeration.
scan_velocity
Hits 46
Points 78.12
Command injection attempts
Request content resembles attempts to execute OS commands via an application.
cmdi
Hits 2
Points 42.50
Credential brute forcing
Repeated authentication attempts consistent with password guessing or credential stuffing.
cred
Hits 3
Points 9.90
Automated client behavior
Traffic patterns strongly suggest automation rather than a human-operated browser.
bot
Hits 7
Points 3.20
User-Agent anomaly
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
ua
Hits 18
Points 2.80
Protocol anomaly
Request structure or protocol-level signals deviate from typical browser HTTP traffic.
proto
Hits 3
Points 2.16
HTTP method anomaly
Unusual or unexpected HTTP methods observed for the target endpoints.
method
Hits 1
Points 0.60

Traffic

Rollup

Daily activity (hits per day) and basic HTTP rollup counters for this organization.

Loading activity…
Daily activity (hits per day). Total in window: .
Traffic rollup
HTTP status classes, URL diversity, and totals.
2xx
118
3xx
377
4xx
147
5xx
1
Unique URLs
340
Total hits
656
First seen
April 30, 2023, 3 a.m.
Last seen
Jan. 10, 2026, 2 a.m.

Annotators (All-time)

Heatmap of annotator × severity. Darker cells mean more volume in that band. Tip: switch to Weighted points to see what drives impact (not just noise).

Severity →
Low High
Requests target commonly sensitive files, configs, backups, or administrative resources.
hits 126 pts 836.88
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
40 65 1 572.00 April 30, 2023, 8:44 a.m. Nov. 15, 2025, 9:58 p.m.
sensitive_file 65
16 40 1 140.80 Nov. 15, 2025, 9:58 p.m. Nov. 15, 2025, 9:58 p.m.
sensitive_file 40
24 15 1 79.20 Sept. 30, 2023, 2:08 a.m. Oct. 14, 2025, 8:57 p.m.
sensitive_file 15
34 6 1 44.88 Nov. 10, 2024, 10:20 a.m. Nov. 10, 2024, 10:22 a.m.
sensitive_file 6
Request paths/parameters resemble attempts to access files outside intended directories.
hits 15 pts 107.64
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
28 6 1 43.68 Nov. 10, 2024, 10:20 a.m. Nov. 10, 2024, 10:22 a.m.
trav 6
26 6 1 40.56 Nov. 10, 2024, 10:20 a.m. Nov. 10, 2024, 10:22 a.m.
trav 6
30 3 1 23.40 Nov. 10, 2024, 10:20 a.m. Nov. 10, 2024, 10:20 a.m.
trav 3
Scan velocity scan_velocity
High request rate and broad endpoint coverage suggest scanning or automated enumeration.
hits 46 pts 78.12
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
22 6 1 23.76 Nov. 10, 2024, 10:21 a.m. Nov. 10, 2024, 10:22 a.m.
scan_velocity 6
10 7 1 12.60 Oct. 16, 2023, 3:38 p.m. Nov. 15, 2025, 9:58 p.m.
scan_velocity 7
16 4 1 11.52 Feb. 20, 2025, 5:33 a.m. Nov. 15, 2025, 9:58 p.m.
scan_velocity 4
14 4 1 10.08 Feb. 20, 2025, 5:33 a.m. Nov. 15, 2025, 9:58 p.m.
scan_velocity 4
20 2 1 7.20 Nov. 10, 2024, 10:21 a.m. Nov. 10, 2024, 10:21 a.m.
scan_velocity 2
12 3 1 6.48 Feb. 20, 2025, 5:33 a.m. Nov. 15, 2025, 9:58 p.m.
scan_velocity 3
18 2 1 6.48 Nov. 10, 2024, 10:20 a.m. Nov. 10, 2024, 10:20 a.m.
scan_velocity 2
0 18 1 0.00 Oct. 16, 2023, 3:38 p.m. Nov. 15, 2025, 9:58 p.m.
scan_velocity 18
Request content resembles attempts to execute OS commands via an application.
hits 2 pts 42.50
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
28 1 1 23.80 Nov. 10, 2024, 10:22 a.m. Nov. 10, 2024, 10:22 a.m.
cmdi 1
22 1 1 18.70 Nov. 10, 2024, 10:22 a.m. Nov. 10, 2024, 10:22 a.m.
cmdi 1
Repeated authentication attempts consistent with password guessing or credential stuffing.
hits 3 pts 9.90
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 1 1 5.50 Oct. 18, 2023, 11:25 p.m. Oct. 18, 2023, 11:25 p.m.
cred 1
8 1 1 4.40 Oct. 18, 2023, 11:25 p.m. Oct. 18, 2023, 11:25 p.m.
cred 1
0 1 1 0.00 Oct. 18, 2023, 11:25 p.m. Oct. 18, 2023, 11:25 p.m.
cred 1
Traffic patterns strongly suggest automation rather than a human-operated browser.
hits 7 pts 3.20
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 4 1 2.00 Oct. 16, 2023, 3:38 p.m. Sept. 8, 2024, 5:49 p.m.
bot 4
8 3 1 1.20 Oct. 18, 2023, 11:24 p.m. Oct. 18, 2023, 11:25 p.m.
bot 3
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
hits 18 pts 2.80
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
8 7 1 1.12 Nov. 10, 2024, 10:20 a.m. Sept. 11, 2025, 2:22 p.m.
ua 7
6 8 1 0.96 Nov. 10, 2024, 10:20 a.m. Dec. 29, 2024, 8:31 a.m.
ua 8
12 3 1 0.72 May 31, 2024, 5:43 p.m. Sept. 8, 2024, 5:49 p.m.
ua 3
Request structure or protocol-level signals deviate from typical browser HTTP traffic.
hits 3 pts 2.16
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
12 2 1 1.92 Nov. 10, 2024, 10:20 a.m. Nov. 10, 2024, 10:20 a.m.
proto 2
3 1 1 0.24 Nov. 10, 2024, 10:20 a.m. Nov. 10, 2024, 10:20 a.m.
proto 1
Unusual or unexpected HTTP methods observed for the target endpoints.
hits 1 pts 0.60
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 1 1 0.60 Sept. 11, 2025, 2:22 p.m. Sept. 11, 2025, 2:22 p.m.
method 1

HTTP Status Breakdown

Response mix grouped by status class (2xx/3xx/4xx/5xx). Uses totals aggregation and renders a donut.

Loading status mix…
Running one aggregation and rendering the chart.

Geolocation

Live geolocation and map tiles auto-load for this Org snapshot (peer IPs with coordinates).

Loading map…

ASNs held by this org

Derived from IP rollups (IPReportTotal). Grouped by (asn, as_org_name).
Loading…

Interesting IPs

Top risky peers inside this org (latest snapshot). Sorted by risk score, then hits.

43.201.96.124 low
25 /100
Last seen 2025-11-16 02:00
Hits
81
Errors
49
Country
South Korea
ASN
AS16509
AS Org
Amazon.com, Inc.
43.201.9.25 low
9 /100
Last seen 2024-11-11 02:00
Hits
47
Errors
44
Country
South Korea
ASN
AS16509
AS Org
Amazon.com, Inc.
52.78.247.231 low
2 /100
Last seen 2023-11-16 02:00
Hits
16
Errors
8
Country
South Korea
ASN
AS16509
AS Org
Amazon.com, Inc.
43.202.60.51 low
1 /100
Last seen 2025-02-21 02:00
Hits
336
Errors
0
Country
South Korea
ASN
AS16509
AS Org
Amazon.com, Inc.
3.34.59.159 low
0 /100
Last seen 2024-09-09 03:00
Hits
32
Errors
0
Country
South Korea
ASN
AS16509
AS Org
Amazon.com, Inc.
43.201.44.165 low
0 /100
Last seen 2023-10-17 03:00
Hits
30
Errors
17
Country
South Korea
ASN
AS16509
AS Org
Amazon.com, Inc.
3.38.211.197 low
0 /100
Last seen 2025-09-09 03:00
Hits
12
Errors
0
Country
South Korea
ASN
AS16509
AS Org
Amazon.com, Inc.
52.78.49.41 low
0 /100
Last seen 2024-12-30 02:00
Hits
12
Errors
6
Country
South Korea
ASN
AS16509
AS Org
Amazon.com, Inc.
3.36.44.142 low
0 /100
Last seen 2024-11-23 02:00
Hits
12
Errors
1
Country
South Korea
ASN
AS16509
AS Org
Amazon.com, Inc.
15.164.179.101 low
0 /100
Last seen 2025-09-30 03:00
Hits
10
Errors
0
Country
South Korea
ASN
AS16509
AS Org
Amazon.com, Inc.
3.38.134.108 low
0 /100
Last seen 2024-09-16 03:00
Hits
10
Errors
0
Country
South Korea
ASN
AS16509
AS Org
Amazon.com, Inc.
43.203.115.211 low
0 /100
Last seen 2025-09-12 03:00
Hits
6
Errors
3
Country
South Korea
ASN
AS16509
AS Org
Amazon.com, Inc.
43.203.157.60 low
0 /100
Last seen 2025-09-12 03:00
Hits
4
Errors
2
Country
South Korea
ASN
AS16509
AS Org
Amazon.com, Inc.
52.78.156.178 low
0 /100
Last seen 2025-09-09 03:00
Hits
4
Errors
0
Country
South Korea
ASN
AS16509
AS Org
Amazon.com, Inc.
15.165.77.128 low
0 /100
Last seen 2025-10-04 03:00
Hits
3
Errors
0
Country
South Korea
ASN
AS16509
AS Org
Amazon.com, Inc.
3.36.130.238 low
0 /100
Last seen 2025-10-03 03:00
Hits
3
Errors
1
Country
South Korea
ASN
AS16509
AS Org
Amazon.com, Inc.
3.37.61.23 low
0 /100
Last seen 2025-09-12 03:00
Hits
3
Errors
2
Country
South Korea
ASN
AS16509
AS Org
Amazon.com, Inc.
52.78.192.211 low
0 /100
Last seen 2025-09-12 03:00
Hits
3
Errors
1
Country
South Korea
ASN
AS16509
AS Org
Amazon.com, Inc.
16.184.13.84 low
0 /100
Last seen 2025-09-08 03:00
Hits
3
Errors
1
Country
South Korea
ASN
AS16509
AS Org
Amazon.com, Inc.
3.35.51.21 low
0 /100
Last seen 2023-10-19 03:00
Hits
3
Errors
0
Country
South Korea
ASN
AS16509
AS Org
Amazon.com, Inc.
3.35.157.56 low
0 /100
Last seen 2026-01-10 02:00
Hits
2
Errors
1
Country
South Korea
ASN
AS16509
AS Org
Amazon.com, Inc.
15.165.19.25 low
0 /100
Last seen 2025-10-04 03:00
Hits
2
Errors
0
Country
South Korea
ASN
AS16509
AS Org
Amazon.com, Inc.
3.36.106.107 low
0 /100
Last seen 2025-09-10 03:00
Hits
2
Errors
2
Country
South Korea
ASN
AS16509
AS Org
Amazon.com, Inc.
3.36.52.147 low
0 /100
Last seen 2025-09-09 03:00
Hits
2
Errors
0
Country
South Korea
ASN
AS16509
AS Org
Amazon.com, Inc.
43.202.45.124 low
0 /100
Last seen 2023-11-19 02:00
Hits
2
Errors
1
Country
South Korea
ASN
AS16509
AS Org
Amazon.com, Inc.
43.203.163.65 low
0 /100
Last seen 2025-10-15 03:00
Hits
1
Errors
1
Country
South Korea
ASN
AS16509
AS Org
Amazon.com, Inc.
3.35.5.186 low
0 /100
Last seen 2025-10-04 03:00
Hits
1
Errors
0
Country
South Korea
ASN
AS16509
AS Org
Amazon.com, Inc.
15.164.240.240 low
0 /100
Last seen 2025-10-04 03:00
Hits
1
Errors
0
Country
South Korea
ASN
AS16509
AS Org
Amazon.com, Inc.
16.184.41.231 low
0 /100
Last seen 2025-10-04 03:00
Hits
1
Errors
0
Country
South Korea
ASN
AS16509
AS Org
Amazon.com, Inc.
43.200.252.227 low
0 /100
Last seen 2025-10-04 03:00
Hits
1
Errors
0
Country
South Korea
ASN
AS16509
AS Org
Amazon.com, Inc.
54.180.249.239 low
0 /100
Last seen 2025-10-04 03:00
Hits
1
Errors
0
Country
South Korea
ASN
AS16509
AS Org
Amazon.com, Inc.
3.38.209.205 low
0 /100
Last seen 2025-10-02 03:00
Hits
1
Errors
1
Country
South Korea
ASN
AS16509
AS Org
Amazon.com, Inc.
16.184.13.178 low
0 /100
Last seen 2025-09-30 03:00
Hits
1
Errors
1
Country
South Korea
ASN
AS16509
AS Org
Amazon.com, Inc.
3.38.201.185 low
0 /100
Last seen 2025-09-29 03:00
Hits
1
Errors
1
Country
South Korea
ASN
AS16509
AS Org
Amazon.com, Inc.
52.78.240.244 low
0 /100
Last seen 2025-09-10 03:00
Hits
1
Errors
0
Country
South Korea
ASN
AS16509
AS Org
Amazon.com, Inc.
43.202.99.40 low
0 /100
Last seen 2025-09-09 03:00
Hits
1
Errors
1
Country
South Korea
ASN
AS16509
AS Org
Amazon.com, Inc.
43.203.145.2 low
0 /100
Last seen 2025-09-09 03:00
Hits
1
Errors
1
Country
South Korea
ASN
AS16509
AS Org
Amazon.com, Inc.
13.124.7.0 low
0 /100
Last seen 2023-09-30 03:00
Hits
1
Errors
1
Country
South Korea
ASN
AS16509
AS Org
Amazon.com, Inc.
15.165.180.3 low
0 /100
Last seen 2023-07-11 03:00
Hits
1
Errors
0
Country
South Korea
ASN
AS16509
AS Org
Amazon.com, Inc.
43.200.4.140 low
0 /100
Last seen 2023-05-01 03:00
Hits
1
Errors
1
Country
South Korea
ASN
AS16509
AS Org
Amazon.com, Inc.
43.200.191.168 low
0 /100
Last seen 2023-05-01 03:00
Hits
1
Errors
1
Country
South Korea
ASN
AS16509
AS Org
Amazon.com, Inc.