DigitalOcean Referral Badge
cloud1
cloud2
cloud3
cloud4
cloud5
cloud6
← Back

ORG REPORT — Code 200, UAB · code 200, uab

First sighted: Sept. 20, 2023, 3 a.m. · Last sighted: Dec. 18, 2025, 2 a.m.

Risk
16 (low)
Total hits
3268
Total errors
1908
Distinct IPs
660
Distinct ASNs
1
Top country
United Kingdom
Top city
London
Top region
England

Risk

Model: v1 Computed: 2026-01-29 19:10:08
Risk score
16
Low
Risk gradient
Key drivers are enriched against the published annotator catalog when available; otherwise sensible defaults are used.
Key drivers
Scan velocity
High request rate and broad endpoint coverage suggest scanning or automated enumeration.
scan_velocity
Hits 169
Points 153.72
Protocol anomaly
Request structure or protocol-level signals deviate from typical browser HTTP traffic.
proto
Hits 148
Points 128.96
Automated client behavior
Traffic patterns strongly suggest automation rather than a human-operated browser.
bot
Hits 291
Points 116.40
User-Agent anomaly
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
ua
Hits 184
Points 22.08
Credential brute forcing
Repeated authentication attempts consistent with password guessing or credential stuffing.
cred
Hits 6
Points 19.80

Traffic

Rollup

Daily activity (hits per day) and basic HTTP rollup counters for this organization.

Loading activity…
Daily activity (hits per day). Total in window: .
Traffic rollup
HTTP status classes, URL diversity, and totals.
2xx
1131
3xx
43
4xx
1881
5xx
27
Unique URLs
1423
Total hits
3268
First seen
Sept. 20, 2023, 3 a.m.
Last seen
Dec. 18, 2025, 2 a.m.

Annotators (All-time)

Heatmap of annotator × severity. Darker cells mean more volume in that band. Tip: switch to Weighted points to see what drives impact (not just noise).

Severity →
Low High
Scan velocity scan_velocity
High request rate and broad endpoint coverage suggest scanning or automated enumeration.
hits 169 pts 153.72
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 83 1 149.40 Oct. 14, 2024, 6:55 a.m. Sept. 30, 2025, 9:12 p.m.
scan_velocity 83
12 2 1 4.32 Aug. 6, 2025, 10:56 a.m. Aug. 6, 2025, 10:56 a.m.
scan_velocity 2
0 84 1 0.00 Oct. 14, 2024, 6:55 a.m. Sept. 30, 2025, 9:12 p.m.
scan_velocity 84
Request structure or protocol-level signals deviate from typical browser HTTP traffic.
hits 148 pts 128.96
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
11 146 1 128.48 Nov. 23, 2024, 8:18 a.m. Feb. 23, 2025, 2:52 p.m.
proto 146
3 2 1 0.48 Dec. 21, 2024, 8:59 a.m. Dec. 21, 2024, 8:59 a.m.
proto 2
Traffic patterns strongly suggest automation rather than a human-operated browser.
hits 291 pts 116.40
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
8 291 1 116.40 Sept. 6, 2024, 1:51 a.m. Jan. 3, 2025, 1:45 a.m.
bot 291
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
hits 184 pts 22.08
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
6 184 1 22.08 Oct. 2, 2023, 11:33 p.m. Feb. 2, 2025, 6:31 p.m.
ua 184
Repeated authentication attempts consistent with password guessing or credential stuffing.
hits 6 pts 19.80
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 2 1 11.00 Oct. 2, 2023, 11:32 p.m. Oct. 2, 2023, 11:32 p.m.
cred 2
8 2 1 8.80 Oct. 2, 2023, 11:32 p.m. Oct. 2, 2023, 11:32 p.m.
cred 2
0 2 1 0.00 Oct. 2, 2023, 11:32 p.m. Oct. 2, 2023, 11:32 p.m.
cred 2

HTTP Status Breakdown

Response mix grouped by status class (2xx/3xx/4xx/5xx). Uses totals aggregation and renders a donut.

Loading status mix…
Running one aggregation and rendering the chart.

Geolocation

Live geolocation and map tiles auto-load for this Org snapshot (peer IPs with coordinates).

Loading map…

ASNs held by this org

Derived from IP rollups (IPReportTotal). Grouped by (asn, as_org_name).
Loading…

Interesting IPs

Top risky peers inside this org (latest snapshot). Sorted by risk score, then hits.

No matching IP rows available for this org.