DigitalOcean Referral Badge
cloud1
cloud2
cloud3
cloud4
cloud5
cloud6
← Back

ORG REPORT — mohammad khatibi · mohammad khatibi

First sighted: Dec. 9, 2024, 2 a.m. · Last sighted: March 18, 2025, 2 a.m.

Risk
100 (high)
Total hits
18254
Total errors
4441
Distinct IPs
12
Distinct ASNs
1
Top country
United Arab Emirates
Top city
Abu Dhabi
Top region
Abu Dhabi

Risk

Model: v1 Computed: 2026-01-15 08:32:00
Risk score
100
High
Risk gradient
Key drivers are enriched against the published annotator catalog when available; otherwise sensible defaults are used.
Key drivers
Sensitive file probing
Requests target commonly sensitive files, configs, backups, or administrative resources.
sfp
Hits 6862
Points 56656.60
Path traversal attempts
Request paths/parameters resemble attempts to access files outside intended directories.
trav
Hits 505
Points 4456.92
Scan velocity
High request rate and broad endpoint coverage suggest scanning or automated enumeration.
scan_velocity
Hits 2052
Points 4015.80
User-Agent anomaly
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
ua
Hits 14330
Points 2241.84
Protocol anomaly
Request structure or protocol-level signals deviate from typical browser HTTP traffic.
proto
Hits 1490
Points 1013.20
Credential brute forcing
Repeated authentication attempts consistent with password guessing or credential stuffing.
cred
Hits 131
Points 317.90
Firewall probing
Traffic behavior suggests probing of access controls and protected surfaces.
fwprobe
Hits 9
Points 72.90
Referrer abuse
Referrer patterns look manipulated, irrelevant, or inconsistent with normal navigation.
ref
Hits 10
Points 2.70
Automated client behavior
Traffic patterns strongly suggest automation rather than a human-operated browser.
bot
Hits 1
Points 0.50

Traffic

Rollup

Daily activity (hits per day) and basic HTTP rollup counters for this organization.

Loading activity…
Daily activity (hits per day). Total in window: .
Traffic rollup
HTTP status classes, URL diversity, and totals.
2xx
1248
3xx
11291
4xx
4435
5xx
6
Unique URLs
7147
Total hits
18254
First seen
Dec. 9, 2024, 2 a.m.
Last seen
March 18, 2025, 2 a.m.

Annotators (All-time)

Heatmap of annotator × severity. Darker cells mean more volume in that band. Tip: switch to Weighted points to see what drives impact (not just noise).

Severity →
Low High
Requests target commonly sensitive files, configs, backups, or administrative resources.
hits 6862 pts 56656.60
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
40 5908 1 51990.40 Dec. 9, 2024, 3:36 a.m. March 17, 2025, 8:07 a.m.
sensitive_file 5908
16 518 1 1823.36 Dec. 9, 2024, 3:36 a.m. March 17, 2025, 8:05 a.m.
sensitive_file 518
30 133 1 877.80 Dec. 19, 2024, 11:20 a.m. March 15, 2025, 4:11 a.m.
sensitive_file 133
36 106 1 839.52 Dec. 19, 2024, 11:20 a.m. March 17, 2025, 8:04 a.m.
sensitive_file 106
24 149 1 786.72 Dec. 19, 2024, 11:20 a.m. March 17, 2025, 8:05 a.m.
sensitive_file 149
44 20 1 193.60 March 10, 2025, 11:47 p.m. March 17, 2025, 8:04 a.m.
sensitive_file 20
22 25 1 121.00 Dec. 20, 2024, 8:43 a.m. March 17, 2025, 8:05 a.m.
sensitive_file 25
34 2 1 14.96 Jan. 4, 2025, 7:01 p.m. Jan. 4, 2025, 7:01 p.m.
sensitive_file 2
42 1 1 9.24 Feb. 13, 2025, 3:07 a.m. Feb. 13, 2025, 3:07 a.m.
sensitive_file 1
Request paths/parameters resemble attempts to access files outside intended directories.
hits 505 pts 4456.92
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
34 501 1 4428.84 Dec. 19, 2024, 11:20 a.m. March 17, 2025, 8:07 a.m.
trav 501
28 2 1 14.56 Jan. 4, 2025, 7:01 p.m. Jan. 4, 2025, 7:01 p.m.
trav 2
26 2 1 13.52 Jan. 4, 2025, 7:01 p.m. Jan. 4, 2025, 7:01 p.m.
trav 2
Scan velocity scan_velocity
High request rate and broad endpoint coverage suggest scanning or automated enumeration.
hits 2052 pts 4015.80
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 540 1 972.00 Dec. 9, 2024, 3:36 a.m. March 17, 2025, 8:02 a.m.
scan_velocity 540
22 102 1 403.92 Jan. 4, 2025, 9:14 p.m. March 17, 2025, 8:02 a.m.
scan_velocity 102
24 86 1 371.52 Jan. 4, 2025, 9:14 p.m. March 17, 2025, 8:02 a.m.
scan_velocity 86
36 51 1 330.48 March 17, 2025, 4 a.m. March 17, 2025, 8:07 a.m.
scan_velocity 51
16 92 1 264.96 Dec. 22, 2024, 2:45 p.m. March 17, 2025, 8:01 a.m.
scan_velocity 92
20 73 1 262.80 Dec. 22, 2024, 2:45 p.m. March 17, 2025, 8:02 a.m.
scan_velocity 73
18 81 1 262.44 Dec. 22, 2024, 2:45 p.m. March 17, 2025, 8:02 a.m.
scan_velocity 81
14 102 1 257.04 Dec. 22, 2024, 2:45 p.m. March 17, 2025, 8:01 a.m.
scan_velocity 102
12 108 1 233.28 Dec. 17, 2024, 3:33 p.m. March 17, 2025, 8 a.m.
scan_velocity 108
26 45 1 210.60 Feb. 20, 2025, 8 p.m. March 17, 2025, 8:02 a.m.
scan_velocity 45
28 31 1 156.24 Feb. 25, 2025, 1:52 a.m. March 17, 2025, 8:07 a.m.
scan_velocity 31
30 21 1 113.40 Feb. 25, 2025, 1:52 a.m. March 17, 2025, 8:07 a.m.
scan_velocity 21
32 18 1 103.68 Feb. 25, 2025, 1:52 a.m. March 17, 2025, 8:03 a.m.
scan_velocity 18
34 12 1 73.44 Feb. 25, 2025, 1:53 a.m. March 17, 2025, 8:03 a.m.
scan_velocity 12
0 690 1 0.00 Dec. 9, 2024, 3:36 a.m. March 17, 2025, 8:07 a.m.
scan_velocity 690
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
hits 14330 pts 2241.84
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
8 13056 1 2088.96 Dec. 9, 2024, 3:36 a.m. March 17, 2025, 8 a.m.
ua 13056
6 1274 1 152.88 Dec. 22, 2024, 2:45 p.m. March 15, 2025, 4:10 a.m.
ua 1274
Request structure or protocol-level signals deviate from typical browser HTTP traffic.
hits 1490 pts 1013.20
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
14 745 1 834.40 Jan. 22, 2025, 11:17 p.m. March 2, 2025, 4:21 a.m.
proto 745
3 745 1 178.80 Jan. 22, 2025, 11:17 p.m. March 2, 2025, 4:21 a.m.
proto 745
Repeated authentication attempts consistent with password guessing or credential stuffing.
hits 131 pts 317.90
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
6 37 1 122.10 Dec. 22, 2024, 2:45 p.m. March 12, 2025, 7:48 p.m.
cred 37
10 18 1 99.00 Feb. 19, 2025, 10:58 a.m. March 17, 2025, 8:04 a.m.
cred 18
8 22 1 96.80 Dec. 22, 2024, 2:45 p.m. Jan. 16, 2025, 1 p.m.
cred 22
0 54 1 0.00 Dec. 22, 2024, 2:45 p.m. March 17, 2025, 8:04 a.m.
cred 54
Traffic behavior suggests probing of access controls and protected surfaces.
hits 9 pts 72.90
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
16 6 1 43.20 March 17, 2025, 4 a.m. March 17, 2025, 8:04 a.m.
fwprobe 6
22 3 1 29.70 March 17, 2025, 4 a.m. March 17, 2025, 8:04 a.m.
fwprobe 3
Referrer patterns look manipulated, irrelevant, or inconsistent with normal navigation.
hits 10 pts 2.70
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
9 10 1 2.70 Feb. 27, 2025, 9:15 p.m. March 15, 2025, 4:11 a.m.
ref 10
Traffic patterns strongly suggest automation rather than a human-operated browser.
hits 1 pts 0.50
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 1 1 0.50 Jan. 28, 2025, 4:08 a.m. Jan. 28, 2025, 4:08 a.m.
bot 1

HTTP Status Breakdown

Response mix grouped by status class (2xx/3xx/4xx/5xx). Uses totals aggregation and renders a donut.

Loading status mix…
Running one aggregation and rendering the chart.

Geolocation

Live geolocation and map tiles auto-load for this Org snapshot (peer IPs with coordinates).

Loading map…

ASNs held by this org

Derived from IP rollups (IPReportTotal). Grouped by (asn, as_org_name).
Loading…

Interesting IPs

Top risky peers inside this org (latest snapshot). Sorted by risk score, then hits.

193.41.206.36 high
100 /100
Last seen 2025-03-18 02:00
Hits
6500
Errors
1666
Country
United Arab Emirates
ASN
AS44947
AS Org
AMWAJ ALKHYR COMMERCIAL BROKERS CO.
193.41.206.24 high
100 /100
Last seen 2025-01-13 02:00
Hits
6075
Errors
7
Country
United Arab Emirates
ASN
AS44947
AS Org
AMWAJ ALKHYR COMMERCIAL BROKERS CO.
193.41.206.176 high
84 /100
Last seen 2025-03-17 02:00
Hits
1378
Errors
721
Country
United Arab Emirates
ASN
AS44947
AS Org
AMWAJ ALKHYR COMMERCIAL BROKERS CO.
193.41.206.202 high
80 /100
Last seen 2025-03-13 02:00
Hits
1297
Errors
888
Country
United Arab Emirates
ASN
AS44947
AS Org
AMWAJ ALKHYR COMMERCIAL BROKERS CO.
193.41.206.98 high
77 /100
Last seen 2025-03-13 02:00
Hits
1483
Errors
320
Country
United Arab Emirates
ASN
AS44947
AS Org
AMWAJ ALKHYR COMMERCIAL BROKERS CO.
193.41.206.189 med
44 /100
Last seen 2025-03-16 02:00
Hits
467
Errors
226
Country
United Arab Emirates
ASN
AS44947
AS Org
AMWAJ ALKHYR COMMERCIAL BROKERS CO.
193.41.206.12 low
33 /100
Last seen 2025-03-16 02:00
Hits
273
Errors
158
Country
United Arab Emirates
ASN
AS44947
AS Org
AMWAJ ALKHYR COMMERCIAL BROKERS CO.
193.41.206.72 low
32 /100
Last seen 2025-03-12 02:00
Hits
221
Errors
134
Country
United Arab Emirates
ASN
AS44947
AS Org
AMWAJ ALKHYR COMMERCIAL BROKERS CO.
193.41.206.138 low
28 /100
Last seen 2025-03-02 02:00
Hits
332
Errors
194
Country
United Arab Emirates
ASN
AS44947
AS Org
AMWAJ ALKHYR COMMERCIAL BROKERS CO.
193.41.206.246 low
20 /100
Last seen 2025-03-06 02:00
Hits
180
Errors
108
Country
United Arab Emirates
ASN
AS44947
AS Org
AMWAJ ALKHYR COMMERCIAL BROKERS CO.
193.41.206.50 low
4 /100
Last seen 2025-02-20 02:00
Hits
14
Errors
5
Country
United Arab Emirates
ASN
AS44947
AS Org
AMWAJ ALKHYR COMMERCIAL BROKERS CO.
193.41.206.51 low
0 /100
Last seen 2025-01-29 02:00
Hits
34
Errors
14
Country
United Arab Emirates
ASN
AS44947
AS Org
AMWAJ ALKHYR COMMERCIAL BROKERS CO.