DigitalOcean Referral Badge
cloud1
cloud2
cloud3
cloud4
cloud5
cloud6
← Back

ASN REPORT — AS9299 · Philippine Long Distance Telephone Company

First sighted: July 8, 2023, 3 a.m. · Last sighted: Jan. 10, 2026, 1:59 a.m.

Risk
55 (med)
Total hits
5557
Total errors
1018
Observed IPs
976
Top country
N/A
Top city
N/A

Risk

Model: v1 Computed: 2026-01-18 11:55:16
Risk score
55
Medium
Risk gradient
Key drivers are enriched against the published annotator catalog when available; otherwise sensible defaults are used.
Key drivers
Credential brute forcing
Repeated authentication attempts consistent with password guessing or credential stuffing.
cred
Hits 647
Points 1970.49
User-Agent anomaly
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
ua
Hits 204
Points 16.29
Sensitive file probing
Requests target commonly sensitive files, configs, backups, or administrative resources.
sfp
Hits 2
Points 16.19
Request size anomaly
Requests are unusually large or shaped in a way that suggests abuse or automation.
request_size
Hits 312
Points 16.03
Scan velocity
High request rate and broad endpoint coverage suggest scanning or automated enumeration.
scan_velocity
Hits 8
Points 5.04

Traffic

Rollup

Daily activity (hits per day) and basic HTTP rollup counters for this ASN.

Loading activity…
Daily activity (hits per day). Total in window: .
Traffic rollup
HTTP status classes, URL diversity, and totals.
2xx
3124
3xx
519
4xx
804
5xx
214
Unique URLs
2411
Total hits
5557
First seen
July 8, 2023, 3 a.m.
Last seen
Jan. 10, 2026, 1:59 a.m.

Annotators (All-time)

Heatmap of annotator × severity. Darker cells mean more volume in that band. Tip: switch to Weighted points to see what drives impact (not just noise).

Severity →
Low High
Repeated authentication attempts consistent with password guessing or credential stuffing.
hits 647 pts 1970.49
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 263 1 1020.36 Dec. 20, 2023, 3:13 p.m. March 7, 2025, 11:42 p.m.
cred 263
12 190 1 940.50 Dec. 20, 2023, 3:13 p.m. March 7, 2025, 11:42 p.m.
cred 190
14 1 1 6.55 May 22, 2024, 7:19 a.m. May 22, 2024, 7:19 a.m.
cred 1
8 1 1 3.08 May 22, 2024, 7:19 a.m. May 22, 2024, 7:19 a.m.
cred 1
0 192 1 0.00 Dec. 20, 2023, 3:13 p.m. March 7, 2025, 11:42 p.m.
cred 192
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
hits 204 pts 16.29
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
6 186 1 13.39 Jan. 14, 2024, 9:56 a.m. Dec. 31, 2025, 2:30 p.m.
ua 186
12 16 1 2.69 July 26, 2025, 4:11 a.m. Sept. 17, 2025, 1:26 p.m.
ua 16
8 2 1 0.21 March 22, 2025, 6:13 a.m. March 22, 2025, 6:13 a.m.
ua 2
Requests target commonly sensitive files, configs, backups, or administrative resources.
hits 2 pts 16.19
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
40 2 1 16.19 July 8, 2023, 7:10 a.m. July 9, 2023, 8:23 p.m.
sensitive_file 2
Requests are unusually large or shaped in a way that suggests abuse or automation.
hits 312 pts 16.03
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
12 33 1 15.44 Dec. 23, 2024, 12:55 p.m. Aug. 12, 2025, 2:29 p.m.
request_size 33
14 1 1 0.59 Nov. 6, 2025, 11:44 a.m. Nov. 6, 2025, 11:44 a.m.
request_size 1
0 278 1 0.00 Dec. 25, 2024, 3:24 p.m. Oct. 14, 2025, 10:41 a.m.
request_size 278
Scan velocity scan_velocity
High request rate and broad endpoint coverage suggest scanning or automated enumeration.
hits 8 pts 5.04
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 4 1 5.04 Nov. 19, 2024, 6:56 p.m. March 13, 2025, 4:38 p.m.
scan_velocity 4
0 4 1 0.00 Nov. 19, 2024, 6:56 p.m. March 13, 2025, 4:38 p.m.
scan_velocity 4

HTTP Status Breakdown

Response mix grouped by status class (2xx/3xx/4xx/5xx). Auto-loads a single aggregation and renders a donut.

Loading status mix…
Running one aggregation and rendering the chart.

Geolocation

Live geolocation and map tiles auto-load for this ASN snapshot (peer IPs with coordinates).

Loading map…

SUBNETS HELD BY THIS ISP

Derived from ISP snapshot peers (Option A). Grouped into IPv4 /24 and IPv6 /48 by default.
IPv4
IPv6
Limit
Loading subnets…

Interesting IPs

Top risky peers inside this ASN (latest snapshot). Sorted by risk score, then hits.

No peer rows available for this ASN snapshot.