DigitalOcean Referral Badge
cloud1
cloud2
cloud3
cloud4
cloud5
cloud6
← Back

ASN REPORT — AS12430 · VODAFONE ESPANA S.A.U.

First sighted: Aug. 31, 2023, 3 a.m. · Last sighted: Dec. 1, 2025, 1:59 a.m.

Risk
3 (low)
Total hits
1169
Total errors
175
Observed IPs
135
Top country
N/A
Top city
N/A

Risk

Model: v1 Computed: 2026-01-18 11:55:05
Risk score
3
Low
Risk gradient
Key drivers are enriched against the published annotator catalog when available; otherwise sensible defaults are used.
Key drivers
Credential brute forcing
Repeated authentication attempts consistent with password guessing or credential stuffing.
cred
Hits 21
Points 64.68
User-Agent anomaly
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
ua
Hits 124
Points 9.20
Scan velocity
High request rate and broad endpoint coverage suggest scanning or automated enumeration.
scan_velocity
Hits 8
Points 5.04
Request size anomaly
Requests are unusually large or shaped in a way that suggests abuse or automation.
request_size
Hits 71
Points 4.33
HTTP method anomaly
Unusual or unexpected HTTP methods observed for the target endpoints.
method
Hits 2
Points 0.82

Traffic

Rollup

Daily activity (hits per day) and basic HTTP rollup counters for this ASN.

Loading activity…
Daily activity (hits per day). Total in window: .
Traffic rollup
HTTP status classes, URL diversity, and totals.
2xx
573
3xx
56
4xx
62
5xx
113
Unique URLs
504
Total hits
1169
First seen
Aug. 31, 2023, 3 a.m.
Last seen
Dec. 1, 2025, 1:59 a.m.

Annotators (All-time)

Heatmap of annotator × severity. Darker cells mean more volume in that band. Tip: switch to Weighted points to see what drives impact (not just noise).

Severity →
Low High
Repeated authentication attempts consistent with password guessing or credential stuffing.
hits 21 pts 64.68
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 9 1 34.98 Aug. 31, 2023, 6:41 p.m. Dec. 20, 2023, 3:34 p.m.
cred 9
12 6 1 29.70 Aug. 31, 2023, 6:41 p.m. Dec. 20, 2023, 3:34 p.m.
cred 6
0 6 1 0.00 Aug. 31, 2023, 6:41 p.m. Dec. 20, 2023, 3:34 p.m.
cred 6
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
hits 124 pts 9.20
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
6 118 1 8.50 Nov. 21, 2023, 11:05 p.m. Aug. 4, 2025, 11:36 a.m.
ua 118
8 4 1 0.42 Nov. 16, 2023, 4:41 a.m. March 15, 2025, 5:38 a.m.
ua 4
10 2 1 0.29 Feb. 13, 2024, 10:02 a.m. Feb. 13, 2024, 10:03 a.m.
ua 2
Scan velocity scan_velocity
High request rate and broad endpoint coverage suggest scanning or automated enumeration.
hits 8 pts 5.04
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 4 1 5.04 Dec. 24, 2024, midnight Dec. 24, 2024, 12:01 a.m.
scan_velocity 4
0 4 1 0.00 Dec. 24, 2024, midnight Dec. 24, 2024, 12:01 a.m.
scan_velocity 4
Requests are unusually large or shaped in a way that suggests abuse or automation.
hits 71 pts 4.33
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
12 8 1 3.74 Dec. 17, 2024, 11:07 p.m. April 8, 2025, 3:27 p.m.
request_size 8
14 1 1 0.59 Oct. 22, 2025, 11:46 a.m. Oct. 22, 2025, 11:46 a.m.
request_size 1
0 62 1 0.00 Jan. 15, 2025, 9:36 p.m. Aug. 4, 2025, 11:32 a.m.
request_size 62
Unusual or unexpected HTTP methods observed for the target endpoints.
hits 2 pts 0.82
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
8 2 1 0.82 Nov. 21, 2023, 11:05 p.m. Nov. 21, 2023, 11:05 p.m.
method 2

HTTP Status Breakdown

Response mix grouped by status class (2xx/3xx/4xx/5xx). Auto-loads a single aggregation and renders a donut.

Loading status mix…
Running one aggregation and rendering the chart.

Geolocation

Live geolocation and map tiles auto-load for this ASN snapshot (peer IPs with coordinates).

Loading map…

SUBNETS HELD BY THIS ISP

Derived from ISP snapshot peers (Option A). Grouped into IPv4 /24 and IPv6 /48 by default.
IPv4
IPv6
Limit
Loading subnets…

Interesting IPs

Top risky peers inside this ASN (latest snapshot). Sorted by risk score, then hits.

No peer rows available for this ASN snapshot.