DigitalOcean Referral Badge
cloud1
cloud2
cloud3
cloud4
cloud5
cloud6
← Back

ASN REPORT — AS17072 · TOTAL PLAY TELECOMUNICACIONES SA DE CV

First sighted: Dec. 20, 2023, 2 a.m. · Last sighted: Jan. 11, 2026, 1:59 a.m.

Risk
5 (low)
Total hits
2966
Total errors
562
Observed IPs
1961
Top country
N/A
Top city
N/A

Risk

Model: v1 Computed: 2026-01-18 11:54:44
Risk score
5
Low
Risk gradient
Key drivers are enriched against the published annotator catalog when available; otherwise sensible defaults are used.
Key drivers
Credential brute forcing
Repeated authentication attempts consistent with password guessing or credential stuffing.
cred
Hits 37
Points 112.64
User-Agent anomaly
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
ua
Hits 60
Points 4.90
Request size anomaly
Requests are unusually large or shaped in a way that suggests abuse or automation.
request_size
Hits 104
Points 3.64
Automated client behavior
Traffic patterns strongly suggest automation rather than a human-operated browser.
bot
Hits 3
Points 1.42
Scan velocity
High request rate and broad endpoint coverage suggest scanning or automated enumeration.
scan_velocity
Hits 2
Points 1.26

Traffic

Rollup

Daily activity (hits per day) and basic HTTP rollup counters for this ASN.

Loading activity…
Daily activity (hits per day). Total in window: .
Traffic rollup
HTTP status classes, URL diversity, and totals.
2xx
1506
3xx
736
4xx
502
5xx
60
Unique URLs
2285
Total hits
2966
First seen
Dec. 20, 2023, 2 a.m.
Last seen
Jan. 11, 2026, 1:59 a.m.

Annotators (All-time)

Heatmap of annotator × severity. Darker cells mean more volume in that band. Tip: switch to Weighted points to see what drives impact (not just noise).

Severity →
Low High
Repeated authentication attempts consistent with password guessing or credential stuffing.
hits 37 pts 112.64
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 15 1 58.19 Dec. 20, 2023, 3:11 p.m. Dec. 7, 2024, 11:37 a.m.
cred 15
12 11 1 54.45 Dec. 20, 2023, 3:11 p.m. Dec. 7, 2024, 11:37 a.m.
cred 11
0 11 1 0.00 Dec. 20, 2023, 3:11 p.m. Dec. 7, 2024, 11:37 a.m.
cred 11
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
hits 60 pts 4.90
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
6 42 1 3.02 May 22, 2024, 8:17 a.m. Jan. 2, 2026, 6:25 p.m.
ua 42
8 18 1 1.87 May 20, 2024, 10:20 p.m. Nov. 6, 2025, 11:06 a.m.
ua 18
Requests are unusually large or shaped in a way that suggests abuse or automation.
hits 104 pts 3.64
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
12 4 1 1.87 Jan. 10, 2025, 8:09 a.m. Aug. 27, 2025, 10:09 p.m.
request_size 4
14 3 1 1.76 Aug. 1, 2025, 4:31 a.m. Nov. 28, 2025, 7:48 p.m.
request_size 3
0 97 1 0.00 Jan. 10, 2025, 8:09 a.m. Oct. 7, 2025, 10:04 a.m.
request_size 97
Traffic patterns strongly suggest automation rather than a human-operated browser.
hits 3 pts 1.42
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 3 1 1.42 Aug. 1, 2025, 4:58 a.m. Sept. 14, 2025, 3:06 a.m.
bot 3
Scan velocity scan_velocity
High request rate and broad endpoint coverage suggest scanning or automated enumeration.
hits 2 pts 1.26
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 1 1 1.26 Aug. 1, 2025, 10:32 p.m. Aug. 1, 2025, 10:32 p.m.
scan_velocity 1
0 1 1 0.00 Aug. 1, 2025, 10:32 p.m. Aug. 1, 2025, 10:32 p.m.
scan_velocity 1

HTTP Status Breakdown

Response mix grouped by status class (2xx/3xx/4xx/5xx). Auto-loads a single aggregation and renders a donut.

Loading status mix…
Running one aggregation and rendering the chart.

Geolocation

Live geolocation and map tiles auto-load for this ASN snapshot (peer IPs with coordinates).

Loading map…

SUBNETS HELD BY THIS ISP

Derived from ISP snapshot peers (Option A). Grouped into IPv4 /24 and IPv6 /48 by default.
IPv4
IPv6
Limit
Loading subnets…

Interesting IPs

Top risky peers inside this ASN (latest snapshot). Sorted by risk score, then hits.

No peer rows available for this ASN snapshot.