DigitalOcean Referral Badge
cloud1
cloud2
cloud3
cloud4
cloud5
cloud6
← Back

ASN REPORT — AS20978 · TT Mobil Iletisim Hizmetleri A.S

First sighted: June 1, 2024, 3 a.m. · Last sighted: Jan. 26, 2026, 1:59 a.m.

Risk
2 (low)
Total hits
344
Total errors
76
Observed IPs
41
Top country
N/A
Top city
N/A

Risk

Model: v1 Computed: 2026-01-29 10:18:33
Risk score
2
Low
Risk gradient
Key drivers are enriched against the published annotator catalog when available; otherwise sensible defaults are used.
Key drivers
Credential brute forcing
Repeated authentication attempts consistent with password guessing or credential stuffing.
cred
Hits 10
Points 30.36
User-Agent anomaly
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
ua
Hits 52
Points 3.74
Scan velocity
High request rate and broad endpoint coverage suggest scanning or automated enumeration.
scan_velocity
Hits 4
Points 2.52
Request size anomaly
Requests are unusually large or shaped in a way that suggests abuse or automation.
request_size
Hits 15
Points 1.40

Traffic

Rollup

Daily activity (hits per day) and basic HTTP rollup counters for this ASN.

Loading activity…
Daily activity (hits per day). Total in window: .
Traffic rollup
HTTP status classes, URL diversity, and totals.
2xx
116
3xx
13
4xx
28
5xx
48
Unique URLs
139
Total hits
344
First seen
June 1, 2024, 3 a.m.
Last seen
Jan. 26, 2026, 1:59 a.m.

Annotators (All-time)

Heatmap of annotator × severity. Darker cells mean more volume in that band. Tip: switch to Weighted points to see what drives impact (not just noise).

Severity →
Low High
Repeated authentication attempts consistent with password guessing or credential stuffing.
hits 10 pts 30.36
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 4 1 15.51 Jan. 2, 2025, 5:20 p.m. Jan. 2, 2025, 5:21 p.m.
cred 4
12 3 1 14.85 Jan. 2, 2025, 5:20 p.m. Jan. 2, 2025, 5:21 p.m.
cred 3
0 3 1 0.00 Jan. 2, 2025, 5:20 p.m. Jan. 2, 2025, 5:21 p.m.
cred 3
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
hits 52 pts 3.74
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
6 52 1 3.74 June 1, 2024, 11:12 p.m. Dec. 28, 2025, 10:02 a.m.
ua 52
Scan velocity scan_velocity
High request rate and broad endpoint coverage suggest scanning or automated enumeration.
hits 4 pts 2.52
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 2 1 2.52 Sept. 11, 2024, 12:01 a.m. Sept. 11, 2024, 12:02 a.m.
scan_velocity 2
0 2 1 0.00 Sept. 11, 2024, 12:01 a.m. Sept. 11, 2024, 12:02 a.m.
scan_velocity 2
Requests are unusually large or shaped in a way that suggests abuse or automation.
hits 15 pts 1.40
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
12 3 1 1.40 Jan. 12, 2025, 3:48 p.m. Feb. 12, 2025, 9:51 p.m.
request_size 3
0 12 1 0.00 Dec. 25, 2024, 7:22 p.m. Feb. 12, 2025, 9:51 p.m.
request_size 12

HTTP Status Breakdown

Response mix grouped by status class (2xx/3xx/4xx/5xx). Auto-loads a single aggregation and renders a donut.

Loading status mix…
Running one aggregation and rendering the chart.

Geolocation

Live geolocation and map tiles auto-load for this ASN snapshot (peer IPs with coordinates).

Loading map…

SUBNETS HELD BY THIS ISP

Derived from ISP snapshot peers (Option A). Grouped into IPv4 /24 and IPv6 /48 by default.
IPv4
IPv6
Limit
Loading subnets…

Interesting IPs

Top risky peers inside this ASN (latest snapshot). Sorted by risk score, then hits.

No peer rows available for this ASN snapshot.