DigitalOcean Referral Badge
cloud1
cloud2
cloud3
cloud4
cloud5
cloud6
← Back

ASN REPORT — AS3209 · Vodafone GmbH

First sighted: July 27, 2023, 3 a.m. · Last sighted: Dec. 18, 2025, 1:59 a.m.

Risk
93 (high)
Total hits
36088
Total errors
6346
Observed IPs
400
Top country
N/A
Top city
N/A

Risk

Model: v1 Computed: 2026-01-18 11:55:12
Risk score
93
High
Risk gradient
Key drivers are enriched against the published annotator catalog when available; otherwise sensible defaults are used.
Key drivers
Automated client behavior
Traffic patterns strongly suggest automation rather than a human-operated browser.
bot
Hits 12965
Points 6158.38
Scan velocity
High request rate and broad endpoint coverage suggest scanning or automated enumeration.
scan_velocity
Hits 467
Points 324.63
User-Agent anomaly
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
ua
Hits 1174
Points 84.85
Request size anomaly
Requests are unusually large or shaped in a way that suggests abuse or automation.
request_size
Hits 467
Points 40.25
Credential brute forcing
Repeated authentication attempts consistent with password guessing or credential stuffing.
cred
Hits 6
Points 13.86

Traffic

Rollup

Daily activity (hits per day) and basic HTTP rollup counters for this ASN.

Loading activity…
Daily activity (hits per day). Total in window: .
Traffic rollup
HTTP status classes, URL diversity, and totals.
2xx
20396
3xx
4395
4xx
5289
5xx
1057
Unique URLs
11167
Total hits
36088
First seen
July 27, 2023, 3 a.m.
Last seen
Dec. 18, 2025, 1:59 a.m.

Annotators (All-time)

Heatmap of annotator × severity. Darker cells mean more volume in that band. Tip: switch to Weighted points to see what drives impact (not just noise).

Severity →
Low High
Traffic patterns strongly suggest automation rather than a human-operated browser.
hits 12965 pts 6158.38
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 12965 1 6158.38 July 28, 2023, 1:29 a.m. Aug. 1, 2025, 9:53 p.m.
bot 12965
Scan velocity scan_velocity
High request rate and broad endpoint coverage suggest scanning or automated enumeration.
hits 467 pts 324.63
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 254 1 324.63 July 31, 2023, 9:22 p.m. July 25, 2025, 2 p.m.
scan_velocity 254
0 213 1 0.00 July 31, 2023, 9:22 p.m. July 25, 2025, 2 p.m.
scan_velocity 213
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
hits 1174 pts 84.85
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
6 1164 1 83.81 Nov. 12, 2023, 11:58 p.m. Sept. 9, 2025, 4 p.m.
ua 1164
8 10 1 1.04 Sept. 2, 2023, 2:59 a.m. May 29, 2025, 9:07 p.m.
ua 10
Requests are unusually large or shaped in a way that suggests abuse or automation.
hits 467 pts 40.25
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
12 86 1 40.25 Nov. 12, 2024, 11:13 p.m. Aug. 1, 2025, 9:53 p.m.
request_size 86
0 381 1 0.00 Dec. 25, 2024, 2:02 p.m. Dec. 17, 2025, 3:21 a.m.
request_size 381
Repeated authentication attempts consistent with password guessing or credential stuffing.
hits 6 pts 13.86
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 2 1 7.70 Jan. 6, 2025, 9:48 a.m. April 6, 2025, 6:18 a.m.
cred 2
8 2 1 6.16 Jan. 6, 2025, 9:48 a.m. April 6, 2025, 6:18 a.m.
cred 2
0 2 1 0.00 Jan. 6, 2025, 9:48 a.m. April 6, 2025, 6:18 a.m.
cred 2

HTTP Status Breakdown

Response mix grouped by status class (2xx/3xx/4xx/5xx). Auto-loads a single aggregation and renders a donut.

Loading status mix…
Running one aggregation and rendering the chart.

Geolocation

Live geolocation and map tiles auto-load for this ASN snapshot (peer IPs with coordinates).

Loading map…

SUBNETS HELD BY THIS ISP

Derived from ISP snapshot peers (Option A). Grouped into IPv4 /24 and IPv6 /48 by default.
IPv4
IPv6
Limit
Loading subnets…

Interesting IPs

Top risky peers inside this ASN (latest snapshot). Sorted by risk score, then hits.

No peer rows available for this ASN snapshot.