DigitalOcean Referral Badge
cloud1
cloud2
cloud3
cloud4
cloud5
cloud6
← Back

ASN REPORT — AS3352 · TELEFONICA DE ESPANA S.A.U.

First sighted: Aug. 21, 2023, 3 a.m. · Last sighted: Dec. 29, 2025, 1:59 a.m.

Risk
11 (low)
Total hits
4536
Total errors
705
Observed IPs
323
Top country
N/A
Top city
N/A

Risk

Model: v1 Computed: 2026-01-18 11:55:06
Risk score
11
Low
Risk gradient
Key drivers are enriched against the published annotator catalog when available; otherwise sensible defaults are used.
Key drivers
Command injection attempts
Request content resembles attempts to execute OS commands via an application.
cmdi
Hits 4
Points 83.78
Sensitive file probing
Requests target commonly sensitive files, configs, backups, or administrative resources.
sfp
Hits 10
Points 72.20
Path traversal attempts
Request paths/parameters resemble attempts to access files outside intended directories.
trav
Hits 8
Points 52.93
User-Agent anomaly
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
ua
Hits 604
Points 45.26
Scan velocity
High request rate and broad endpoint coverage suggest scanning or automated enumeration.
scan_velocity
Hits 38
Points 26.21
Request size anomaly
Requests are unusually large or shaped in a way that suggests abuse or automation.
request_size
Hits 220
Points 17.90
Automated client behavior
Traffic patterns strongly suggest automation rather than a human-operated browser.
bot
Hits 2
Points 0.95
Protocol anomaly
Request structure or protocol-level signals deviate from typical browser HTTP traffic.
proto
Hits 1
Points 0.69

Traffic

Rollup

Daily activity (hits per day) and basic HTTP rollup counters for this ASN.

Loading activity…
Daily activity (hits per day). Total in window: .
Traffic rollup
HTTP status classes, URL diversity, and totals.
2xx
2134
3xx
125
4xx
127
5xx
578
Unique URLs
1435
Total hits
4536
First seen
Aug. 21, 2023, 3 a.m.
Last seen
Dec. 29, 2025, 1:59 a.m.

Annotators (All-time)

Heatmap of annotator × severity. Darker cells mean more volume in that band. Tip: switch to Weighted points to see what drives impact (not just noise).

Severity →
Low High
Request content resembles attempts to execute OS commands via an application.
hits 4 pts 83.78
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
28 4 1 83.78 Jan. 21, 2024, 12:50 p.m. June 8, 2024, 6:47 p.m.
cmdi 4
Requests target commonly sensitive files, configs, backups, or administrative resources.
hits 10 pts 72.20
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
40 6 1 48.58 Nov. 22, 2024, 1:59 p.m. Nov. 27, 2024, 7:52 a.m.
sensitive_file 6
34 3 1 19.30 June 26, 2025, 6:06 a.m. June 26, 2025, 6:06 a.m.
sensitive_file 3
24 1 1 4.33 Oct. 7, 2024, 8:16 p.m. Oct. 7, 2024, 8:16 p.m.
sensitive_file 1
Request paths/parameters resemble attempts to access files outside intended directories.
hits 8 pts 52.93
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
28 3 1 20.09 June 26, 2025, 6:06 a.m. June 26, 2025, 6:06 a.m.
trav 3
26 3 1 18.25 June 26, 2025, 6:06 a.m. June 26, 2025, 6:06 a.m.
trav 3
30 2 1 14.59 June 26, 2025, 6:06 a.m. June 26, 2025, 6:06 a.m.
trav 2
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
hits 604 pts 45.26
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
6 566 1 40.75 Sept. 7, 2023, 12:31 a.m. Aug. 20, 2025, 1:12 p.m.
ua 566
8 30 1 3.12 Sept. 7, 2023, 7:42 a.m. Sept. 10, 2025, 6:18 p.m.
ua 30
10 5 1 0.72 Aug. 21, 2023, 10:01 a.m. Nov. 27, 2024, 7:52 a.m.
ua 5
14 3 1 0.67 March 31, 2025, 6:31 a.m. March 31, 2025, 6:32 a.m.
ua 3
Scan velocity scan_velocity
High request rate and broad endpoint coverage suggest scanning or automated enumeration.
hits 38 pts 26.21
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 15 1 18.90 Sept. 6, 2024, 5:50 p.m. May 19, 2025, 4:15 p.m.
scan_velocity 15
16 2 1 4.03 May 8, 2025, 12:01 a.m. May 8, 2025, 12:01 a.m.
scan_velocity 2
14 1 1 1.76 May 8, 2025, 12:01 a.m. May 8, 2025, 12:01 a.m.
scan_velocity 1
12 1 1 1.51 May 8, 2025, 12:01 a.m. May 8, 2025, 12:01 a.m.
scan_velocity 1
0 19 1 0.00 Sept. 6, 2024, 5:50 p.m. May 19, 2025, 4:15 p.m.
scan_velocity 19
Requests are unusually large or shaped in a way that suggests abuse or automation.
hits 220 pts 17.90
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
12 37 1 17.32 Dec. 25, 2024, 10:19 a.m. Aug. 1, 2025, 11:51 a.m.
request_size 37
14 1 1 0.59 May 26, 2025, 1:47 p.m. May 26, 2025, 1:47 p.m.
request_size 1
0 182 1 0.00 Dec. 25, 2024, 10:19 a.m. Oct. 19, 2025, 9:12 p.m.
request_size 182
Traffic patterns strongly suggest automation rather than a human-operated browser.
hits 2 pts 0.95
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 2 1 0.95 May 19, 2025, 4:15 p.m. May 19, 2025, 4:15 p.m.
bot 2
Request structure or protocol-level signals deviate from typical browser HTTP traffic.
hits 1 pts 0.69
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
12 1 1 0.69 June 26, 2025, 6:06 a.m. June 26, 2025, 6:06 a.m.
proto 1

HTTP Status Breakdown

Response mix grouped by status class (2xx/3xx/4xx/5xx). Auto-loads a single aggregation and renders a donut.

Loading status mix…
Running one aggregation and rendering the chart.

Geolocation

Live geolocation and map tiles auto-load for this ASN snapshot (peer IPs with coordinates).

Loading map…

SUBNETS HELD BY THIS ISP

Derived from ISP snapshot peers (Option A). Grouped into IPv4 /24 and IPv6 /48 by default.
IPv4
IPv6
Limit
Loading subnets…

Interesting IPs

Top risky peers inside this ASN (latest snapshot). Sorted by risk score, then hits.

No peer rows available for this ASN snapshot.