DigitalOcean Referral Badge
cloud1
cloud2
cloud3
cloud4
cloud5
cloud6
← Back

ASN REPORT — AS852 · TELUS Communications Inc.

First sighted: July 7, 2023, 3 a.m. · Last sighted: Nov. 29, 2025, 1:59 a.m.

Risk
6 (low)
Total hits
5798
Total errors
637
Observed IPs
289
Top country
N/A
Top city
N/A

Risk

Model: v1 Computed: 2026-01-18 11:55:16
Risk score
6
Low
Risk gradient
Key drivers are enriched against the published annotator catalog when available; otherwise sensible defaults are used.
Key drivers
Request size anomaly
Requests are unusually large or shaped in a way that suggests abuse or automation.
request_size
Hits 488
Points 62.48
Scan velocity
High request rate and broad endpoint coverage suggest scanning or automated enumeration.
scan_velocity
Hits 68
Points 42.84
User-Agent anomaly
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
ua
Hits 332
Points 24.48
Credential brute forcing
Repeated authentication attempts consistent with password guessing or credential stuffing.
cred
Hits 9
Points 20.79
Sensitive file probing
Requests target commonly sensitive files, configs, backups, or administrative resources.
sfp
Hits 1
Points 8.10
Automated client behavior
Traffic patterns strongly suggest automation rather than a human-operated browser.
bot
Hits 4
Points 1.90
HTTP method anomaly
Unusual or unexpected HTTP methods observed for the target endpoints.
method
Hits 4
Points 1.63
Referrer abuse
Referrer patterns look manipulated, irrelevant, or inconsistent with normal navigation.
ref
Hits 3
Points 0.38

Traffic

Rollup

Daily activity (hits per day) and basic HTTP rollup counters for this ASN.

Loading activity…
Daily activity (hits per day). Total in window: .
Traffic rollup
HTTP status classes, URL diversity, and totals.
2xx
3662
3xx
53
4xx
261
5xx
376
Unique URLs
2010
Total hits
5798
First seen
July 7, 2023, 3 a.m.
Last seen
Nov. 29, 2025, 1:59 a.m.

Annotators (All-time)

Heatmap of annotator × severity. Darker cells mean more volume in that band. Tip: switch to Weighted points to see what drives impact (not just noise).

Severity →
Low High
Requests are unusually large or shaped in a way that suggests abuse or automation.
hits 488 pts 62.48
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
12 131 1 61.31 Dec. 30, 2024, 10:43 a.m. Aug. 17, 2025, 5:12 a.m.
request_size 131
14 2 1 1.18 July 26, 2025, 1:18 a.m. July 26, 2025, 10:04 p.m.
request_size 2
0 355 1 0.00 Dec. 24, 2024, 5:55 p.m. Oct. 5, 2025, 8:16 a.m.
request_size 355
Scan velocity scan_velocity
High request rate and broad endpoint coverage suggest scanning or automated enumeration.
hits 68 pts 42.84
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 34 1 42.84 Oct. 4, 2024, 12:01 a.m. April 3, 2025, 7:44 p.m.
scan_velocity 34
0 34 1 0.00 Oct. 4, 2024, 12:01 a.m. April 3, 2025, 7:44 p.m.
scan_velocity 34
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
hits 332 pts 24.48
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
6 318 1 22.90 Sept. 4, 2023, 3:22 a.m. Aug. 17, 2025, 5:12 a.m.
ua 318
8 12 1 1.25 Sept. 4, 2023, 3:22 a.m. March 4, 2025, 1:56 p.m.
ua 12
12 2 1 0.34 Nov. 26, 2024, 3:23 p.m. Nov. 26, 2024, 3:23 p.m.
ua 2
Repeated authentication attempts consistent with password guessing or credential stuffing.
hits 9 pts 20.79
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 3 1 11.55 March 28, 2025, 1:24 a.m. March 28, 2025, 1:24 a.m.
cred 3
8 3 1 9.24 March 28, 2025, 1:24 a.m. March 28, 2025, 1:24 a.m.
cred 3
0 3 1 0.00 March 28, 2025, 1:24 a.m. March 28, 2025, 1:24 a.m.
cred 3
Requests target commonly sensitive files, configs, backups, or administrative resources.
hits 1 pts 8.10
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
40 1 1 8.10 Jan. 2, 2025, 4:42 p.m. Jan. 2, 2025, 4:42 p.m.
sensitive_file 1
Traffic patterns strongly suggest automation rather than a human-operated browser.
hits 4 pts 1.90
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 4 1 1.90 Jan. 16, 2025, 10:27 a.m. March 2, 2025, 1:51 a.m.
bot 4
Unusual or unexpected HTTP methods observed for the target endpoints.
hits 4 pts 1.63
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
8 4 1 1.63 Sept. 4, 2023, 3:22 a.m. Sept. 4, 2023, 8:28 a.m.
method 4
Referrer patterns look manipulated, irrelevant, or inconsistent with normal navigation.
hits 3 pts 0.38
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
6 3 1 0.38 March 28, 2025, 1:24 a.m. March 28, 2025, 1:24 a.m.
ref 3

HTTP Status Breakdown

Response mix grouped by status class (2xx/3xx/4xx/5xx). Auto-loads a single aggregation and renders a donut.

Loading status mix…
Running one aggregation and rendering the chart.

Geolocation

Live geolocation and map tiles auto-load for this ASN snapshot (peer IPs with coordinates).

Loading map…

SUBNETS HELD BY THIS ISP

Derived from ISP snapshot peers (Option A). Grouped into IPv4 /24 and IPv6 /48 by default.
IPv4
IPv6
Limit
Loading subnets…

Interesting IPs

Top risky peers inside this ASN (latest snapshot). Sorted by risk score, then hits.

No peer rows available for this ASN snapshot.