DigitalOcean Referral Badge
cloud1
cloud2
cloud3
cloud4
cloud5
cloud6
← Back

ASN REPORT — AS26599 · TELEFÔNICA BRASIL S.A

First sighted: Sept. 22, 2023, 3 a.m. · Last sighted: Jan. 11, 2026, 1:59 a.m.

Risk
4 (low)
Total hits
10907
Total errors
2097
Observed IPs
8271
Top country
N/A
Top city
N/A

Risk

Model: v1 Computed: 2026-01-18 11:55:01
Risk score
4
Low
Risk gradient
Key drivers are enriched against the published annotator catalog when available; otherwise sensible defaults are used.
Key drivers
Credential brute forcing
Repeated authentication attempts consistent with password guessing or credential stuffing.
cred
Hits 24
Points 71.61
User-Agent anomaly
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
ua
Hits 240
Points 20.65
Protocol anomaly
Request structure or protocol-level signals deviate from typical browser HTTP traffic.
proto
Hits 13
Points 8.68
Request size anomaly
Requests are unusually large or shaped in a way that suggests abuse or automation.
request_size
Hits 66
Points 5.16
Scan velocity
High request rate and broad endpoint coverage suggest scanning or automated enumeration.
scan_velocity
Hits 6
Points 3.78

Traffic

Rollup

Daily activity (hits per day) and basic HTTP rollup counters for this ASN.

Loading activity…
Daily activity (hits per day). Total in window: .
Traffic rollup
HTTP status classes, URL diversity, and totals.
2xx
3068
3xx
5413
4xx
1938
5xx
159
Unique URLs
8645
Total hits
10907
First seen
Sept. 22, 2023, 3 a.m.
Last seen
Jan. 11, 2026, 1:59 a.m.

Annotators (All-time)

Heatmap of annotator × severity. Darker cells mean more volume in that band. Tip: switch to Weighted points to see what drives impact (not just noise).

Severity →
Low High
Repeated authentication attempts consistent with password guessing or credential stuffing.
hits 24 pts 71.61
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 10 1 38.83 Dec. 20, 2023, 3:18 p.m. July 22, 2025, 10:47 a.m.
cred 10
12 6 1 29.70 Dec. 20, 2023, 3:18 p.m. July 22, 2025, 10:47 a.m.
cred 6
8 1 1 3.08 June 20, 2025, 8:49 a.m. June 20, 2025, 8:49 a.m.
cred 1
0 7 1 0.00 Dec. 20, 2023, 3:18 p.m. July 22, 2025, 10:47 a.m.
cred 7
User-Agent signals look missing, inconsistent, or indicative of non-browser tooling.
hits 240 pts 20.65
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
8 103 1 10.71 Jan. 12, 2024, 7:14 a.m. Nov. 7, 2025, 7:48 a.m.
ua 103
6 136 1 9.79 June 4, 2024, 2:05 a.m. Dec. 21, 2025, 8:31 p.m.
ua 136
10 1 1 0.14 April 14, 2025, 4:10 p.m. April 14, 2025, 4:10 p.m.
ua 1
Request structure or protocol-level signals deviate from typical browser HTTP traffic.
hits 13 pts 8.68
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
12 9 1 6.22 Oct. 7, 2024, 8:49 p.m. June 23, 2025, 12:23 p.m.
proto 9
11 4 1 2.46 Sept. 12, 2025, 1:59 p.m. Dec. 17, 2025, 4:52 p.m.
proto 4
Requests are unusually large or shaped in a way that suggests abuse or automation.
hits 66 pts 5.16
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
12 6 1 2.81 Jan. 3, 2025, 1:20 a.m. Aug. 13, 2025, 5:47 a.m.
request_size 6
14 4 1 2.35 July 2, 2025, 2:45 a.m. Nov. 25, 2025, 6:32 a.m.
request_size 4
0 56 1 0.00 Jan. 3, 2025, 1:20 a.m. Oct. 11, 2025, 5:04 p.m.
request_size 56
Scan velocity scan_velocity
High request rate and broad endpoint coverage suggest scanning or automated enumeration.
hits 6 pts 3.78
Breakdown by severity band (all-time). “Weighted” reflects your weight configuration.
Severity Total Labels Weighted First seen Last seen Top labels
10 3 1 3.78 May 24, 2025, 7:09 a.m. July 7, 2025, 5:01 p.m.
scan_velocity 3
0 3 1 0.00 May 24, 2025, 7:09 a.m. July 7, 2025, 5:01 p.m.
scan_velocity 3

HTTP Status Breakdown

Response mix grouped by status class (2xx/3xx/4xx/5xx). Auto-loads a single aggregation and renders a donut.

Loading status mix…
Running one aggregation and rendering the chart.

Geolocation

Live geolocation and map tiles auto-load for this ASN snapshot (peer IPs with coordinates).

Loading map…

SUBNETS HELD BY THIS ISP

Derived from ISP snapshot peers (Option A). Grouped into IPv4 /24 and IPv6 /48 by default.
IPv4
IPv6
Limit
Loading subnets…

Interesting IPs

Top risky peers inside this ASN (latest snapshot). Sorted by risk score, then hits.

No peer rows available for this ASN snapshot.