Cloud ASN Risk Watchlist

Most teams that start watching where their traffic comes from build the same rule first, and most of them switch it off within a month. The rule says alert when someone connects from a hosting provider, and it fails for arithmetic reasons, not logical ones. A single large VPS network can carry a corporate VPN concentrator, a vendor’s jump box, a mobile carrier’s NAT egress and an attacker’s rented server on consecutive addresses, and the log shows the same autonomous system number for all four. Alerting on the network alone produces a volume nobody can triage, so the rule gets disabled and the environment ends up with less visibility than before it tried.

This is the catalog I built to make that problem tractable. It separates the networks where a connection genuinely warrants immediate attention from the much larger set where the network is context and nothing more, and it records why each row sits where it does along with what would make that judgement wrong.

An autonomous system number appears in almost every log that records a client address, so nothing here is specific to one vendor or one product. The tiering is the work; where you apply it is your choice.

Evidence and routing snapshot . Catalog rebuilt 2026-10-09.

  • 1,151Catalog ASNsEvery researched autonomous system in the current standalone catalog.
  • 559Enabled for monitoringRows switched on by default. The rest are disabled pending tenant validation.
  • 403T1 CriticalHighest-priority identity and infrastructure risk.
  • 60T2 HighDirect campaign, commercial anonymizer, or strong provider evidence.
  • 107T3 ContextHosting and VPS context that needs a corroborating anomaly.
  • 581T4 ReviewBroad cloud, access ISP and lifecycle-review rows, disabled by default.
  • 431On Spamhaus ASN-DROPCurrent membership in the ASN-DROP snapshot for this build.
  • 511Published indicatorsExact IPs, CIDRs, domains, hashes and application IDs with observation dates.
  • 29Detection patternsIdentity and post-authentication patterns, each tied to its event sources.
  • 159Cited sourcesEvery tiering decision resolves to one of these source records.
  • 82Holder countries representedRIR holder registration, which is not where a sign-in came from.
  • 592Review-only rowsCandidates examined and left disabled, with the reason recorded.

Downloads

If you came for the files, they are here rather than at the foot of the page. The Excel workbook is the fullest version and the one worth opening if you want to understand the work rather than automate against it. Every sheet is filtered and frozen, and the internal tuning columns are removed. The CSV bundle is the better choice for a SIEM import or any scripted analysis, the JSON carries every sheet in one document, and the text files are a plain ASN list for a quick lookup.

  • Excel workbookXLSX, 518 KB, 1,151 rowsEvery sheet, filtered and frozen, with the internal tuning columns removed.
  • Everything, zippedZIP, 967 KBThe workbook, every CSV, the JSON, the text files and the utilities.
  • ASN catalog CSVCSV, 806 KB, 1,151 rowsThe full catalog, one row per autonomous system.
  • Review-only CSVCSV, 230 KB, 592 rowsCandidates examined and left disabled, with the reason.
  • Published indicators CSVCSV, 177 KB, 511 rowsExact IPs, CIDRs, domains, hashes and application IDs with dates.
  • Provider evidence CSVCSV, 43 KB, 68 rowsThe named provider records, with role assessment and confidence.
  • Detection patterns CSVCSV, 18 KB, 29 rowsIdentity and post-authentication patterns with event sources and TTPs.
  • Provider families CSVCSV, 158 KB, 819 rowsAggregated view for handling a provider rather than one ASN.
  • Country summary CSVCSV, 17 KB, 82 rowsHolder-registration rollup with the event-country policy column.
  • Community feeds CSVCSV, 2 KB, 6 rowsThe public feeds used for exact-IP enrichment, with their limits.
  • Sources CSVCSV, 57 KB, 159 rowsEvery cited source, what it supports and what it does not.
  • Full JSONJSON, 2.8 MB, 1,151 rowsEvery sheet in one document, for automation.
  • Enabled ASNs TXTTXT, 5 KB, 559 rowsOne ASN per line, for a quick import or a scripted lookup.
  • T1 and T2 ASNs TXTTXT, 4 KB, 463 rowsThe alerting set only, for teams that want the narrow list.
  • Sentinel Watchlist CSVCSV, 274 KB, 1,151 rowsShaped for a Microsoft Sentinel Watchlist keyed on ASNumber.
  • KQL set literalsKQL, 9 KB, 559 rowsPaste-ready dynamic() sets for Defender XDR advanced hunting.
  • Methodology and changelogMD, 60 KBTier definitions, operating rules, limitations and every cited source.

Free to use with attribution, CC BY 4.0. The internal tuning columns from the research workbook are removed from every file here.

Everything below explains what the tiers mean and how the rows were decided, which is worth reading before the catalog is wired into anything that alerts.

Where this applies

Anything that records the address a request came from can use this catalog, because an autonomous system number is a property of the address rather than of the service being connected to. In practice that covers identity providers and their sign-in logs, VPN concentrators and remote access gateways, firewalls and edge devices, SaaS audit trails, mail gateways, web application firewalls, and the SSH and RDP logs on anything exposed.

The worked examples further down lean on Entra ID and Microsoft 365 because that is where the detection patterns in this release are most developed, and the sign-in telemetry there is rich enough to show what corroboration actually looks like. There are also examples for Splunk against any source-IP index and for Okta, which carries the autonomous system number on every System Log event without any enrichment step. The logic in all of them is the same: find the connection worth looking at, then establish whether anything actually happened.

What the catalog does not do is decide anything on its own, on any platform. That is the next section, and it is the part most watchlists leave out.

An ASN is a risk feature, not attribution

That distinction decides everything else on this page, so it is worth being precise about. When a catalog like this one lists AS62240, it is recording that published reporting and incident evidence placed activity on that network. It is not saying the provider is complicit, that every address there is hostile, or that the operator behind a given sign-in is in the country the number is registered to. Each of those is a separate claim needing separate evidence, and conflating them is how a watchlist turns into an accusation.

What follows from that is a tiering scheme, which is a different artifact from a block list. A tier here answers one question: how much weight can a sign-in from this network carry on its own, before anything else corroborates it. For the top tier the answer is enough to justify looking immediately. For the bottom tier the answer is almost none, which is why those rows ship switched off.

Why a malicious ASN list produces false positives

The false positives are not noise around the edges of a working signal. They are structural. Four distinct causes are worth separating, because each one needs a different response.

Shared infrastructure is the largest. A hosting provider’s business model is renting capacity to anyone who pays, so the same network serves your backup vendor and somebody’s phishing panel simultaneously. The catalog handles this by refusing to promote a commodity hosting network above the context tier without direct evidence tying that specific network to identity attacks, which is why large VPS providers sit at T3 and need a second signal.

Commercial VPN egress is the second, and it is the one that catches organisations out most often. Consumer VPN providers aggregate thousands of unrelated subscribers behind a handful of exit networks. An employee who turns on a personal VPN on a work laptop appears from the same addresses an attacker using the same product would. Whether that is suspicious depends entirely on whether consumer VPN use is expected in your environment, which is a question about your policy, not about the network.

Provider size distorts every count. A network with a million customers generates more abuse reports than one with a thousand, and no feed in this catalog normalises for that. An ASN appearing frequently in indicator lists can simply mean it is large. Nothing here treats volume as evidence of a provider’s character.

Address reassignment breaks the link between history and the present. Prefixes move between holders, registrations get reassigned, and a network that hosted a campaign in 2024 may belong to an unrelated business now. This is why rows get removed on ownership change instead of carrying their old reputation forward, and why every indicator in the download states the window it was observed in. None of them are presented as currently true.

T1 to T4, and what effective enablement means

Tier definitions, default enablement and false-positive posture
TierDefaultWhat puts an ASN hereHow to handle a matchFalse-positive risk
T1 CriticalEnabledCurrent high-confidence risk plus direct identity, BPH, or local critical evidenceImmediate triage of successful interactive sign-ins. Validate dependencies before deny actions.Medium
T2 HighEnabledDirect credential campaign, commercial anonymizer, or strong threat-infrastructure evidenceHigh-severity alert on success or failed-to-success sequence.High
T3 ContextEnabledCommodity VPS, hosting, or point-IOC provider contextRequire identity, device, session, travel, MFA, or exfiltration corroboration.High to very high
T4 ReviewDisabledBroad cloud, access ISP, uncertain continuity, or non-originating allocationTenant-specific review only. Never use as an ASN-only verdict.Very high

The tier sets the posture; the enabled flag decides whether a row is live at all. T1 and T2 are enabled throughout. T3 is enabled with a small number of exceptions where the evidence did not survive review. T4 is disabled throughout, and it is the largest tier in the catalog, which is the most honest thing about the structure. Those rows are broad cloud platforms, consumer access ISPs, allocations that are not currently announcing routes, and candidates whose ownership continuity could not be established. The research examined them, which is why they are in the file at all. They ship switched off because an ASN-only match on any of them is more likely to be an employee on a phone than an intruder.

The research workbook behind this release also carries a local override layer, so a row can be forced on or off for one tenant with the reason recorded next to it. That layer is specific to somebody’s environment and is stripped from every public file. What you are downloading is the researched default. Keep your own override column alongside it rather than editing the defaults in place, because the next refresh will otherwise revert decisions you made deliberately.

There is also a review-only set: candidates examined and left disabled, each with the reason recorded. It ships as its own file. What a catalog considered and rejected tells you more about how it was built than its inclusions do, and it is the part most watchlists never publish.

The high-interest ASNs and provider families

The table below carries every network the research can speak to by name, which means it either has a provider-level evidence record or a named actor or campaign attached. That makes the selection checkable instead of an arbitrary sample. The full catalog is considerably larger and ships in the download, because a table of that length is useful in a spreadsheet and hostile on a web page.

Filter by ASN, provider, country, campaign or category. The tier checkboxes narrow it further.

Showing 106 of 106 named ASNs

Named autonomous systems with provider or campaign evidence
ASNNetworkTierHolderFP riskEvidence
AS8100SPLICE-AS-AP - Splice Internet Pty LtdShared hosting / VPS / cloudT4 ReviewAUVery High
Campaign watch ended; retained for history
Evidence
Published reporting includes 2 time-bounded indicators attributed to or currently mapped to AS8100 across Akira ransomware targeting SonicWall SSL VPN. This does not implicate the provider or every tenant.
Provider family
SPLICE-AS-AP
Category
Campaign watch ended; retained for history
Actor or campaign
Akira ransomware targeting SonicWall SSL VPN
How to handle it
Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2025-09-22
Sources
N06, N01
AS11878TZULO - tzulo, inc.Shared hosting / VPS / cloudT3 ContextUSHigh
Campaign watch
Evidence
Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS11878 across UNC6671 multi-brand vishing, AiTM, and SaaS extortion. This does not implicate the provider or every tenant.
Provider family
tzulo
Category
Campaign watch
Actor or campaign
UNC6671 multi-brand vishing, AiTM, and SaaS extortion
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
High for exact infrastructure; medium at ASN level
How to handle it
Campaign watch: 1 campaign (N17).
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-08-06
Sources
N17, N01
AS12586ASGHOSTNET GHOSTnet GmbHShared hosting / VPS / cloudT4 ReviewDEHigh
Behavior-correlated enrollment infrastructure
Evidence
eSentire observed final Intune enrollment from 5.230.71.51 on reported AS12586 after GhostCode device-code token theft. This is one incident and does not establish provider complicity.
Provider family
GHOSTnet
Category
Behavior-correlated enrollment infrastructure
Actor or campaign
GhostCode
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
High for the exact incident endpoint and sequence; low for ASN-wide inference.
How to handle it
Disabled by default; use exact-IP and behavior correlation.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-09-29
Sources
N48, N01
AS13335CLOUDFLARENET - Cloudflare, Inc.Shared hosting / VPS / cloudT4 ReviewUSVery High
Broad cloud/CDN control row
Evidence
Broad shared cloud, CDN, or first-party network. Disabled to avoid ASN-only false positives; use exact indicators and behavioral corroboration.
Provider family
Cloudflare
Category
Broad cloud/CDN control row
Actor or campaign
ARToken / EvilTokens phishing infrastructure behind Cloudflare
How to handle it
Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-07-01
Sources
N20, N01
AS13926NETPROTECT-PHX - Strong Technology, LLC.Strong Technology / NetProtectCommercial VPN / hosting / proxyT4 ReviewUSHigh
Commercial VPN provider family expansion
Evidence
Active Strong Technology / NetProtect family ASN without sufficient direct campaign-time evidence for automatic monitoring. Disabled pending local need and validation.
Provider family
Strong Technology / NetProtect
Category
Commercial VPN provider family expansion
Actor or campaign
StrongVPN / Strong Technology family
How to handle it
Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-09-15
Sources
N35, N36, N01
AS14061DIGITALOCEAN-ASN - DigitalOcean, LLCShared hosting / VPS / cloudT3 ContextUSMedium
Published campaign infrastructure in shared hosting or VPN space
Evidence
Published reporting includes 5 time-bounded indicators attributed to or currently mapped to AS14061 across Akira ransomware targeting SonicWall SSL VPN; Console Chaos FortiGate management-interface exploitation. This does not implicate the provider or every tenant.
Provider family
DigitalOcean
Category
Published campaign infrastructure in shared hosting or VPN space
Actor or campaign
Akira ransomware targeting SonicWall SSL VPN; Console Chaos FortiGate management-interface exploitation
How to handle it
Use as a risk enhancer for interactive sign-ins, VPN access, management traffic, and post-authentication anomalies.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2025-09-22
Sources
N06, N09, N01
AS143151GSERVERS - 1GSERVERS, LLCShared hosting / VPS / cloudT4 ReviewUSVery High
Campaign watch ended; retained for history
Evidence
Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS14315 across Akira ransomware targeting SonicWall SSL VPN. This does not implicate the provider or every tenant.
Provider family
1GSERVERS
Category
Campaign watch ended; retained for history
Actor or campaign
Akira ransomware targeting SonicWall SSL VPN
How to handle it
Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2025-09-22
Sources
N06, N01
AS14956ROUTERHOSTING - RouterHosting LLCCommercial VPS/cloud hostingT1 CriticalUSMedium
Current Spamhaus ASN-DROP
Evidence
Listed in the 2026-10-09 Spamhaus ASN-DROP snapshot (ROUTERHOSTING, cloudzy.com). Halcyon reported substantial Cloudzy infrastructure used by ransomware and nation-state C2 and alleged a permissive operating model; Cloudzy disputed those conclusions. JUMPSEC subsequently mapped multiple 2026 DPRK BlueNoroff campaign domains to AS14956. Repeated malicious use is strong; knowing complicity remains disputed.
Category
Current Spamhaus ASN-DROP
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
Strong observed misuse; provider complicity disputed
How to handle it
Append provider evidence; preserve existing T2 High
Route status
Announced
On Spamhaus ASN-DROP
Yes
Last evidence
2026-10-09
Sources
S01, S02, S05, X016, X017, X018, N01
AS16276OVH OVH SASOVHcloudLarge shared cloud / VPST4 ReviewFRVery High
Broad cloud provider with exact historical IOCs
Evidence
Two exact Proofpoint login-source IOCs historically originated from AS16276. OVH is a large shared cloud; keep the IP history but disable whole-ASN alerts by default.
Provider family
OVHcloud
Category
Broad cloud provider with exact historical IOCs
Actor or campaign
Proofpoint 2022 cloud credential attacks
How to handle it
Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2022-03-03
Sources
S04, S06, N01
AS19318IS-AS-1 - Interserver, IncHosting / VPS / proxyT3 ContextUSHigh
Campaign watch
Evidence
Microsoft published 64.20.53.230 as a Storm-3168 source for App Service probing. 64.20.32.0/19 was originated by AS19318 during the activity and still is.
Provider family
Interserver
Category
Campaign watch
Actor or campaign
Storm-3168 compromised service principals
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
Primary source names the ASN or an address it originated during the activity
How to handle it
T3 until 2027-03-24.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-09-25
Sources
N52, N01
AS20473AS-VULTR - The Constant Company, LLCUnknown / reviewT3 ContextUSHigh
Broad VPS cloud with exact ransomware and management-interface IOCs
Evidence
Three short-lived Gamaredon C2 IPs were reported in Vultr. Disable ASN-wide alerts and retain the exact historical IPs.
Provider family
Vultr
Category
Broad VPS cloud with exact ransomware and management-interface IOCs
Actor or campaign
Gamaredon / Primitive Bear
How to handle it
Use as context for interactive sign-ins, VPN authentication, and management traffic. Require exact IOC or behavioral corroboration because Vultr is a broad multi-tenant cloud.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2022-02-03
Sources
S08, N01, N06, N07, N09
AS21249RUTIL-BG-AS Rutil Ltd.Shared hosting / VPS / cloudT4 ReviewBGVery High
Campaign watch ended; retained for history
Evidence
Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS21249 across Akira ransomware targeting SonicWall SSL VPN. This does not implicate the provider or every tenant.
Provider family
RUTIL-BG-AS Rutil Ltd.
Category
Campaign watch ended; retained for history
Actor or campaign
Akira ransomware targeting SonicWall SSL VPN
How to handle it
Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2025-09-22
Sources
N06, N01
AS22781STRTEC - Strong Technology, LLC.Strong Technology / NetProtectCommercial VPN / hosting / proxyT4 ReviewUSHigh
Commercial VPN provider family expansion
Evidence
Active Strong Technology / NetProtect family ASN without sufficient direct campaign-time evidence for automatic monitoring. Disabled pending local need and validation.
Provider family
Strong Technology / NetProtect
Category
Commercial VPN provider family expansion
Actor or campaign
StrongVPN / Strong Technology family
How to handle it
Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-09-15
Sources
N35, N36, N01
AS23470RELIABLESITE - ReliableSite.Net LLCShared hosting / VPS / cloudT4 ReviewUSVery High
Campaign watch ended; retained for history
Evidence
Published reporting includes 3 time-bounded indicators attributed to or currently mapped to AS23470 across Akira ransomware targeting SonicWall SSL VPN. This does not implicate the provider or every tenant.
Provider family
RELIABLESITE
Category
Campaign watch ended; retained for history
Actor or campaign
Akira ransomware targeting SonicWall SSL VPN
How to handle it
Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2025-09-22
Sources
N06, N01
AS25369BANDWIDTH-AS Hydra Communications LtdShared hosting / VPS / cloudT3 ContextGBHigh
Campaign watch
Evidence
Published reporting includes 2 time-bounded indicators attributed to or currently mapped to AS25369 across UNC6671 multi-brand vishing, AiTM, and SaaS extortion. This does not implicate the provider or every tenant.
Provider family
Hydra Communications
Category
Campaign watch
Actor or campaign
UNC6671 multi-brand vishing, AiTM, and SaaS extortion
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
High for exact infrastructure; medium at ASN level
How to handle it
Campaign watch: 1 campaign (N17).
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-08-06
Sources
N17, N01
AS25820IT7NET - IT7 Networks IncShared hosting / VPS / cloudT4 ReviewCAHigh
Point-IOC provider context
Evidence
Current origin of Kapibala C2 104.225.153.141. This supports source-scoped review, not provider-wide malicious attribution.
Provider family
IT7 Networks Inc
Category
Point-IOC provider context
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
High exact-IP; low ASN-wide attribution
How to handle it
Disabled pending independent or local corroboration.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-09-29
Sources
N39, N01
AS29182RU-JSCIOT JSC IOTUnknown / reviewT4 ReviewRUVery High
Historical single-IP actor infrastructure
Evidence
One short-lived Gamaredon C2 resolution was reported in this ASN. Preserve the exact IP only; do not enable ASN-wide monitoring without local evidence.
Category
Historical single-IP actor infrastructure
Actor or campaign
Gamaredon / Primitive Bear
How to handle it
Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2022-02-03
Sources
S08, N01
AS29802HVC-AS - HIVELOCITY, Inc.Shared hosting / VPS / cloudT3 ContextUSHigh
Campaign watch
Evidence
Published reporting includes 4 time-bounded indicators attributed to or currently mapped to AS29802 across Akira and Fog ransomware via SonicWall SSL VPN; Akira ransomware targeting SonicWall SSL VPN. This does not implicate the provider or every tenant. eSentire saw pre-takedown Tycoon 2FA Microsoft 365 login attempts from AS29802 (2026-04-01).
Provider family
HVC-AS
Category
Campaign watch
Actor or campaign
Akira and Fog ransomware via SonicWall SSL VPN; Akira ransomware targeting SonicWall SSL VPN
How to handle it
Risk multiplier only. Raise the risk of a sign-in that already has a device, MFA, session, travel or post-authentication anomaly. Do not alert or block on the ASN alone.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-04-01
Sources
N07, N06, N10, N01
AS30633LEASEWEB-USA-WDC - Leaseweb USA, Inc.Shared hosting / VPS / cloudT4 ReviewUSVery High
Campaign watch ended; retained for history
Evidence
Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS30633 across Akira ransomware targeting SonicWall SSL VPN. This does not implicate the provider or every tenant.
Provider family
LEASEWEB-USA-WDC
Category
Campaign watch ended; retained for history
Actor or campaign
Akira ransomware targeting SonicWall SSL VPN
How to handle it
Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2025-09-22
Sources
N06, N01
AS30823AUROLOGIC aurologic GmbHcombahton GmbHTransit / upstream carrier context onlyT4 ReviewDEVery High
Legitimate upstream carrier, context only
Evidence
Recorded Future found aurologic to be a central upstream providing connectivity to many high-risk networks. The report expressly frames it as a legitimate carrier and does not establish aurologic itself as criminal or bulletproof hosting. Recorded Future's 2025 investigation identifies AS30823 as a central upstream and hosting nexus for multiple high-risk networks and suspected threat-activity enablers, including sanctioned Aeza infrastructure. The report expressly leaves negligence-versus-complicity unresolved and notes legitimate hosting/transit operations.
Provider family
combahton GmbH
Category
Legitimate upstream carrier, context only
Actor or campaign
upstream transit for multiple high-risk and malicious networks
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
High for topology and transit role; insufficient for provider-level maliciousness. This row is a deliberate no-block/context control.
How to handle it
Active and announcing routes as aurologic GmbH on 2026-09-15. CONTEXT ONLY-do not put the whole ASN in an identity deny list.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2025-11-06
Sources
S05, X003, X031, N01
AS32167LSHIY-USER-CONTENT - LSHIY LLCHosting / VPS / proxyT3 ContextUSHigh
Campaign watch
Evidence
Huntress attributed most of an Entra ID password and token spray, 81 million login attempts and 78 compromised accounts across 64 organizations between 2026-06-12 and 2026-06-26, to 2a0a:d683::/32 originated by AS32167. On 2026-07-02 LSHIY told Huntress the abuser was a bring-your-own-IP customer and suspended it. The operators moved to FranTech AS53667 and then 3xK AS200373, both already catalogued.
Provider family
LSHIY LLC
Category
Campaign watch
Actor or campaign
LSHIY password spray (Azure CLI / ROPC against Entra ID)
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
Primary source names the ASN or an address it originated during the activity
How to handle it
T3 until 2026-12-29.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-07-02
Sources
X008, N01
AS32613IWEB-AS - Leaseweb Canada Inc.Shared hosting / VPS / cloudT4 ReviewCAVery High
Campaign watch ended; retained for history
Evidence
Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS32613 across Akira and Fog ransomware via SonicWall SSL VPN. This does not implicate the provider or every tenant.
Provider family
IWEB-AS
Category
Campaign watch ended; retained for history
Actor or campaign
Akira and Fog ransomware via SonicWall SSL VPN
How to handle it
Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2024-10-24
Sources
N07, N01
AS33993UFO-AS UFO Hosting LLCStark / PQ.Hosting / THE.Hosting / UFOBulletproof / high-risk hosting familyT1 CriticalRUMedium
Sanctioned threat-activity-enabler successor (active)
Evidence
Recorded Future assessed with high confidence that UFO Hosting/AS33993 was established or repurposed as a sanctions-resilient vehicle for Stark Industries/PQ.Hosting infrastructure after the EU designation. The current Spamhaus ASN-DROP feed identifies its domain as stark-industries.solutions. AS33993 is active and in live Spamhaus ASN-DROP, mapped by Spamhaus to Stark Industries Solutions. Research tracks AS44477 through PQ.Hosting/THE.Hosting changes, creation of AS209847 and Russian infrastructure migration to AS33993. AS209847 and AS33993 are in current ASN-DROP; AS44477 is currently unannounced. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as UFO-AS (stark-industries.solutions).
Provider family
Stark / PQ.Hosting / THE.Hosting / UFO
Category
Sanctioned threat-activity-enabler successor (active)
Actor or campaign
Russian state-sponsored operations; Iranian state-sponsored operations; DPRK operations; Chinese state-sponsored operations; Doppelgänger; cybercrime infrastructure
Provider role
Source-supported provider or enabler assessment. It does not imply every customer or address is malicious.
Why this confidence
High for successor/control relationship and threat-actor-enabler status; label is TAE rather than asserting that every customer is malicious.
How to handle it
Active and announcing routes as UFO Hosting LLC on 2026-09-15; present in the current Spamhaus ASN-DROP snapshot.
Route status
Announced
On Spamhaus ASN-DROP
Yes
Last evidence
2026-09-29
Sources
S01, S02, S05, S12, S13, N01, S03
AS35758HQSERV_NETWORKS Rachamim Aviel TwitoCommercial VPN / hosting / proxyT4 ReviewILVery High
Campaign watch ended; retained for history
Evidence
Check Point reported Microsoft 365 password spray waves on 2026-03-03, 03-13 and 03-23 against Israel and the UAE using commercial VPN nodes hosted at AS35758, including Windscribe exits geolocated in Israel.
Provider family
HQSERV
Category
Campaign watch ended; retained for history
Actor or campaign
Iran-nexus Microsoft 365 password spray
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
Primary source names the ASN or an address it originated during the activity
How to handle it
Campaign watch ended 2026-09-27: 1 campaign (N61), newest report 2026-03-31.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-03-31
Sources
N61, N01
AS36352AS-COLOCROSSING - HostPapaShared hosting / VPS / cloudT4 ReviewUSVery High
Campaign watch ended; retained for history
Evidence
Published reporting includes 2 time-bounded indicators attributed to or currently mapped to AS36352 across Akira ransomware targeting SonicWall SSL VPN. This does not implicate the provider or every tenant.
Provider family
AS-COLOCROSSING
Category
Campaign watch ended; retained for history
Actor or campaign
Akira ransomware targeting SonicWall SSL VPN
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
High exact IOC; medium ASN-level relevance
How to handle it
Campaign watch ended 2026-03-21: 1 campaign (N06), newest report 2025-09-22.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2025-09-22
Sources
N06, N01
AS36680NETIFACELLC - Netiface LLCBulletproof / high-risk hosting familyT1 CriticalUSLow
Source-confirmed BPH (active)
Evidence
Spamhaus explicitly described Netiface/AS36680 as a bulletproof hoster during an investigation of abuse-resilient infrastructure, and the ASN is in the current ASN-DROP feed. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as NETIFACELLC (netiface.co.uk).
Provider family
Netiface
Category
Source-confirmed BPH (active)
Actor or campaign
bulletproof hosting
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
High: direct provider-level BPH wording from Spamhaus plus live ASN-DROP membership.
How to handle it
Active and announcing routes as Netiface LLC on 2026-09-15; present in current ASN-DROP.
Route status
Not currently originating
On Spamhaus ASN-DROP
Yes
Last evidence
2026-10-07
Sources
S01, S02, X073, N01, S03
AS39287materialism Materialism s.r.l.NjallaShared hosting / VPS / cloudT2 HighROMedium
Related provider or broad shared-service context
Evidence
Active related network for Njalla. No direct provider-level malicious designation was established; retain as enabled T2 monitoring context and require device, session, event-country, or post-authentication corroboration.
Provider family
Njalla
Category
Related provider or broad shared-service context
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
High for exact infrastructure; medium at ASN level
How to handle it
Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-09-15
Sources
N18, N21, N01
AS39798MivoCloud MivoCloud SRLHosting / VPS / proxyT4 ReviewMDVery High
Historical single-IP actor infrastructure
Evidence
One short-lived Gamaredon C2 resolution was reported in this ASN. Preserve the exact IP only; do not enable ASN-wide monitoring without local evidence.
Category
Historical single-IP actor infrastructure
Actor or campaign
Gamaredon / Primitive Bear
How to handle it
Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2022-02-03
Sources
S08, N01
AS43350NFORCE NForce Entertainment B.V.Hosting / VPS / proxyT4 ReviewNLVery High
Campaign watch ended; retained for history
Evidence
GreyNoise attributed most of over 9 million GlobalProtect login sessions, late September to mid-October 2025, to four ASNs including AS43350.
Provider family
NForce
Category
Campaign watch ended; retained for history
Actor or campaign
Palo Alto GlobalProtect login brute force
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
Primary source names the ASN or an address it originated during the activity
How to handle it
Campaign watch ended 2026-06-02: 1 campaign (N60), newest report 2025-12-04.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2025-12-04
Sources
N60, N01
AS43641Sollutium-NL SOLLUTIUM EU Sp z.o.o.Shared hosting / VPS / cloudT4 ReviewPLVery High
Campaign watch ended; retained for history
Evidence
Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS43641 across Akira and Fog ransomware via SonicWall SSL VPN. This does not implicate the provider or every tenant.
Provider family
Sollutium-NL SOLLUTIUM EU Sp z.o.o.
Category
Campaign watch ended; retained for history
Actor or campaign
Akira and Fog ransomware via SonicWall SSL VPN
How to handle it
Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2024-10-24
Sources
N07, N01
AS43830DIGITALENERGY-AS Basis LLCUnknown / reviewT4 ReviewRUVery High
Historical single-IP actor infrastructure
Evidence
One short-lived Gamaredon C2 resolution was reported in this ASN. Preserve the exact IP only; do not enable ASN-wide monitoring without local evidence.
Category
Historical single-IP actor infrastructure
Actor or campaign
Gamaredon / Primitive Bear
How to handle it
Disabled by default. Review with tenant geography, user population and vendor dependencies before enabling.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2022-02-03
Sources
S08, N01
AS48721FLYSERVERS-ENDCLIENTS Flyservers S.A.Bulletproof / high-risk hosting familyT2 HighPAMedium-High
Published BPH attribution, older evidence (active)
Evidence
Recorded Future's 2022 Adversary Infrastructure Report explicitly listed Flyservers S.A. among known BPH providers and mapped it to AS48721 in its ASN table.
Provider family
Flyservers
Category
Published BPH attribution, older evidence (active)
Actor or campaign
adversary command-and-control hosting
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
Medium: provider-level BPH wording is explicit, but the public evidence is older and should be refreshed with current IP/campaign signals.
How to handle it
Active and announcing routes as Flyservers S.A. on 2026-09-15. Watch/step-up tier pending fresh corroboration.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2022-12-15
Sources
X057, N01
AS49468MAGHOST_RO MAGIT'ST SRLShared hosting / VPS / cloudT4 ReviewROHigh
Conditional fast-flux ASN seed
Evidence
Conditional fast-flux analytic includes this ASN. This supports source-scoped review, not provider-wide malicious attribution.
Provider family
MAGIT'ST SRL
Category
Conditional fast-flux ASN seed
Actor or campaign
Fast-flux phishing infrastructure
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
High analytic membership, low ASN-wide attribution
How to handle it
Disabled pending independent or local corroboration.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-09-29
Sources
N38, N01
AS50867ORG-LVA15-AS HOSTKEY B.V.Shared hosting / VPS / cloudT4 ReviewNLVery High
Campaign watch ended; retained for history
Evidence
Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS50867 across Console Chaos FortiGate management-interface exploitation. This does not implicate the provider or every tenant.
Provider family
ORG-LVA15-AS HOSTKEY B.V.
Category
Campaign watch ended; retained for history
Actor or campaign
Console Chaos FortiGate management-interface exploitation
How to handle it
Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2025-01-10
Sources
N09, N01
AS51396PFCLOUD Pfcloud UG (haftungsbeschrankt)Bulletproof / high-risk hosting familyT1 CriticalDEMedium
BPH facilitator / upstream risk (active)
Evidence
Spamhaus described Pfcloud and aurologic as known in anti-abuse circles for persistent proliferation of bulletproof hosts. AS51396 is also present in the live ASN-DROP feed; this row labels facilitation/uplink risk rather than asserting Pfcloud owns every downstream BPH. AS51396 is active and in current Spamhaus ASN-DROP. Pfcloud publicly offers KVM VPS, dedicated servers, reseller hosting, and BGP services; URLhaus maintains an ASN page for malware-distribution URLs hosted there. Inclusion does not imply every tenant is malicious. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as PFCLOUD (pfcloud.io).
Provider family
PFCLOUD
Category
BPH facilitator / upstream risk (active)
Actor or campaign
upstream/facilitation for proliferating BPH networks
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
High for current feed status and facilitation role; deliberately narrower than provider-level criminal attribution.
How to handle it
Active and announcing routes as Pfcloud UG on 2026-09-15; present in current ASN-DROP.
Route status
Announced
On Spamhaus ASN-DROP
Yes
Last evidence
2026-09-29
Sources
S01, S02, S05, X053, X054, X076, N01, S03
AS51852PLI-AS Private Layer INCShared hosting / VPS / cloudT2 HighPAMedium
Published campaign infrastructure in shared hosting or VPN space
Evidence
Published reporting includes 2 time-bounded indicators attributed to or currently mapped to AS51852 across UNC6671 multi-brand vishing, AiTM, and SaaS extortion. This does not implicate the provider or every tenant.
Provider family
Private Layer
Category
Published campaign infrastructure in shared hosting or VPN space
Actor or campaign
UNC6671 multi-brand vishing, AiTM, and SaaS extortion
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
High for exact infrastructure; medium at ASN level
How to handle it
Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-08-06
Sources
N17, N01
AS53667PONYNET - FranTech SolutionsFranTech / BuyVMLow-cost VPS / VPN hostingT3 ContextUSHigh
Campaign watch
Evidence
Huntress reported a 2026 Microsoft 365 and Azure CLI password-spray wave moving into AS53667 IPv6 space. Huntress observed a 2026 Microsoft 365/Azure CLI password-spray wave move to AS53667 IPv6 space, with 87% target overlap from the preceding provider and prior password-spray history. This is direct identity-attack evidence but does not establish provider complicity. ipapi.is ranks this hosting ASN #963 with 12.11% observed abuse concentration (High).
Provider family
FranTech / BuyVM
Category
Campaign watch
Actor or campaign
LSHIY password spray
How to handle it
Risk multiplier only. Raise the risk of a sign-in that already has a device, MFA, session, travel or post-authentication anomaly. Do not alert or block on the ASN alone.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-07-15
Sources
S02, S03, S05, X008, N01
AS54203NETPROTECT-SP - Strong Technology, LLC.Strong Technology / NetProtectCommercial VPN / hosting / proxyT3 ContextUSMedium-High
Commercial VPN / proxy egress observed in brute-force campaign
Evidence
Time-matched RouteViews mapping attributes 178 IPs across 34 /24s from the Cisco Talos April 2024 brute-force IOC set to this Strong Technology / NetProtect ASN. Treat as commercial VPN/proxy egress context; no provider complicity is asserted.
Provider family
Strong Technology / NetProtect
Category
Commercial VPN / proxy egress observed in brute-force campaign
Actor or campaign
Cisco Talos 2024 VPN and SSH brute-force activity
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
Medium; no provider complicity
How to handle it
Use as a risk enhancer for interactive sign-ins, VPN access, management traffic, and post-authentication anomalies.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-09-15
Sources
N35, N36, N01
AS55286SERVER-MANIA - B2 Net Solutions Inc.Shared VPS / dedicated hostingT4 ReviewCAVery High
Campaign watch ended; retained for history
Evidence
Eight Proofpoint cloud login-source IOCs historically originated from AS55286 during the campaign window. Use as a step-up signal because ServerMania is shared hosting.
Provider family
ServerMania / B2 Net Solutions
Category
Campaign watch ended; retained for history
Actor or campaign
Proofpoint 2022 cloud credential attacks
How to handle it
Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2022-03-03
Sources
S04, S06, N01
AS57523changway-as Chang Way Technologies Co. LimitedBulletproof / high-risk hosting familyT4 ReviewHKN/A
Unannounced or low-visibility ASN retained for review
Evidence
Recorded Future's 2022 report explicitly named Chang Way Technologies as a known BPH provider and mapped AS57523 to it. Spamhaus still lists the ASN in its 2026-09-15 ASN-DROP snapshot, but it is not currently announcing routes. Recorded Future's 2022 adversary-infrastructure report listed AS57523 among networks observed hosting Cobalt Strike. It remains in current Spamhaus ASN-DROP, but RIPEstat reports it as not currently announced. This is infrastructure evidence, not nationality attribution. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as changway-as (changway.hk).
Provider family
Chang Way Technologies
Category
Unannounced or low-visibility ASN retained for review
Actor or campaign
adversary command-and-control hosting
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
High historical provider classification; no basis for current enforcement while withdrawn.
How to handle it
Not announcing routes on 2026-09-15. Move from active deny/watch logic to a tombstone with holder-change checks.
Route status
Not currently originating
On Spamhaus ASN-DROP
Yes
Last evidence
2026-09-29
Sources
S01, S02, S05, X057, N01, S03
AS57724DDOS-GUARD DDOS-GUARD LTDShared hosting / VPS / cloudT3 ContextRUMedium
Published campaign infrastructure in shared hosting or VPN space
Evidence
Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS57724 across UNC6671 multi-brand vishing, AiTM, and SaaS extortion. This does not implicate the provider or every tenant.
Provider family
DDoS-Guard
Category
Published campaign infrastructure in shared hosting or VPN space
Actor or campaign
UNC6671 multi-brand vishing, AiTM, and SaaS extortion
How to handle it
Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-08-06
Sources
N17, N01
AS58061SCALAXY-AS Scalaxy B.V.Shared hosting / VPS / cloudT2 HighLVMedium
Conditional fast-flux and shared-hosting context
Evidence
Silent Push included AS58061 in a conditional multi-ASN fast-flux DNS analytic. The source explicitly warns that not every rotating ASN is bulletproof; preserve T2 monitoring but require the full DNS-diversity or identity/behavior context.
Provider family
SCALAXY-AS Scalaxy B.V.
Category
Conditional fast-flux and shared-hosting context
Actor or campaign
Silent Push fast-flux analytic
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
High analytic inclusion; low provider maliciousness
How to handle it
Enabled as T2 context. Do not treat the ASN alone as a malicious verdict.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-09-15
Sources
N01, N38
AS59711HZ-EU-AS HZ Hosting LtdShared hosting / VPS / cloudT3 ContextBGHigh
Campaign watch
Evidence
Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS59711 across Akira and Fog ransomware via SonicWall SSL VPN. This does not implicate the provider or every tenant. Microsoft listed 89.150.45.0 (HZ Hosting), originated by AS59711, as threat actor infrastructure observed with sign-in on 2026-04-06.
Provider family
HZ-EU-AS HZ Hosting Ltd
Category
Campaign watch
Actor or campaign
Akira and Fog ransomware via SonicWall SSL VPN
How to handle it
Risk multiplier only. Raise the risk of a sign-in that already has a device, MFA, session, travel or post-authentication anomaly. Do not alert or block on the ASN alone.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-04-06
Sources
N07, N59, N01
AS60117HS Host Sailor LtdBulletproof / high-risk hosting familyT2 HighAEHigh
Published BPH attribution, older evidence (active)
Evidence
Recorded Future's 2022 report described Host Sailor Ltd as a BPH provider observed in adversary infrastructure and mapped it to AS60117.
Provider family
HostSailor
Category
Published BPH attribution, older evidence (active)
Actor or campaign
adversary command-and-control hosting
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
Medium: explicit provider-level wording but stale public evidence; current posture should be refreshed before punitive action.
How to handle it
Active and announcing routes as Host Sailor Ltd on 2026-09-15. Watch tier only without fresher corroboration.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2022-12-15
Sources
X057, N01
AS60602INOVARE-AS Inovare-Prim SRLShared hosting / VPS / cloudT4 ReviewMDVery High
Campaign watch ended; retained for history
Evidence
Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS60602 across Akira ransomware targeting SonicWall SSL VPN. This does not implicate the provider or every tenant.
Provider family
INOVARE-AS Inovare-Prim SRL
Category
Campaign watch ended; retained for history
Actor or campaign
Akira ransomware targeting SonicWall SSL VPN
How to handle it
Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2025-09-22
Sources
N06, N01
AS61046HZ-UK-AS HZ Hosting LtdShared hosting / VPS / cloudT3 ContextBGHigh
Campaign watch
Evidence
Microsoft listed 185.81.113.0 (HZ Hosting) as threat actor infrastructure observed with sign-in. 185.81.112.0/23 is originated by AS61046.
Provider family
HZ-UK-AS HZ Hosting Ltd
Category
Campaign watch
Actor or campaign
AI-enabled device-code phishing
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
Primary source names the ASN or an address it originated during the activity
How to handle it
Campaign watch: 3 campaigns across the HZ Hosting family (N07, N06, N59).
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-04-06
Sources
N59, N01
AS62005BV-EU-AS BlueVPS OUShared hosting / VPS / cloudT4 ReviewEEVery High
Campaign watch ended; retained for history
Evidence
Published reporting includes 5 time-bounded indicators attributed to or currently mapped to AS62005 across Akira ransomware targeting SonicWall SSL VPN; MuddyWater / BugSleep infrastructure cluster. This does not implicate the provider or every tenant.
Provider family
BlueVPS
Category
Campaign watch ended; retained for history
Actor or campaign
Akira ransomware targeting SonicWall SSL VPN; MuddyWater / BugSleep infrastructure cluster
How to handle it
Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2025-09-22
Sources
N06, N08, N01
AS62240Clouvider Clouvider LimitedShared hosting / VPS / colocation / proxy-exit ecosystemT1 CriticalGBMedium
Local incident plus repeated published identity and intrusion infrastructure
Evidence
Clouvider AS62240 is legitimate global hosting, transit, and proxy-exit infrastructure repeatedly used for credential replay, phishing authentication, malicious VPN access, ransomware access, and C2. The requester also reported a local 2026 compromise. This supports high-priority monitoring, not a claim of provider complicity.
Provider family
Clouvider
Category
Local incident plus repeated published identity and intrusion infrastructure
Actor or campaign
Local 2026 compromise; Proofpoint cloud credential attacks; Tycoon 2FA; human-operated phishing; Akira and Fog ransomware; TAG-53; ToolShell
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
High for repeated use, but no evidence of provider complicity
How to handle it
Immediate triage for successful interactive employee sign-ins. Correlate new device, MFA or passkey changes, token behavior, VPN access, session anomalies, and post-authentication activity before containment.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-09-15
Sources
S04, S06, N01, N06, N07, N08, N09, N10, N11, N12, N13, N14, N16, N34
AS62651NETPROTECT-DP - Strong Technology, LLC.Strong Technology / NetProtectCommercial VPN / hosting / proxyT3 ContextUSMedium-High
Commercial VPN / proxy egress observed in brute-force campaign
Evidence
Time-matched RouteViews mapping attributes 130 IPs across 37 /24s from the Cisco Talos April 2024 brute-force IOC set to this Strong Technology / NetProtect ASN. Treat as commercial VPN/proxy egress context; no provider complicity is asserted.
Provider family
Strong Technology / NetProtect
Category
Commercial VPN / proxy egress observed in brute-force campaign
Actor or campaign
Cisco Talos 2024 VPN and SSH brute-force activity
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
Medium; no provider complicity
How to handle it
Use as a risk enhancer for interactive sign-ins, VPN access, management traffic, and post-authentication anomalies.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-09-15
Sources
N35, N36, N01
AS62904AS62904 - Eonix CorporationShared hosting / VPS / cloudT4 ReviewUSVery High
Campaign watch ended; retained for history
Evidence
Published reporting includes 2 time-bounded indicators attributed to or currently mapped to AS62904 across Akira ransomware targeting SonicWall SSL VPN. This does not implicate the provider or every tenant.
Provider family
AS62904
Category
Campaign watch ended; retained for history
Actor or campaign
Akira ransomware targeting SonicWall SSL VPN
How to handle it
Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2025-09-22
Sources
N06, N01
AS63473HOSTHATCH - HostHatch, LLCShared hosting / VPS / cloudT4 ReviewUSVery High
Campaign watch ended; retained for history
Evidence
Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS63473 across Akira ransomware targeting SonicWall SSL VPN. This does not implicate the provider or every tenant.
Provider family
HOSTHATCH
Category
Campaign watch ended; retained for history
Actor or campaign
Akira ransomware targeting SonicWall SSL VPN
How to handle it
Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2025-09-22
Sources
N06, N01
AS64236UNREAL-SERVERS - UnReal Servers, LLCShared hosting / VPS / cloudT4 ReviewUSVery High
Campaign watch ended; retained for history
Evidence
Published reporting includes 2 time-bounded indicators attributed to or currently mapped to AS64236 across Akira and Fog ransomware via SonicWall SSL VPN; Akira ransomware targeting SonicWall SSL VPN. This does not implicate the provider or every tenant.
Provider family
UNREAL-SERVERS
Category
Campaign watch ended; retained for history
Actor or campaign
Akira and Fog ransomware via SonicWall SSL VPN; Akira ransomware targeting SonicWall SSL VPN
How to handle it
Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2025-09-22
Sources
N07, N06, N01
AS131199NEXEON-AS-AP - Nexeon Technologies, Inc.Shared hosting / VPS / cloudT4 ReviewUSVery High
Campaign watch ended; retained for history
Evidence
Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS131199 across Akira ransomware targeting SonicWall SSL VPN. This does not implicate the provider or every tenant.
Provider family
NEXEON-AS-AP
Category
Campaign watch ended; retained for history
Actor or campaign
Akira ransomware targeting SonicWall SSL VPN
How to handle it
Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2025-09-22
Sources
N06, N01
AS136787PACKETHUBSA-AS-AP - PacketHub S.A.Commercial VPN / hosting / proxyT2 HighPAMedium-High
Commercial VPN / anonymizer infrastructure
Evidence
PacketHub S.A. operates global hosting infrastructure associated with NordVPN exit traffic. Published reporting observed PacketHub infrastructure in token replay, exploitation, and DDoS activity. Monitor unexpected employee logins; there is no evidence of provider complicity.
Provider family
PacketHub
Category
Commercial VPN / anonymizer infrastructure
Actor or campaign
EvilTokens post-compromise Microsoft 365 token replay; NordVPN-associated egress; EvilTokens token replay; exploitation and DDoS observations
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
High for observed infrastructure; no provider complicity
How to handle it
Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-04-06
Sources
N15, N16, N29, N30, N31, N01
AS138915KAOPU-HK - Kaopu Cloud HK LimitedBulletproof / high-risk hosting familyT1 CriticalHKLow
Current Spamhaus ASN-DROP
Evidence
AS138915 is present in the 2026-09-15 Spamhaus ASN-DROP feed. This review did not find a sufficiently authoritative public source tying the entire ASN to Funnull or another named campaign, so no such alias or actor attribution is asserted. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as KAOPU-HK (kaopuyun.com).
Provider family
KAOPU-HK
Category
Current Spamhaus ASN-DROP
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
High for current Spamhaus feed membership; unproven as a named BPH-provider attribution in the reviewed public reporting.
How to handle it
Active and announcing routes as Kaopu Cloud HK Limited on 2026-09-15. Use the live ASN-DROP feed rather than copying this ASN permanently.
Route status
Announced
On Spamhaus ASN-DROP
Yes
Last evidence
2026-09-29
Sources
S01, S02, N01, S03
AS140952STL-AS-AP - Strong Technology, LLCStrong Technology / NetProtectCommercial VPN / hosting / proxyT4 ReviewUSHigh
Commercial VPN provider family expansion
Evidence
Active Strong Technology / NetProtect family ASN without sufficient direct campaign-time evidence for automatic monitoring. Disabled pending local need and validation.
Provider family
Strong Technology / NetProtect
Category
Commercial VPN provider family expansion
Actor or campaign
StrongVPN / Strong Technology family
How to handle it
Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-09-15
Sources
N35, N36, N01
AS141039PACKETHUBSA-AS-AP - PacketHub S.A.Commercial VPN / hosting / proxyT2 HighPAMedium-High
Commercial VPN / anonymizer infrastructure
Evidence
PacketHub S.A. operates global hosting infrastructure associated with NordVPN exit traffic. Published reporting observed PacketHub infrastructure in token replay, exploitation, and DDoS activity. Monitor unexpected employee logins; there is no evidence of provider complicity.
Provider family
PacketHub
Category
Commercial VPN / anonymizer infrastructure
Actor or campaign
NordVPN-associated egress; EvilTokens token replay; exploitation and DDoS observations
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
Medium provider-family association
How to handle it
Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-09-15
Sources
N15, N16, N29, N30, N31, N01
AS147049PACKETHUBSA-AS-AP - PacketHub S.A.Commercial VPN / hosting / proxyT2 HighAUMedium-High
Commercial VPN / anonymizer infrastructure
Evidence
PacketHub S.A. operates global hosting infrastructure associated with NordVPN exit traffic. Published reporting observed PacketHub infrastructure in token replay, exploitation, and DDoS activity. Monitor unexpected employee logins; there is no evidence of provider complicity.
Provider family
PacketHub
Category
Commercial VPN / anonymizer infrastructure
Actor or campaign
NordVPN-associated egress; EvilTokens token replay; exploitation and DDoS observations
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
Medium provider-family association
How to handle it
Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-09-15
Sources
N15, N16, N29, N30, N31, N01
AS149440EVOXTSDNBHD-AS-AP - Evoxt Sdn. Bhd.Shared hosting / VPS / cloudT4 ReviewMYVery High
Campaign watch ended; retained for history
Evidence
Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS149440 across Console Chaos FortiGate management-interface exploitation. This does not implicate the provider or every tenant.
Provider family
EVOXTSDNBHD-AS-AP
Category
Campaign watch ended; retained for history
Actor or campaign
Console Chaos FortiGate management-interface exploitation
How to handle it
Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2025-01-10
Sources
N09, N01
AS154177LIGHT4-AS-AP - LIGHT NODE LIMITEDkaopuyun.comMixed / not independently classifiedT1 CriticalHKMedium
Current Spamhaus ASN-DROP
Evidence
Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as LIGHT4-AS-AP (kaopuyun.com).
Provider family
kaopuyun.com
Category
Current Spamhaus ASN-DROP
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
High exact IOC and RIPEstat origin; ASN-wide maliciousness rests on existing Spamhaus status
How to handle it
Append exact-IP campaign evidence; preserve existing T1 Critical
Route status
Announced
On Spamhaus ASN-DROP
Yes
Last evidence
2026-09-29
Sources
S01, S02, N01, S03
AS197574EXPRESSHOST ExpressHost LtdShared hosting / VPS / cloudT4 ReviewGBHigh
Conditional fast-flux ASN seed
Evidence
Conditional fast-flux analytic includes this ASN. This supports source-scoped review, not provider-wide malicious attribution.
Provider family
ExpressHost Ltd
Category
Conditional fast-flux ASN seed
Actor or campaign
Fast-flux phishing infrastructure
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
High analytic membership, low ASN-wide attribution
How to handle it
Disabled pending independent or local corroboration.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-09-29
Sources
N38, N01
AS197695AS-REGRU "Domain names registrar REG.RU", LtdShared hosting / registrar infrastructureT3 ContextRUHigh
Historical actor infrastructure concentration
Evidence
Microsoft observed more than 70% of 200-plus ACTINIUM operational IPs in AS197695; Unit 42 independently observed 131 of 136 recent downloader IPs there. Both characterize REG.RU as a legitimate provider.
Provider family
REG.RU
Category
Historical actor infrastructure concentration
Actor or campaign
ACTINIUM / Aqua Blizzard / Gamaredon
How to handle it
Use as a risk multiplier. Require at least one corroborating anomaly such as new ASN, impossible travel, unfamiliar device, legacy auth or MFA change.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2022-02-04
Sources
S07, S08, N01
AS198550nodehost-as NODE HOST LIMITEDShared hosting / VPS / cloudT4 ReviewGBHigh
Conditional fast-flux ASN seed
Evidence
Conditional fast-flux analytic includes this ASN. This supports source-scoped review, not provider-wide malicious attribution.
Provider family
NODE HOST LIMITED
Category
Conditional fast-flux ASN seed
Actor or campaign
Fast-flux phishing infrastructure
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
High analytic membership, low ASN-wide attribution
How to handle it
Disabled pending independent or local corroboration.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-09-29
Sources
N38, N01
AS200373Drei-K-Tech-GmbH 3xK Tech GmbH3xK Tech / Plain ProxiesProxy / BYOIP / transit infrastructureT1 CriticalDELow
Current ASN-DROP + recent Microsoft login spraying
Evidence
Huntress reported roughly 1.5 million Microsoft login attempts per day from about 12,800 rotating IPs in AS200373 during July 2026. AS200373 is in the live Spamhaus ASN-DROP feed. Huntress also observed roughly 1.5 million Microsoft login attempts per day from about 12,800 rotating IPs on this ASN in July 2026, following a malicious BYOIP user's moves between providers. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as Drei-K-Tech-GmbH (plainproxies.com).
Provider family
3xK Tech / Plain Proxies
Category
Current ASN-DROP + recent Microsoft login spraying
Actor or campaign
LSHIY password spray
How to handle it
Immediate triage for any successful interactive sign-in. Correlate failures, MFA/device/session changes and user history. Consider deny only after dependency review.
Route status
Announced
On Spamhaus ASN-DROP
Yes
Last evidence
2026-09-29
Sources
S01, S02, S05, X008, N01, S03
AS200651FlokiNET FlokiNET ehfShared hosting / VPS / cloudT2 HighISMedium
Source-described bulletproof hosting monolith
Evidence
Censys identifies FlokiNET AS200651 as a widely recognized bulletproof-hosting monolith. Use for monitoring and triage, not unconditional blocking of every customer.
Provider family
FlokiNET
Category
Source-described bulletproof hosting monolith
Actor or campaign
Bulletproof hosting
Provider role
Source-supported provider or enabler assessment. It does not imply every customer or address is malicious.
Why this confidence
High provider-level wording from Censys
How to handle it
Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-09-15
Sources
N19, N01
AS201002PebbleHost-Customers PebbleHost LtdHosting / VPS / proxyT3 ContextGBHigh
Campaign watch
Evidence
The FBI and USSS observed 193.8.186.33 in FortiBleed brute force from 2026-06-18 to 2026-07-20. 193.8.186.0/24 was originated by AS201002 then and now.
Provider family
PebbleHost
Category
Campaign watch
Actor or campaign
FortiBleed FortiGate SSL-VPN brute force
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
Primary source names the ASN or an address it originated during the activity
How to handle it
T3 until 2027-04-04.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-10-06
Sources
N62, N01
AS201738UFO-TECHNOLOGIES-LIMITED UFO TECHNOLOGIES LIMITEDBearhost-linkedBulletproof / high-risk hosting familyT1 CriticalGBLow
Source-confirmed BPH (active)
Evidence
Spamhaus linked AS201738 to the Bearhost threat actor's BPH comeback and confirmed inclusion in DROP/ASN-DROP. The live feed currently associates the ASN with changway.hk. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as UFO-TECHNOLOGIES-LIMITED (changway.hk).
Provider family
Bearhost-linked
Category
Source-confirmed BPH (active)
Actor or campaign
Bearhost bulletproof-hosting ecosystem
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
High: direct BPH/operator linkage by Spamhaus and current block-feed inclusion.
How to handle it
Active and announcing routes as UFO TECHNOLOGIES LIMITED on 2026-09-15; present in current ASN-DROP.
Route status
Announced
On Spamhaus ASN-DROP
Yes
Last evidence
2026-09-29
Sources
S01, S02, X072, N01, S03
AS201814Mevspace MEVSPACE sp. z o.o.Shared hosting / VPS / cloudT2 HighPLMedium
Published campaign infrastructure in shared hosting or VPN space
Evidence
Published reporting includes 4 time-bounded indicators attributed to or currently mapped to AS201814 across Doko's Panel / ShinyHunters phishing-panel infrastructure; UNC6671 multi-brand vishing, AiTM, and SaaS extortion; UNC6671 phishing infrastructure. This does not implicate the provider or every tenant.
Provider family
MEVSPACE
Category
Published campaign infrastructure in shared hosting or VPN space
Actor or campaign
Doko's Panel / ShinyHunters phishing-panel infrastructure; UNC6671 multi-brand vishing, AiTM, and SaaS extortion; UNC6671 phishing infrastructure
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
High for exact infrastructure; medium at ASN level
How to handle it
Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-08-06
Sources
N18, N17, N21, N01
AS202015HZ-US-AS HZ Hosting LtdShared hosting / VPS / cloudT3 ContextBGHigh
Campaign watch
Evidence
Published reporting includes 4 time-bounded indicators attributed to or currently mapped to AS202015 across Akira and Fog ransomware via SonicWall SSL VPN; Akira ransomware targeting SonicWall SSL VPN. This does not implicate the provider or every tenant.
Provider family
HZ-US-AS HZ Hosting Ltd
Category
Campaign watch
Actor or campaign
Akira and Fog ransomware via SonicWall SSL VPN; Akira ransomware targeting SonicWall SSL VPN
How to handle it
Risk multiplier only. Raise the risk of a sign-in that already has a device, MFA, session, travel or post-authentication anomaly. Do not alert or block on the ASN alone.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-04-06
Sources
N07, N06, N59, N01
AS202412OMEGATECH-AS Omegatech LTDVirtualineBulletproof / high-risk hosting familyT1 CriticalSCLow
Source-confirmed BPH (active)
Evidence
Spamhaus identified Virtualine as a BPH operation and the January-June 2026 Spamhaus botnet report ranked it fifth among newly observed networks with 382 C2 observations and seventeenth among active networks. AS202412 remains in ASN-DROP. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as OMEGATECH-AS (virtualine.org).
Provider family
Virtualine
Category
Source-confirmed BPH (active)
Actor or campaign
bulletproof hosting; botnet command-and-control
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
High: direct BPH attribution, sustained measured C2 concentration, and current block-feed inclusion.
How to handle it
Active and announcing routes as Omegatech LTD on 2026-09-15; present in current ASN-DROP.
Route status
Announced
On Spamhaus ASN-DROP
Yes
Last evidence
2026-09-29
Sources
S01, S02, X075, N01, S03
AS203020HostRoyale HostRoyale Technologies Pvt LtdShared hosting / VPS / cloudT4 ReviewINVery High
Campaign watch ended; retained for history
Evidence
Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS203020 across MuddyWater / BugSleep infrastructure cluster. This does not implicate the provider or every tenant.
Provider family
HostRoyale
Category
Campaign watch ended; retained for history
Actor or campaign
MuddyWater / BugSleep infrastructure cluster
How to handle it
Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-01-28
Sources
N08, N01
AS204957GREENFLOID-AS ROUTE 95 LLCHosting / VPS / proxyT4 ReviewUSVery High
Campaign watch ended; retained for history
Evidence
eSentire saw post-takedown Tycoon 2FA Microsoft 365 login attempts from AS204957.
Provider family
GREEN FLOID
Category
Campaign watch ended; retained for history
Actor or campaign
Tycoon 2FA AiTM operator logins
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
Primary source names the ASN or an address it originated during the activity
How to handle it
Campaign watch ended 2026-09-28: 1 campaign (N10), newest report 2026-04-01.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-04-01
Sources
N10, N01
AS204997FIRSTBYTE-AS FIRST SERVER LIMITEDShared hosting / VPS / cloudT3 ContextGBMedium
Related provider or broad shared-service context
Evidence
Active related network for FIRST SERVER. No direct provider-level malicious designation was established; retain as enabled T3 risk context and require at least one corroborating identity or behavioral anomaly.
Provider family
FIRST SERVER
Category
Related provider or broad shared-service context
Actor or campaign
Reused VM, C2, and brute-force-as-a-service infrastructure
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
Medium; shared infrastructure
How to handle it
Use as a risk enhancer for interactive sign-ins, VPN access, management traffic, and post-authentication anomalies.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-09-15
Sources
N19, N22, N01
AS205090FIRST-SERVER-EUROPE FIRST SERVER LIMITEDShared hosting / VPS / cloudT3 ContextGBMedium
Published campaign infrastructure in shared hosting or VPN space
Evidence
Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS205090 across Reverse-connection endpoint exposed with C2 and persistence tooling. This does not implicate the provider or every tenant.
Provider family
FIRST SERVER
Category
Published campaign infrastructure in shared hosting or VPN space
Actor or campaign
Reverse-connection endpoint exposed with C2 and persistence tooling; Reused VM, C2, and brute-force-as-a-service infrastructure
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
Medium; shared infrastructure and current IP mapping changed
How to handle it
Use as a risk enhancer for interactive sign-ins, VPN access, management traffic, and post-authentication anomalies.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-02-03
Sources
N19, N22, N01
AS206728MEDIALAND-AS Media Land LLCMedia Land / ML CloudBulletproof / high-risk hosting familyT1 CriticalRUMedium
Source-confirmed sanctioned BPH (active)
Evidence
Team Cymru maps sanctioned Media Land to AS206728 and found the network continuing to announce infrastructure and host suspicious domains after designation. Treasury described Media Land as a BPH provider supporting ransomware and attacks against U.S. critical infrastructure. Government and technical reporting identify Media Land as bulletproof-hosting infrastructure. AS206728 remains in current ASN-DROP. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as MEDIALAND-AS (sshvps.net).
Provider family
Media Land / ML Cloud
Category
Source-confirmed sanctioned BPH (active)
Actor or campaign
LockBit; BlackSuit; Play ransomware; phishing; brute-force attacks; malware delivery
Provider role
Source-supported provider or enabler assessment. It does not imply every customer or address is malicious.
Why this confidence
High: exact ASN mapping, provider-level government designation, and post-designation activity measurement. High provider designation and historical ASN identity; verify current feed/routes separately
How to handle it
Active and announcing routes as Media Land LLC on 2026-09-15; present in the current Spamhaus ASN-DROP snapshot. Append official designation source and fresh service-model evidence; preserve T1
Route status
Announced
On Spamhaus ASN-DROP
Yes
Last evidence
2026-09-29
Sources
S01, S02, S11, S20, N01, S03
AS207137PACKETHUBSA PacketHub S.A.Commercial VPN / hosting / proxyT2 HighPAMedium-High
Commercial VPN / anonymizer infrastructure
Evidence
PacketHub S.A. operates global hosting infrastructure associated with NordVPN exit traffic. Published reporting observed PacketHub infrastructure in token replay, exploitation, and DDoS activity. Monitor unexpected employee logins; there is no evidence of provider complicity.
Provider family
PacketHub
Category
Commercial VPN / anonymizer infrastructure
Actor or campaign
NordVPN-associated egress; EvilTokens token replay; exploitation and DDoS observations
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
Medium provider-family association
How to handle it
Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-09-15
Sources
N15, N16, N29, N30, N31, N01
AS207461host-industry HOSTING INDUSTRY LIMITEDShared hosting / VPS / cloudT4 ReviewGBHigh
Point-IOC provider context
Evidence
Current origin of repeated Settra MeshAgent C2 endpoint 193.5.65.114. This supports source-scoped review, not provider-wide malicious attribution.
Provider family
HOSTING INDUSTRY LIMITED
Category
Point-IOC provider context
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
High exact-IP incident evidence; medium network inference
How to handle it
Independent current abuse concentration or direct successful sign-in campaign evidence required for ASN-wide alert escalation
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-09-29
Sources
N41, N01
AS209378INIOS-AS Inios OyShared hosting / VPS / cloudT4 ReviewFIHigh
Conditional fast-flux ASN seed
Evidence
Conditional fast-flux analytic includes this ASN. This supports source-scoped review, not provider-wide malicious attribution.
Provider family
Inios Oy
Category
Conditional fast-flux ASN seed
Actor or campaign
Fast-flux phishing infrastructure
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
High analytic membership, low ASN-wide attribution
How to handle it
Disabled pending independent or local corroboration.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-09-29
Sources
N38, N01
AS209588FLYSERVERS-ASN Flyservers S.A.Bulletproof / high-risk hosting familyT2 HighPAMedium-High
Published BPH attribution, older evidence (active)
Evidence
Recorded Future's 2022 report explicitly identified Flyservers S.A. as a known BPH provider and mapped AS209588 to it in the report's ASN table.
Provider family
Flyservers
Category
Published BPH attribution, older evidence (active)
Actor or campaign
adversary command-and-control hosting
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
Medium: explicit provider-level classification, tempered by the age of the public report.
How to handle it
Active and announcing routes as Flyservers S.A. on 2026-09-15. Watch/step-up tier pending fresh corroboration.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2022-12-15
Sources
X057, N01
AS209847THE WorkTitans B.V.Stark / PQ.Hosting / THE.Hosting / UFOBulletproof / high-risk hosting familyT1 CriticalNLMedium
Sanctioned threat-activity-enabler successor (active)
Evidence
Recorded Future documented AS209847 as a newly created network for THE.Hosting, the brand succeeding PQ.Hosting/Stark Industries, and assessed continued operation despite sanctions and ownership changes. Research tracks AS44477 through PQ.Hosting/THE.Hosting changes, creation of AS209847 and Russian infrastructure migration to AS33993. AS209847 and AS33993 are in current ASN-DROP; AS44477 is currently unannounced. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as THE (stark-industries.solutions).
Provider family
Stark / PQ.Hosting / THE.Hosting / UFO
Category
Sanctioned threat-activity-enabler successor (active)
Actor or campaign
Russian state-sponsored operations; Iranian state-sponsored operations; DPRK operations; Chinese state-sponsored operations; cybercrime infrastructure
Provider role
Source-supported provider or enabler assessment. It does not imply every customer or address is malicious.
Why this confidence
High for infrastructure continuity; provider is best treated as a sanctioned threat-actor enabler/successor rather than proof every hosted workload is malicious.
How to handle it
Active and announcing routes as WorkTitans B.V. on 2026-09-15; present in the current Spamhaus ASN-DROP snapshot.
Route status
Announced
On Spamhaus ASN-DROP
Yes
Last evidence
2026-09-29
Sources
S01, S02, S12, S13, N01, S03
AS210328ALMAZ AO ALMAZHosting / VPS / proxyT3 ContextRUHigh
Campaign watch
Evidence
Current origin of 185.136.15.0/24. The FBI and USSS observed 185.136.15.43 and 185.136.15.66 in FortiBleed brute force from 2026-06-27 to 2026-07-23, when the prefix was originated by ASN-DROP listed AS205997, which stopped originating in August.
Provider family
AO ALMAZ
Category
Campaign watch
Actor or campaign
FortiBleed FortiGate SSL-VPN brute force
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
Primary source names the ASN or an address it originated during the activity
How to handle it
T3 until 2027-04-04.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-10-06
Sources
N62, N01
AS210558services-1337-gmbh 1337 Services GmbHas210558.netMixed / not independently classifiedT1 CriticalDEMedium
Current Spamhaus ASN-DROP
Evidence
Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as services-1337-gmbh (as210558.net).
Provider family
as210558.net
Category
Current Spamhaus ASN-DROP
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
High report metrics
How to handle it
Append anti-abuse report context; no tier change
Route status
Announced
On Spamhaus ASN-DROP
Yes
Last evidence
2026-09-29
Sources
S01, S02, N01, S03
AS210644AEZA-AS AEZA GROUP LLCBulletproof / high-risk hosting familyT1 CriticalRUMedium
Source-confirmed sanctioned BPH (active)
Evidence
Silent Push identifies AS210644 as Aeza bulletproof-hosting infrastructure and documents post-sanctions route migration to Hypercore. U.S. Treasury separately designated Aeza Group for providing BPH to infostealers, ransomware actors and illicit markets. OFAC designated Aeza Group as a bulletproof hosting provider. Technical research maps the family to AS210644 and AS216246; both are in current ASN-DROP. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as AEZA-AS (aeza.net).
Provider family
Aeza Group
Category
Source-confirmed sanctioned BPH (active)
Actor or campaign
Meduza Stealer; Lumma Stealer; BianLian; RedLine Stealer; BlackSprut; Doppelgänger; DDoSia
Provider role
Source-supported provider or enabler assessment. It does not imply every customer or address is malicious.
Why this confidence
High: the ASN-to-provider mapping is explicit and the provider itself was sanctioned as BPH; this is provider-level evidence, not merely one malicious tenant.
How to handle it
Active and announcing routes as Aéza International Limited on 2026-09-15; also present in the 2026-09-15 Spamhaus ASN-DROP snapshot. Revalidate holder and announcements before enforcement.
Route status
Announced
On Spamhaus ASN-DROP
Yes
Last evidence
2026-09-29
Sources
S01, S02, S09, S14, N01, S03
AS211632ORG-ISI14-RIPE Internet Solutions & Innovations LTD.Hosting / VPS / proxyT4 ReviewSCVery High
Campaign watch ended; retained for history
Evidence
GreyNoise attributed most of over 9 million GlobalProtect login sessions, late September to mid-October 2025, to four ASNs including AS211632.
Provider family
Internet Solutions & Innovations
Category
Campaign watch ended; retained for history
Actor or campaign
Palo Alto GlobalProtect login brute force
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
Primary source names the ASN or an address it originated during the activity
How to handle it
Campaign watch ended 2026-06-02: 1 campaign (N60), newest report 2025-12-04.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2025-12-04
Sources
N60, N01
AS211663GALEON-AS GALEON LLCBearhost-linkedBulletproof / high-risk hosting familyT1 CriticalRULow
Source-confirmed BPH (active)
Evidence
Spamhaus linked AS211663 to the Bearhost threat actor's BPH return and placed it in DROP/ASN-DROP. The live ASN-DROP feed currently associates it with changway.hk. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as GALEON-AS (changway.hk).
Provider family
Bearhost-linked
Category
Source-confirmed BPH (active)
Actor or campaign
Bearhost bulletproof-hosting ecosystem
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
High: direct BPH/operator linkage by Spamhaus and current block-feed inclusion.
How to handle it
Active and announcing routes as GALEON LLC on 2026-09-15; present in current ASN-DROP.
Route status
Announced
On Spamhaus ASN-DROP
Yes
Last evidence
2026-09-29
Sources
S01, S02, X072, N01, S03
AS212171Local-as Local NCC Ltd.Hosting / VPS / proxyT3 ContextGBHigh
Campaign watch
Evidence
The FBI and USSS FortiBleed advisory lists 185.199.199.56 (observed 2026-06-25) among IPs conducting brute force or authenticating with compromised accounts. 185.199.196.0/22 was originated by AS212171 during the activity and is now originated by AS213929.
Provider family
Local NCC
Category
Campaign watch
Actor or campaign
FortiBleed FortiGate SSL-VPN brute force
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
Primary source names the ASN or an address it originated during the activity
How to handle it
T3 until 2027-04-04.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-10-06
Sources
N62, N01
AS212238CDNEXT Datacamp LimitedShared hosting / VPS / cloudT2 HighGBMedium
Commercial VPN / anonymizer infrastructure
Evidence
Datacamp (CDN77, DataPacket) hosts commercial VPN and anonymizer services (Netify). Proofpoint's TeamFiltration report shows the actor's post-access VPN pivot from 149.88.104.19, originated by AS212238, in 2026. Arctic Wolf also published one Console Chaos management-interface indicator here.
Provider family
CDNEXT Datacamp Limited
Category
Commercial VPN / anonymizer infrastructure
Actor or campaign
UNK_CondorFiltration post-access VPN pivot; Console Chaos FortiGate management-interface exploitation
How to handle it
Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-09-22
Sources
N09, N57, N64, N01
AS213250ITP-SOLUTIONS Dominic Scholz trading as ITP-Solutions GmbH & Co. KGHosting / VPS / proxyT3 ContextDEHigh
Campaign watch
Evidence
Microsoft published 45.131.66.106 as a Storm-3168 source for App Service probing and malicious Azure Resource Manager requests made with compromised service principals. 45.131.66.0/23 was originated by AS213250 during the activity and still is.
Provider family
ITP-Solutions
Category
Campaign watch
Actor or campaign
Storm-3168 compromised service principals
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
Primary source names the ASN or an address it originated during the activity
How to handle it
T3 until 2027-03-24.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-09-25
Sources
N52, N01
AS213511VSVK VSVK Onderhoud B.V.Bulletproof / high-risk hosting familyT4 ReviewNLN/A
Unannounced or low-visibility ASN retained for review
Evidence
Recorded Future found that AS213511 used the identity of an unrelated Dutch construction company and operated through the Railnet ecosystem; the legitimate VSVK business denied involvement. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as VSVK (vonie.net).
Provider family
VSVK
Category
Unannounced or low-visibility ASN retained for review
Actor or campaign
malicious infrastructure registration; Railnet ecosystem
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
High for fraudulent historical registration; that is not evidence against the impersonated legitimate company.
How to handle it
Not announcing routes on 2026-09-15, though the ASN remains in the current Spamhaus ASN-DROP feed. Do not label the impersonated company malicious.
Route status
Not currently originating
On Spamhaus ASN-DROP
Yes
Last evidence
2026-09-29
Sources
S01, S02, X031, N01, S03
AS213929UP-NETWORK UP-NETWORK SarlHosting / VPS / proxyT3 ContextCHHigh
Campaign watch
Evidence
Current origin of 185.199.196.0/22, which held 185.199.199.56 when the FBI and USSS observed it in FortiBleed brute force on 2026-06-25 under AS212171.
Provider family
UP-NETWORK
Category
Campaign watch
Actor or campaign
FortiBleed FortiGate SSL-VPN brute force
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
Primary source names the ASN or an address it originated during the activity
How to handle it
T3 until 2027-04-04.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-10-06
Sources
N62, N01
AS213999THE-CLIENTS WorkTitans B.V.THE.Hosting clientsBulletproof / high-risk hosting familyT4 ReviewNLN/A
Unannounced or low-visibility ASN retained for review
Evidence
The 2026-09-15 Spamhaus ASN-DROP feed associates AS213999 with stark-industries.solutions. This is a current block-oriented source signal, but no independent provider-level campaign attribution was established in this review. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as THE-CLIENTS (stark-industries.solutions).
Provider family
THE.Hosting clients
Category
Unannounced or low-visibility ASN retained for review
Actor or campaign
Stark/PQ.Hosting/THE.Hosting infrastructure
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
High for current feed inclusion; medium for analytical attribution because this row relies on the live feed rather than a detailed public case report.
How to handle it
Not announcing routes on 2026-09-15 despite current ASN-DROP inclusion. Treat as a tombstone until route and holder are revalidated.
Route status
Not currently originating
On Spamhaus ASN-DROP
Yes
Last evidence
2026-09-29
Sources
S01, S02, N01, S03
AS214238iwihost HOST TELECOM LTDCommercial VPN / hosting / proxyT4 ReviewGBVery High
Campaign watch ended; retained for history
Evidence
eSentire saw post-takedown Tycoon 2FA Microsoft 365 login attempts from AS214238, and ProxyLine use through it in Gmail-targeted campaigns since at least February 2026.
Provider family
HOST TELECOM
Category
Campaign watch ended; retained for history
Actor or campaign
Tycoon 2FA AiTM operator logins
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
Primary source names the ASN or an address it originated during the activity
How to handle it
Campaign watch ended 2026-09-28: 1 campaign (N10), newest report 2026-04-01.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-04-01
Sources
N10, N01
AS214351FEMOIT FEMO IT SOLUTIONS LIMITEDBulletproof / high-risk hosting familyT1 CriticalGBMedium
Source-confirmed BPH (active)
Evidence
Recorded Future assessed with high confidence that AS214351 is controlled by Defhost, a service that openly markets resilience to governments, regulators and Spamhaus. The report observed numerous malware and C2 families in its space. AS214351 is in live Spamhaus ASN-DROP. Recorded Future found one of the highest validated-malicious-infrastructure concentrations relative to size, including Cobalt Strike, DcRat, Rhadamanthys, TinyLoader and THC Hydra C2, and assessed with high confidence that Femo is controlled by Defhost, which advertises abuse-resistant VDS. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as FEMOIT (as214351.com).
Provider family
Femo IT Solutions
Category
Source-confirmed BPH (active)
Actor or campaign
Cobalt Strike; DcRat; Rhadamanthys; TinyLoader; THC Hydra; Amadey; QuasarRAT; RedLine Stealer; REMCOS; Stealc; SystemBC; SvcStealer; CastleLoader
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
High: provider-control assessment, abuse-resilience marketing, multiple independent malware families, and current ASN-DROP inclusion collectively exceed one-off rental evidence. High report metrics
How to handle it
Active and announcing routes as FEMO IT SOLUTIONS LIMITED on 2026-09-15; present in the current Spamhaus ASN-DROP snapshot. Append anti-abuse report context; no tier change
Route status
Announced
On Spamhaus ASN-DROP
Yes
Last evidence
2026-09-29
Sources
S01, S02, S05, X003, X031, N01, S03
AS215439PLAY2GO-NET PLAY2GO INTERNATIONAL LIMITEDShared hosting / VPS / cloudT4 ReviewGBHigh
Conditional fast-flux ASN seed
Evidence
Conditional fast-flux analytic includes this ASN. This supports source-scoped review, not provider-wide malicious attribution.
Provider family
PLAY2GO INTERNATIONAL LIMITED
Category
Conditional fast-flux ASN seed
Actor or campaign
Fast-flux phishing infrastructure
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
High analytic membership, low ASN-wide attribution
How to handle it
Disabled pending independent or local corroboration.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-09-29
Sources
N38, N01
AS215540GCS-AS GLOBAL CONNECTIVITY SOLUTIONS LLPHosting / VPS / proxyT3 ContextGBHigh
Campaign watch
Evidence
eSentire saw pre-takedown Tycoon 2FA Microsoft 365 login attempts from AS215540. 185.168.208.102, an Akira SonicWall VPN client IP published by Arctic Wolf in 2025, is now originated by AS215540.
Provider family
Global Connectivity Solutions
Category
Campaign watch
Actor or campaign
Tycoon 2FA AiTM operator logins; Akira ransomware targeting SonicWall SSL VPN
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
Primary source names the ASN or an address it originated during the activity
How to handle it
Campaign watch: 2 campaigns (N06, N10).
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-04-01
Sources
N10, N06, N01
AS215703FREAKHOSTING FREAKHOSTING LTDShared hosting / VPS / cloudT4 ReviewGBVery High
Campaign watch ended; retained for history
Evidence
Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS215703 across Akira ransomware targeting SonicWall SSL VPN. This does not implicate the provider or every tenant.
Provider family
FREAKHOSTING FREAKHOSTING LTD
Category
Campaign watch ended; retained for history
Actor or campaign
Akira ransomware targeting SonicWall SSL VPN
How to handle it
Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2025-09-22
Sources
N06, N01
AS215929datacampus Data Campus LimitedHosting / VPS / proxyT4 ReviewHKVery High
Campaign watch ended; retained for history
Evidence
GreyNoise attributed most of over 9 million GlobalProtect login sessions, late September to mid-October 2025, to four ASNs including AS215929.
Provider family
Data Campus
Category
Campaign watch ended; retained for history
Actor or campaign
Palo Alto GlobalProtect login brute force
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
Primary source names the ASN or an address it originated during the activity
How to handle it
Campaign watch ended 2026-06-02: 1 campaign (N60), newest report 2025-12-04.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2025-12-04
Sources
N60, N01
AS216246RU-AEZA-AS Aeza Group LLCBulletproof / high-risk hosting familyT1 CriticalRUMedium
Source-confirmed sanctioned BPH (active)
Evidence
Silent Push explicitly maps AS216246 to Aeza Group and calls Aeza a sanctioned BPH provider. Treasury described Aeza as supplying infrastructure to malware, ransomware and illicit-drug-market operators. OFAC designated Aeza Group as a bulletproof hosting provider. Technical research maps the family to AS210644 and AS216246; both are in current ASN-DROP. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as RU-AEZA-AS (aeza.net).
Provider family
Aeza Group
Category
Source-confirmed sanctioned BPH (active)
Actor or campaign
Meduza Stealer; Lumma Stealer; BianLian; RedLine Stealer; BlackSprut
Provider role
Source-supported provider or enabler assessment. It does not imply every customer or address is malicious.
Why this confidence
High: explicit ASN mapping plus government provider-level sanctions designation.
How to handle it
Active and announcing routes as Aeza Group LLC on 2026-09-15; also present in the current Spamhaus ASN-DROP snapshot.
Route status
Announced
On Spamhaus ASN-DROP
Yes
Last evidence
2026-09-29
Sources
S01, S02, S09, S14, N01, S03
AS219067CHIARA-AS Chiara ContiBulletproof / high-risk hosting familyT1 CriticalITLow
Current malicious prefix-hopping network
Evidence
Spamhaus tied AS219067's sole prefix to Roblox phishing, documented deliberate prefix-hopping behavior, and placed the network in SBL/DROP. This is strong malicious-network evidence but not a generalized BPH-provider attribution. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as CHIARA-AS (eggywall.org).
Provider family
CHIARA-AS
Category
Current malicious prefix-hopping network
Actor or campaign
Roblox credential phishing; prefix hopping
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
High for current malicious operation; category intentionally avoids claiming a broader BPH service without evidence.
How to handle it
Active and announcing routes as Chiara Conti/CHIARA-AS on 2026-09-15; present in current ASN-DROP.
Route status
Announced
On Spamhaus ASN-DROP
Yes
Last evidence
2026-09-29
Sources
S01, S02, X074, N01, S03
AS267784AS267784 - Flyservers S.A.Bulletproof / high-risk hosting familyT3 ContextPAHigh
Campaign watch
Evidence
The FBI and USSS observed 45.227.254.210 in FortiBleed brute force from 2026-06-18 to 2026-07-23. 45.227.254.0/24 was originated by AS267784 then and now. Sibling of Flyservers AS209588, already T2 High.
Provider family
Flyservers
Category
Campaign watch
Actor or campaign
FortiBleed FortiGate SSL-VPN brute force
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
Primary source names the ASN or an address it originated during the activity
How to handle it
T3 until 2027-04-04.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-10-06
Sources
N62, N01
AS272096AS272096 - PACKETHUB S.A.Commercial VPN / hosting / proxyT2 HighPAMedium-High
Commercial VPN / anonymizer infrastructure
Evidence
PacketHub S.A. operates global hosting infrastructure associated with NordVPN exit traffic. Published reporting observed PacketHub infrastructure in token replay, exploitation, and DDoS activity. Monitor unexpected employee logins; there is no evidence of provider complicity.
Provider family
PacketHub
Category
Commercial VPN / anonymizer infrastructure
Actor or campaign
NordVPN-associated egress; EvilTokens token replay; exploitation and DDoS observations
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
Medium provider-family association
How to handle it
Alert on successful interactive employee sign-ins. Require device, MFA, session, travel, or post-authentication corroboration before containment.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-09-15
Sources
N15, N16, N29, N30, N31, N01
AS394711KORGRID - KorGrid, LLCShared hosting / VPS / cloudT4 ReviewUSCritical
Historical LIMENET evidence; current-holder continuity unresolved
Evidence
Censys described historical LIMENET AS394711 as a known bulletproof-hosting monolith; Rapid7 and time-matched Cisco Talos data add historical abuse context. The current holder is KORGRID / KorGrid LLC. Continuity or reassignment is unresolved, so the BPH label is not carried to the current holder and the row remains disabled.
Provider family
KorGrid
Category
Historical LIMENET evidence; current-holder continuity unresolved
Actor or campaign
Historical ransomware malvertising and brute-force infrastructure
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
Historical evidence only; do not transfer reputation to current holder
How to handle it
Disabled by default. Use exact IOCs or enable only after tenant dependency, geography, and false-positive review.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-09-15
Sources
N19, N35, N37, N01
AS396356LATITUDE-SH - Latitude.shShared hosting / VPS / cloudT4 ReviewUSVery High
Campaign watch ended; retained for history
Evidence
Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS396356 across Akira ransomware targeting SonicWall SSL VPN. This does not implicate the provider or every tenant.
Provider family
LATITUDE-SH
Category
Campaign watch ended; retained for history
Actor or campaign
Akira ransomware targeting SonicWall SSL VPN
How to handle it
Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2025-09-22
Sources
N06, N01
AS399629BLNWX - BL NetworksShared hosting / VPS / cloudT4 ReviewUSVery High
Campaign watch ended; retained for history
Evidence
Published reporting includes 1 time-bounded indicator attributed to or currently mapped to AS399629 across Console Chaos FortiGate management-interface exploitation. This does not implicate the provider or every tenant.
Provider family
BLNWX
Category
Campaign watch ended; retained for history
Actor or campaign
Console Chaos FortiGate management-interface exploitation
How to handle it
Disabled by default. Campaign history only: use the cited indicators for retro-hunts and re-enable if the network appears in new identity-attack reporting.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2025-01-10
Sources
N09, N01
AS399979AS-493NETWORKING - 49.3 Networking LLCBulletproof / high-risk hosting familyT1 CriticalUSLow
Source-confirmed BPH (active)
Evidence
Spamhaus publicly identified AS399979/49.3 Networking as a bulletproof host and described the operator as using a Delaware shell company. The ASN remains in the live ASN-DROP feed. Listed in the 2026-09-29 Spamhaus ASN-DROP snapshot as AS-493NETWORKING (493networking.cc).
Provider family
AS-493NETWORKING
Category
Source-confirmed BPH (active)
Actor or campaign
bulletproof hosting; cybercriminal infrastructure
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
High: explicit BPH attribution by Spamhaus plus current ASN-DROP inclusion; the ASN announces a very small footprint, reducing carrier-scale collateral risk.
How to handle it
Active and announcing routes as 49.3 Networking LLC on 2026-09-15; present in current Spamhaus ASN-DROP.
Route status
Announced
On Spamhaus ASN-DROP
Yes
Last evidence
2026-09-29
Sources
S01, S02, X071, N01, S03
AS400940RAILWAY - RailwayShared hosting / VPS / cloudT4 ReviewUSVery High
Campaign watch ended; retained for history
Evidence
Huntress tied a device-code phishing and token replay campaign against 344 organizations, 2026-02-19 to mid-March 2026, to Railway PaaS ranges 162.220.232.0/22 and 162.220.234.0/22, with 162.220.234.41 the dominant token engine. Microsoft listed both ranges as threat actor infrastructure observed with sign-in on 2026-04-06.
Provider family
Railway
Category
Campaign watch ended; retained for history
Actor or campaign
EvilTokens device-code phishing and M365 token replay
Provider role
Observed infrastructure use. No provider-complicity claim.
Why this confidence
Primary source names the ASN or an address it originated during the activity
How to handle it
Campaign watch ended 2026-10-03: 1 campaign (N58, N59), newest report 2026-04-06.
Route status
Announced
On Spamhaus ASN-DROP
No
Last evidence
2026-04-06
Sources
N58, N59, N01

Clouvider AS62240

Clouvider is a legitimate hosting and transit business, and AS62240 carries the catalog’s top tier. Both of those statements are true at once, which makes it the clearest illustration of what the tiering does and does not claim.

The network appears repeatedly in published reporting across credential replay, phishing authentication, malicious VPN access, ransomware access and command and control, and it also featured in a local compromise reported during 2026. Named activity associated with it in the catalog includes Tycoon 2FA, TAG-53, Akira, Fog and ToolShell. That accumulation of independent sightings is what supports immediate triage of a successful interactive employee sign-in from it.

It does not support a claim about Clouvider’s conduct as a company, and the row says so explicitly in its provider role field. The false-positive risk is recorded as medium, not low, and two related Clouvider networks sit in the review-only set at the context tier precisely because the evidence that justifies AS62240 does not transfer to them by association. A provider’s other networks are a separate question, and treating them as one decision is a common way to generate false positives while feeling thorough.

PacketHub, NordVPN egress and the anonymizer problem

Five active PacketHub networks are classified as commercial VPN and anonymizer infrastructure, and the catalog is deliberate about not calling them bulletproof hosting. These are a consumer VPN product’s exit capacity, which carries a different handling profile entirely.

One of the five carries direct token-replay evidence from device-code phishing activity. The rest are included as provider family rather than on individual evidence, and their confidence field records exactly that weaker basis. All five sit at the high tier with a medium to high false-positive risk, because the thing that makes them worth watching also makes them noisy: a legitimate employee with a NordVPN subscription arrives from the same place.

The operational answer is a policy decision before it is a detection decision. If consumer VPN use on managed devices is not expected in your environment, these networks are worth an alert and the alert will be meaningful. If it is tolerated or common, step-up authentication is the better response, and you will want these rows as context attached to other signals instead of a trigger of their own.

GTHost, and why Spamhaus ASN-DROP delisting is not exoneration

GTHost is a small, useful case study in reading feed membership over time. AS63023 was present in the Spamhaus ASN-DROP snapshot of 15 September 2026 and absent from the snapshot two weeks later. It remains in this catalog at the context tier.

Leaving a feed is a change in that feed. A delisting describes that list’s current contents and says nothing about whether the underlying network changed. Spamhaus reporting in the first half of 2026 separately identified GlobalTeleHost among newly prominent botnet command and control networks, and that observation did not expire when the ASN-DROP entry did. The row is kept at the context tier with a high false-positive risk, which is the honest position: enough to be worth correlating, not enough to alert on alone.

The same reasoning runs in the other direction. Appearing on ASN-DROP is current, high-confidence network risk and it is not proof that every customer of that network is malicious. Membership is a strong input to a tier and it is never the only one.

Bulletproof hosting ASNs and sanctioned networks

A smaller group of networks is in a genuinely different category, where the evidence speaks to the provider’s business and not merely to activity that happened to occur there. Spamhaus described Netiface in provider-level bulletproof-hosting terms directly. Media Land and Aeza are source-confirmed bulletproof hosting under sanctions. UFO Hosting is assessed by Recorded Future with high confidence as a successor to Stark infrastructure, and WorkTitans appears as another sanctioned successor entity. Others in the set are source-confirmed active bulletproof hosting, one is tracked as a current malicious prefix-hopping network, and one is recorded as a facilitator carrying upstream risk rather than hosting the activity itself.

These rows carry the top tier with a low to medium false-positive risk, which is unusually low for this catalog and reflects that very little legitimate enterprise traffic originates there. The confidence field on each one records whether the basis is a direct provider-level assessment or a successor and control relationship. Those are different strengths of claim, and collapsing them would overstate the weaker ones.

Joint guidance from CISA, NSA, FBI and international partners on mitigating bulletproof hosting risk is one of the sources behind this section, and it is also the source of a caution worth repeating: whole-ASN blocking affects legitimate services, so baselining, allowlisting and logging come before any deny decision.

Current credential campaigns and edge device infrastructure

Infrastructure rotates faster than tiers do, so the catalog separates ASN-level risk from exact indicators, each carrying its own observation window. Several campaign families drive the current indicator set.

Adversary-in-the-middle phishing kits remain the dominant credential theft route into Microsoft 365, and the catalog tracks both reverse-proxy infrastructure and the phishing-panel backends behind it. Device-code phishing and token replay are represented by their own detection patterns, because the sequence they produce in the logs is distinctive: the same identity and token appearing across different networks, addresses and user agents within minutes.

Anomalous application identifiers are a particularly clean signal when you have them. The catalog carries specific client and resource identifiers observed in campaign activity, including the broker application identifier abused by Tycoon 2FA. Alerting when an unexpected application identifier appears in your tenant’s authentication logs costs very little and does not depend on any network judgement at all.

Edge devices produce the fastest chains in the whole dataset. SonicWall SSL VPN access associated with Akira ransomware activity, and FortiGate management access followed by account creation, VPN configuration changes and credential access, both move from initial access to impact within hours. The detection patterns for those sequences correlate a hosting or VPN origin login with what happens immediately afterwards, which is the only part of the chain fast enough to matter.

Provider families, because a provider is one decision

A hosting business announcing thirty autonomous systems is one handling decision, not thirty. Working ASN by ASN through a family produces inconsistent coverage, where some of a provider’s networks are monitored and others are not for no reason anyone recorded. The family view is how to avoid that.

It also shows where concentration genuinely sits. The largest single family in the enabled set is a Moldovan hosting operation whose networks are almost entirely top tier, which is a more useful thing to know than any individual row within it.

Provider families by enabled ASN count
Provider familyEnabledT1T2T3T4Holder countries
kontrast.md3434002MD:36
Unclassified170314114BR:33, RU:17, MD:13, UA:12, MX:7, US:6, AR:5, IN:5, GB:3, AL:2, AM:2, CO:2, DE:2, HK:2, ID:2, TR:2, VE:2, AE:1, AT:1, DO:1, EC:1, ES:1, GT:1, IQ:1, IR:1, KE:1, LB:1, RO:1, UZ:1, ZA:1, ZZ:1
bignet.ua1414003UA:11, NL:6
cloudie.hk99000HK:8, US:1
pitline.net99000UA:6, CH:1, FR:1, RU:1
ipswat.com66000US:6
serverion.com66000NL:4, US:2
bunnycommunications.com55000US:4, JP:1
fineproxy.org55000ZA:3, IL:1, RU:1
PacketHub50500PA:4, AU:1
62yun.com44001US:3, KG:1, NG:1
bunea.eu44000RO:3, GB:1
centralnic.com40400GB:4
globaltelehost.com40041CA:4, US:1
lordvps.net44000IR:3, ZA:1
netinnovation.net44000US:4
almaseabi.net33000GB:1, IR:1, RS:1
alphainfolab.com33000US:2, IN:1
chosting.solutions33000GB:3
eksenbilisim.com.tr33000TR:3
ipconnect.services33000SC:3
ithostline.com33000IN:2, CY:1
net-gate.ro33000RO:3
netiface.co.uk33000US:2, GB:1
qwins.co33000GB:1, LV:1, UA:1
rapidoserver.com33000IR:3
ryzehosting.com33000AT:3
sunucun.com.tr33000TR:2, BR:1
xor.sc33000SC:3
Flyservers30210PA:3
Aeza Group22000RU:2
Bearhost-linked22000GB:1, RU:1
berdiev-ruslan-mukhabatovich22000RU:2
changway.hk22000HK:2
cognetcloud.com22000US:2
ddps.jp22000JP:2
dedik.io22000GB:2
ekoiniciative.pp.ua22000UA:2
FIRST SERVER20020GB:2
globtelgroup.com22000US:2

Holder country against event-time IP geolocation

The country field in this catalog records where an autonomous system’s holder is registered with its regional internet registry. That is useful for understanding provider ownership context. For deciding where a sign-in came from it is close to useless, and treating it as a location is the single most common way to misread data of this kind.

The catalog’s own numbers make the point better than an argument does. The United States holds more top-tier networks in this catalog than any other country, by a clear margin. Brazil has a large number of catalog entries and very few enabled ones, because almost all of them are broad access networks that sit in the disabled review tier. A country-based filter built on holder registration would miss most of the first case and generate noise on the second.

For geography-based rules, use event-time IP geolocation and apply the event-country policy column to that, marking each country as expected, no employees, or prohibited according to where your people actually are. Then correlate a match with user history, managed device state, anonymizer classification, travel feasibility and authentication method. A United States exit address can carry a foreign operator’s traffic, and a foreign-registered server can be a compromised host belonging to anyone.

ASN holder registration country, which is not the country a sign-in came from
Holder countryIn catalogEnabledT1T2T3T4
United States US1469461102352
United Kingdom GB80553961916
Ukraine UA8247430435
India IN7347441226
Moldova MD5136350115
Russia RU9627201768
Türkiye TR4725913322
Hong Kong SAR China HK272318054
Germany DE2919102710
Seychelles SC201716013
Netherlands NL2412100311
Iran IR121110011
Brazil BR97923488
Vietnam VN1694327
Romania RO1297113
Panama PA990720
Bangladesh BD33770026
Bulgaria BG1174034
Indonesia ID20660014
South Africa ZA866002
Kazakhstan KZ953204
Japan JP855003
Lithuania LT551040
Poland PL28403124
France FR1141217
Pakistan PK1144007
Canada CA940135
Israel IL544001
China CN833005
Austria AT533002

Detection patterns, including Entra ID risky sign-in monitoring

The patterns below are the logic, recorded with the event sources each one needs, what has to corroborate it, and the ATT&CK techniques involved. Most are written against identity telemetry because that is where the evidence in this release is deepest, and the shape of each one carries over to any system that logs an address alongside an account. They are stated as logic and not as finished rules, deliberately. Thresholds that work in one tenant are wrong in another, and a rule presented as universal invites being deployed without tuning.

The ones marked critical share a shape worth noticing. Almost none of them fire on a sign-in. They fire on what happens after it: an authentication method being registered, a token appearing from a second network, a scripted client reading files in bulk, a device registration following suspected session theft. Sign-in infrastructure is how you find the session worth looking at, and post-authentication behaviour is how you establish that something actually happened.

Anonymizer plus high-volume exfiltrationCritical

Logic
VPN/proxy/anonymizer source plus at least 5 GB or 1,000 file events in 2 hours.
Event sources
File events, bytes, ASN/anonymizer class, user/session
What has to corroborate it
Use a slower companion rule to catch low-and-slow theft.
Response
Suspend session and investigate data scope.
ATT&CK
T1530; T1567
Sources
N23, N26

Device-code phishing or token replayCritical

Logic
Unexpected OAuth device-code flow, token replay, or the same identity/session across different IP, ASN, user-agent, and interactive/non-interactive token streams.
Event sources
OAuth/device-code events, token/session IDs, IP, UA, app ID
What has to corroborate it
Validate approved CLI and device-code workflows.
Response
Revoke tokens, remove consent/persistence, reset account, and hunt post-authentication actions.
ATT&CK
T1528; T1550.001; T1078.004
Sources
N15, N20, N32, N48, N50

Edge exploitation exact-IOC and artifact correlationCritical

Logic
Exact Kapibala or Citrix source, C2, webshell path/hash, or wildcard domain appears with exploit requests, configuration change, process execution, or credential access.
Event sources
Citrix/FortiGate/web logs; EDR; DNS and network telemetry
What has to corroborate it
Exact IOC alone starts a retro-hunt; containment requires target-side evidence or a confirmed malicious session.
Response
Isolate the appliance or host, preserve volatile evidence, rotate exposed credentials, and search for persistence.
ATT&CK
T1190; T1505.003; T1059
Sources
N39, N40

FortiGate Console Chaos chainCritical

Logic
jsconsole or management access followed by account creation, VPN configuration change, or DCSync behavior.
Event sources
FortiGate config/admin logs, VPN changes, AD replication
What has to corroborate it
Sequence is higher confidence than any source ASN alone.
Response
Contain appliance and identity plane; rotate credentials and inspect domain compromise.
ATT&CK
T1190; T1136; T1003.006
Sources
N09, N54

PRT or rogue-device persistenceCritical

Logic
New device registration or PRT-capable enrollment after suspected AiTM or token theft.
Event sources
Device registration, PRT indicators, sign-in and audit logs
What has to corroborate it
Session revocation alone may not remove device-backed persistence.
Response
For confirmed compromise, inspect and disable every rogue device, revoke tokens and sessions, reset credentials, remove inbox or consent persistence, and consider temporary account disablement.
ATT&CK
T1098; T1550.001
Sources
N20, N27, N34, N48, N50

SSPR takeover to pipeline and Kubernetes credentialsCritical

Logic
Unexpected self-service password reset or auth-method registration followed by Azure DevOps enumeration, pipeline or service-connection edits, kubeconfig collection, or tunnel/RMM deployment.
Event sources
Entra audit; Azure DevOps audit; repository and Kubernetes logs
What has to corroborate it
Correlate recovery event, identity novelty, pipeline access, and credential retrieval. Legitimate recovery and engineering administration require allowlists.
Response
Revoke identity, pipeline, cloud, and cluster credentials; remove persistence and inspect downstream deployments.
ATT&CK
T1098; T1552; T1078
Sources
N53

Separated auth, recon, and exfil sourcesCritical

Logic
Correlate one identity across different source IPs/ASNs for authentication, Graph reconnaissance, and data exfiltration.
Event sources
Identity/session IDs across sign-in, Graph, and file audit
What has to corroborate it
Do not require one source IP across the attack chain.
Response
Treat as coordinated session theft unless validated.
ATT&CK
T1078; T1090; T1530
Sources
N17, N23, N34, N48, N50

SonicWall VPN rapid-impact chainCritical

Logic
Hosting/VPN-origin login followed within hours by lateral movement, credential access, remote tools, exfiltration, or encryption.
Event sources
SonicWall auth, EDR, SMB/RDP, AnyDesk/FileZilla, file encryption
What has to corroborate it
Arctic Wolf observed rapid impact; exact timing varies by intrusion.
Response
Contain VPN session and endpoints; inspect credential exposure and ransomware staging.
ATT&CK
T1133; T1078; T1021; T1486
Sources
N06, N07, N12, N54, N56, N47

Suspicious login followed by authenticator enrollmentCritical

Logic
Unexpected device-code or token use followed within about 15 minutes by passkey, phone, software-token, Intune, Device Registration Service, PRT-capable, or burst multi-device enrollment, including non-interactive sign-ins.
Event sources
Sign-in, authentication-method change, device registration audit
What has to corroborate it
Approved onboarding should be allowlisted by workflow and device.
Response
Remove rogue method/device, reset account, then revoke sessions.
ATT&CK
T1098; T1556
Sources
N23, N27, N34, N48, N50

Unauthorized MeshAgent or tunnel plus ransomware behaviorCritical

Logic
Unapproved MeshAgent, Atera, ngrok, Cloudflared, Chisel, or Ligolo activity correlated with exact C2, BYOVD, credential access, recovery inhibition, log deletion, or bulk exfiltration.
Event sources
EDR; network telemetry; RMM inventory; Windows event logs
What has to corroborate it
Dual-use tools require inventory and behavioral corroboration.
Response
Contain the endpoint and remote-management channel, rotate credentials, restore recovery controls, and scope exfiltration.
ATT&CK
T1219; T1562.001; T1490; T1567
Sources
N41, N47, N56

VPS-origin management HTTPS anomalyCritical

Logic
Management HTTPS from hosting/VPS source lasting over 100 seconds and transferring over 1 MB.
Event sources
Firewall flow, URL, bytes, duration, source ASN
What has to corroborate it
Tune for approved administrators and scanners.
Response
Isolate management plane, collect configuration/audit logs, and hunt account/VPN changes.
ATT&CK
T1190
Sources
N09

Valid VPN account to domain-root GPO impactCritical

Logic
Novel or unexpected VPN valid-account access followed by domain-root GPO creation or gPLink changes, non-replication SYSVOL writes, and firewall or security-policy weakening.
Event sources
FortiGate VPN; Windows 5137/5136/4663/4657; Sysmon 11; SYSVOL integrity
What has to corroborate it
Do not require encryptor execution. Baseline approved GPO deployment, replication, and emergency administration.
Response
Contain the VPN session and account, disable malicious GPOs, restore SYSVOL and security policy, and scope extortion activity.
ATT&CK
T1133; T1078; T1484.001; T1562.004
Sources
N54

Workload identity ARM credential and destruction sequenceCritical

Logic
Novel service-principal source or enumeration burst followed by Storage ListKeys, resource deletion, or recovery/backup-lock deletion attempts.
Event sources
Entra service-principal sign-ins; Azure Activity and ARM logs
What has to corroborate it
Require workload-identity novelty, privilege context, and destructive or credential-access operations; shared cloud sources and scripting agents are not sufficient alone.
Response
Disable or rotate the service-principal credential, contain affected resources, restore protections, and scope accessed keys.
ATT&CK
T1078.004; T1526; T1485
Sources
N52

Conditional multi-ASN fast-flux phishingHigh

Logic
Domain delegates through the reported DNS pattern and rotates across at least four ASNs and four IPs, with at least three ASNs from the source seed set, plus phishing or credential-capture evidence.
Event sources
Passive DNS; DNS logs; web telemetry; identity sign-ins
What has to corroborate it
Require the full diversity/delegation pattern or brand/identity behavior. DNSPod and every seed ASN are not malicious by themselves.
Response
Block the malicious domain and session, preserve DNS history, and pivot across the rotating infrastructure.
ATT&CK
T1566; T1583.001; T1090
Sources
N38

Cross-ASN same-user session sequenceHigh

Logic
Same user or token appears from different ASNs within minutes, especially cloud VPS followed by residential or commercial VPN.
Event sources
Sign-in, token/session ID, ASN, IP, user agent
What has to corroborate it
Legitimate mobile/VPN changes can occur; session continuity raises confidence.
Response
Inspect token/session IDs, revoke confirmed replay, and hunt related activity.
ATT&CK
T1550.001; T1090
Sources
N17, N34

Distributed password sprayHigh

Logic
Aggregate failures by tenant/account set/password pattern/time window rather than per source IP.
Event sources
Authentication failures, account set, timestamps, source ASN/family
What has to corroborate it
Residential and commercial proxy rotation defeats per-IP thresholds.
Response
Rate-limit, block proven exact IPs, and investigate any success.
ATT&CK
T1110.003
Sources
N35

Dormant service-account spray and rapid source switchHigh

Logic
Stale TeamFiltration user agent or distributed failures against dormant service accounts followed by success and a rapid switch from AWS EC2 spray infrastructure to a different VPN/hosting ASN.
Event sources
Entra sign-ins; service-account inventory; user-agent and ASN history
What has to corroborate it
Require account dormancy or unusual use, failed-to-success sequence, user-agent match, or post-access behavior. Do not alert on AWS ranges alone.
Response
Disable or rotate the forgotten credential, revoke sessions, review service dependencies, and hunt tenant-wide spray targets.
ATT&CK
T1110.003; T1078; T1090
Sources
N57

Exact IOC match with time scopeHigh

Logic
Exact IP, CIDR, domain, hash, or app ID matches a published indicator within its review TTL.
Event sources
IOC type/value, source, observed dates, current mapping
What has to corroborate it
Stale IP mappings and shared infrastructure are common.
Response
Validate current routing/ownership and campaign context before blocking or attribution.
ATT&CK
Indicator lifecycle
Sources
S02, N33, N39, N40, N41, N45, N48, N49, N52, N54, N55, N57

Graph reconnaissance burstHigh

Logic
After unusual sign-in, at least 10 requests spanning 3 object categories or 6 Graph paths within 30 minutes.
Event sources
Graph audit, application ID, user, paths, timestamps
What has to corroborate it
Tune for administrators and automation accounts.
Response
Investigate identity, app, and data access; revoke confirmed malicious sessions.
ATT&CK
T1087; T1526
Sources
N17, N23, N34, N48, N50

Historical First VPN Service activityHigh

Logic
Historical match to FBI-listed 1VPNS IPs or domains during the relevant period, especially with failed-to-success access, unfamiliar device/MFA/session, scanning, malware deployment, or exfiltration.
Event sources
VPN, identity, edge, DNS, and proxy logs
What has to corroborate it
The May and older exit IPs may be reassigned. Require time alignment and current ownership/service validation for present-day action.
Response
Use for retro-hunting and incident scoping; block current infrastructure only after revalidation.
ATT&CK
T1090; T1133; T1078; T1046; T1110
Sources
N44, N45

Hosting or VPN sign-in plus noveltyHigh

Logic
Hosting/VPN/proxy ASN plus new ASN for user, new device, unmanaged device, or unusual event country.
Event sources
Sign-in, device compliance, user baseline, event-time geolocation
What has to corroborate it
Travel and approved VPN use can explain novelty.
Response
Step up authentication or investigate; contain only with corroboration.
ATT&CK
T1078.004; T1090
Sources
N17, N34

Impossible travel with infrastructure changeHigh

Logic
Same identity succeeds from distant geographies or incompatible ASNs within an infeasible interval.
Event sources
Sign-in times, event IP countries, ASN, device/session ID
What has to corroborate it
Cloud and VPN geolocation can be noisy; weigh device and session continuity.
Response
Revoke suspicious sessions and validate both events.
ATT&CK
T1078.004
Sources
N17, N34

Known malicious or anomalous application IDHigh

Logic
Observed client/resource IDs 9199bf20-a13f-4107-85dc-02114787ef48, c999ed3e-27ae-4cb3-b3a2-46b056af63d3, or campaign-linked application IDs.
Event sources
Sign-in, service principal, consent, Graph audit
What has to corroborate it
Application IDs can be reused in legitimate testing; validate tenant inventory.
Response
Validate consent and expected use; revoke and investigate if unauthorized.
ATT&CK
T1528
Sources
N23

Low-and-slow SaaS exfiltrationHigh

Logic
Unusual identity or anonymizer steadily accesses multiple sensitive repositories below burst thresholds.
Event sources
FileAccessed, repository/category count, time series, ASN
What has to corroborate it
Tenant baselines and job role are essential.
Response
Compare with role baseline and investigate unexplained cross-repository access.
ATT&CK
T1530; T1119
Sources
N17, N23, N26

No-employee or prohibited event countryHigh

Logic
Successful employee sign-in where event-time IP country is marked No Employees or Prohibited.
Event sources
Event IP geolocation, user HR/location policy, ASN and anonymizer flags
What has to corroborate it
Use event IP country, not ASN registration country. VPN exits can mask actor location.
Response
Block or step up according to policy; investigate exceptions.
ATT&CK
T1078.004
Sources
N01, N24, N25

Password spray then successHigh

Logic
Multiple failures across accounts followed by success from related proxy, VPN, or hosting infrastructure.
Event sources
Failure and success logs, source ASN/family, targeted accounts
What has to corroborate it
Aggregate across rotating IPs and provider families.
Response
Reset or protect affected account; inspect source cluster and subsequent access.
ATT&CK
T1110.003; T1078
Sources
N06, N07, N35

Scripting user agent with broad file accessHigh

Logic
python-requests/2.28.1 or 2.34.2, python-httpx, PowerShell, curl, or other rare scripting agents access at least 100 files in 2 hours or follow token/device enrollment.
Event sources
FileAccessed, user agent, app ID, file count, ASN
What has to corroborate it
Known backup and migration tools require allowlists.
Response
Validate automation owner; investigate and contain unexplained access.
ATT&CK
T1119; T1530
Sources
N23, N34, N48, N50

Successful interactive sign-in from T1/T2 networkHigh

Logic
Successful employee interactive login where ASN tier is T1 or T2 and the ASN is enabled.
Event sources
Entra/Google sign-in, ASN, IP, auth type, device, user agent
What has to corroborate it
ASN match is high-priority context, not automatic proof.
Response
Triage immediately; verify user intent, device, MFA, session, and post-authentication behavior.
ATT&CK
T1078.004
Sources
S02, N17, N34

Broad cloud or CDN ASN-only matchInformational

Logic
Sign-in or traffic only matches a disabled broad cloud/CDN ASN without other anomalies.
Event sources
ASN, exact IOC, device, user baseline, application
What has to corroborate it
Prevents false positives from AWS, Google, Microsoft, Cloudflare, Akamai, and similar networks.
Response
Record as context; do not alert or block without exact IOC or behavior.
ATT&CK
Context-only control
Sources
N17, N20, N34

Worked examples for Sentinel, Defender XDR, Splunk and Okta

These queries implement some of the patterns above. Each one states what it needs and what it will wrongly catch, because a detection shipped without its false-positive mode is a detection somebody disables in week two, and the reason they disable it is that nobody told them what to allowlist first.

The Splunk example is the generic one worth reading even if you do not run Splunk, because it shows the whole pattern in four lines: enrich an address with its autonomous system number, join the catalog, filter on tier. Every other query here is a variation on that with a vendor’s field names.

They are correct against the documented schemas as far as review establishes, and they have not been executed against a live tenant as part of this release. Check the Entra audit operation names in the enrollment query against your own environment before trusting it: those operations have been renamed before, and a stale string matches nothing while looking perfectly healthy.

Successful interactive sign-in from a T1 or T2 networkMicrosoft Sentinel

The base case. A real employee account authenticated successfully, interactively, from infrastructure the catalog has direct identity, campaign, anonymizer or bulletproof-hosting evidence for. This is a triage queue, not an alert you can act on blind.

KQL
// Needs a Watchlist named CloudASNRiskWatchlist, built from
// utilities/sentinel-watchlist.csv. _GetWatchlist returns every column as a
// string, which is why ASNumber is cast before the join.
let watch =
    _GetWatchlist('CloudASNRiskWatchlist')
    | where Enabled == "Yes" and Tier in ("T1 Critical", "T2 High")
    | project ASNumber = toint(ASNumber), Tier, ProviderFamily, Category, FPRisk;
SigninLogs
| where TimeGenerated > ago(7d)
| where ResultType == 0
| where IsInteractive == true
| join kind=inner watch on $left.AutonomousSystemNumber == $right.ASNumber
| project
    TimeGenerated,
    UserPrincipalName,
    IPAddress,
    AutonomousSystemNumber,
    Tier,
    ProviderFamily,
    Category,
    FPRisk,
    EventCountry = tostring(LocationDetails.countryOrRegion),
    AppDisplayName,
    ClientAppUsed,
    UserAgent,
    Device = tostring(DeviceDetail.displayName),
    Compliant = tostring(DeviceDetail.isCompliant)
| order by TimeGenerated desc
Needs
A Sentinel Watchlist named CloudASNRiskWatchlist, imported from utilities/sentinel-watchlist.csv with ASNumber as the key.
What it will wrongly catch
Anyone using a personal VPN, a vendor working from a hosted jump box, or a mobile carrier that backhauls through a hosting ASN. Expect to allowlist your own SASE and admin jump hosts before this is quiet enough to watch.
Catalog pattern
Successful interactive sign-in from T1/T2 network

Watchlist ASN that is new for this userMicrosoft Sentinel

The ASN match on its own is weak. Pairing it with a fourteen-day per-user baseline is what turns it into a signal, because the employee who always connects through the same hosting ASN stops generating noise while a first appearance surfaces.

KQL
let lookback = 14d;
let watch =
    _GetWatchlist('CloudASNRiskWatchlist')
    | where Enabled == "Yes"
    | project ASNumber = toint(ASNumber), Tier, ProviderFamily;
// The baseline deliberately stops at ago(1d) so today's activity cannot
// baseline itself and disappear.
let baseline =
    SigninLogs
    | where TimeGenerated between (ago(lookback) .. ago(1d))
    | where ResultType == 0
    | summarize KnownAsns = make_set(AutonomousSystemNumber, 1000)
        by UserPrincipalName;
SigninLogs
| where TimeGenerated > ago(1d)
| where ResultType == 0
| where IsInteractive == true
| join kind=inner watch on $left.AutonomousSystemNumber == $right.ASNumber
| join kind=leftouter baseline on UserPrincipalName
| where isnull(KnownAsns) or not(set_has_element(KnownAsns, AutonomousSystemNumber))
| project
    TimeGenerated,
    UserPrincipalName,
    IPAddress,
    AutonomousSystemNumber,
    Tier,
    ProviderFamily,
    NoBaseline = isnull(KnownAsns),
    Device = tostring(DeviceDetail.displayName),
    Compliant = tostring(DeviceDetail.isCompliant),
    EventCountry = tostring(LocationDetails.countryOrRegion)
| order by TimeGenerated desc
Needs
The same Watchlist, plus at least fourteen days of SigninLogs retention for the baseline to mean anything.
What it will wrongly catch
A genuinely new but legitimate network: a new office, a new VPN vendor, the first week of a new starter. The baseline is also empty for anyone who has not signed in during the lookback, which is why the null case is kept visible rather than dropped.
Catalog pattern
Hosting or VPN sign-in plus novelty

Device-code authentication and token replayMicrosoft Sentinel

Device-code flow has a narrow legitimate footprint in most tenants, so an unexpected success is worth reading on its own. The ASN is attached as context rather than used as a filter, because the interesting cases include the ones from networks the catalog has never seen.

KQL
let watch =
    _GetWatchlist('CloudASNRiskWatchlist')
    | where Enabled == "Yes"
    | project ASNumber = toint(ASNumber), Tier, ProviderFamily;
SigninLogs
| where TimeGenerated > ago(7d)
| where ResultType == 0
| where AuthenticationProtocol =~ "deviceCode"
    or OriginalTransferMethod =~ "deviceCodeFlow"
// leftouter: an unlisted ASN is still worth seeing here.
| join kind=leftouter watch on $left.AutonomousSystemNumber == $right.ASNumber
| project
    TimeGenerated,
    UserPrincipalName,
    IPAddress,
    AutonomousSystemNumber,
    Tier = coalesce(Tier, "not in catalog"),
    ProviderFamily,
    AppDisplayName,
    ResourceDisplayName,
    UserAgent,
    CorrelationId
| order by TimeGenerated desc
Needs
SigninLogs. The Watchlist join is leftouter on purpose, so a device-code success from an unlisted network still appears.
What it will wrongly catch
Legitimate device-code use does exist: shared or kiosk devices, some CLI tooling, and PowerShell modules that fall back to it. Establish which applications in your tenant use it before treating a hit as an incident.
Catalog pattern
Device-code phishing or token replay

Watchlist sign-in followed by an authentication-method changeMicrosoft Sentinel

This is the sequence that turns a stolen session into persistence, and it is the highest-value query here. An attacker who registers their own passkey, phone or device keeps access after the password is reset, so the enrollment matters more than the sign-in that preceded it. Non-interactive sign-ins are included because token replay often is.

KQL
let window = 15m;
let watch =
    _GetWatchlist('CloudASNRiskWatchlist')
    | where Enabled == "Yes" and Tier in ("T1 Critical", "T2 High")
    | project ASNumber = toint(ASNumber), Tier, ProviderFamily;
let risky =
    union SigninLogs, AADNonInteractiveUserSignInLogs
    | where TimeGenerated > ago(7d)
    | where ResultType == 0
    | join kind=inner watch on $left.AutonomousSystemNumber == $right.ASNumber
    | project
        SignInTime = TimeGenerated,
        UserPrincipalName,
        IPAddress,
        AutonomousSystemNumber,
        Tier,
        ProviderFamily;
let enrolment =
    AuditLogs
    | where TimeGenerated > ago(7d)
    // Verify these against your tenant. Entra has renamed them before.
    | where OperationName has_any (
        "User registered security info",
        "User registered all required security info",
        "Admin registered security info",
        "User changed default security info",
        "Add strong authentication method",
        "Add registered device",
        "Register device")
    | extend Actor = tostring(InitiatedBy.user.userPrincipalName)
    | where isnotempty(Actor)
    | project
        EnrolTime = TimeGenerated,
        UserPrincipalName = Actor,
        OperationName,
        AuditResult = tostring(Result);
risky
| join kind=inner enrolment on UserPrincipalName
| where EnrolTime between (SignInTime .. (SignInTime + window))
| project
    SignInTime,
    EnrolTime,
    Gap = EnrolTime - SignInTime,
    UserPrincipalName,
    IPAddress,
    AutonomousSystemNumber,
    Tier,
    ProviderFamily,
    OperationName,
    AuditResult
| order by SignInTime desc
Needs
SigninLogs, AADNonInteractiveUserSignInLogs and AuditLogs. Check the OperationName list against your own tenant: Entra has renamed these operations before and a stale string silently matches nothing.
What it will wrongly catch
A user who travels, connects through a VPN, and then legitimately enrols a new phone. The fifteen-minute window is tight enough that this is uncommon, and the response is a phone call rather than a lockout.
Catalog pattern
Suspicious login followed by authenticator enrollment

One identity succeeding from several networks in the same windowMicrosoft Sentinel

A token used from two unrelated networks inside half an hour is hard to explain innocently, and it does not need the catalog at all. The watchlist is joined afterwards only to say whether any of the networks involved was already known.

KQL
let window = 30m;
union SigninLogs, AADNonInteractiveUserSignInLogs
| where TimeGenerated > ago(1d)
| where ResultType == 0
| where isnotempty(UserPrincipalName) and AutonomousSystemNumber > 0
// bin() is a fixed bucket, not a sliding window: a sequence that straddles a
// boundary is split in two and will not be caught here.
| summarize
    Asns = make_set(AutonomousSystemNumber, 100),
    Ips = make_set(IPAddress, 100),
    Agents = make_set(UserAgent, 50),
    Events = count()
    by UserPrincipalName, Window = bin(TimeGenerated, window)
| where array_length(Asns) > 1
| extend AsnCount = array_length(Asns), IpCount = array_length(Ips)
| order by AsnCount desc, Events desc
Needs
SigninLogs and AADNonInteractiveUserSignInLogs.
What it will wrongly catch
bin() cuts fixed thirty-minute buckets, so a genuine sequence straddling a boundary is split and missed, and a user roaming between a corporate network and a phone will sometimes land in two ASNs legitimately. Treat the ASN count as a sorting key rather than a verdict.
Catalog pattern
Cross-ASN same-user session sequence

The same first query in Defender XDR advanced huntingMicrosoft Defender XDR

Advanced hunting has no watchlist feature, so the list has to travel inside the query as a set literal. That is what utilities/asn-sets.kql in the download is for: paste the AsnT1T2 block in place of the short sample below.

KQL
// Replace this sample with the full AsnT1T2 block from
// utilities/asn-sets.kql in the download bundle. Three entries shown so the
// query is runnable as pasted.
let AsnT1T2 = dynamic([62240, 136787, 206728]);
AADSignInEventsBeta
| where Timestamp > ago(7d)
| where ErrorCode == 0
| where set_has_element(AsnT1T2, AutonomousSystemNumber)
| project
    Timestamp,
    AccountUpn,
    IPAddress,
    AutonomousSystemNumber,
    Country,
    Application,
    ClientAppUsed,
    UserAgent,
    DeviceName,
    IsManaged,
    IsCompliant
| order by Timestamp desc
Needs
AADSignInEventsBeta, which needs Microsoft Defender for Identity or Entra ID P2 data in the workspace.
What it will wrongly catch
The same as the Sentinel version, with one addition: a set literal pasted into a rule goes stale the moment the catalog is updated, so either refresh it on the same cadence or keep the authoritative copy in Sentinel.
Catalog pattern
Successful interactive sign-in from T1/T2 network

Scripting user agent reading files in bulkMicrosoft Defender XDR

What happens after the sign-in is usually more decisive than the sign-in. A scripted client reading a hundred files in two hours is the collection stage, and it is visible without any reference to the ASN at all. Run it alongside the sign-in queries rather than instead of them.

KQL
let agents = dynamic(["python-requests", "python-httpx", "aiohttp", "curl",
                      "Go-http-client", "PowerShell", "WinHttp"]);
CloudAppEvents
| where Timestamp > ago(7d)
| where ActionType == "FileAccessed"
| extend Ua = tostring(RawEventData.UserAgent)
| where isnotempty(Ua) and Ua has_any (agents)
| summarize
    Files = dcount(tostring(RawEventData.ObjectId)),
    Events = count(),
    Ips = make_set(IPAddress, 20)
    by AccountDisplayName, Ua, Window = bin(Timestamp, 2h)
| where Files >= 100
| order by Files desc
Needs
CloudAppEvents, which carries SharePoint and OneDrive file activity in Defender XDR. The Sentinel equivalent is OfficeActivity with different column names.
What it will wrongly catch
Backup agents, migration tooling, eDiscovery exports and any sanctioned integration that uses a generic HTTP client. Inventory those first, because they will each trip this and they will each look identical to collection.
Catalog pattern
Scripting user agent with broad file access

Any source-IP log against the catalogSplunk

The catalog is a list of networks, so it applies to anything that records a source address. This is the generic shape: enrich whatever index already holds your authentication, VPN, firewall or SaaS audit events with the tier, then filter. Nothing about it is identity-specific, and the same join works against a proxy log or a mail gateway.

SPL
``` Generic shape. Replace the index and the field names with your own. ```

``` src_asn has to come from the event or from a lookup. Splunk's iplocation
    command does NOT provide an ASN, only geo fields, so if your source does
    not carry the number already, uncomment the GeoLite2-ASN line below. ```

index=auth action=success
``` | lookup geolite2_asn ip AS src_ip OUTPUT autonomous_system_number AS src_asn ```
| lookup asn_watchlist ASNumber AS src_asn
    OUTPUT Tier, ProviderFamily, Category, FPRisk, Enabled
| where Enabled="Yes" AND Tier IN ("T1 Critical", "T2 High")
| stats count,
        values(Tier) AS tier,
        values(ProviderFamily) AS provider,
        values(FPRisk) AS fp_risk,
        dc(src_ip) AS distinct_ips
        BY user, src_asn
| sort - count
Needs
Two lookups. The catalog itself, defined from utilities/sentinel-watchlist.csv and keyed on ASNumber. And a source of the ASN for each address, because Splunk resolves none on its own: the built-in iplocation command adds City, Country, Region and coordinates and nothing else. Many log sources already carry the number (Okta, Cloudflare and AWS VPC flow logs among them); where yours does not, a GeoLite2-ASN lookup supplies it.
What it will wrongly catch
Exactly the same population as everywhere else: corporate VPN egress, vendor jump boxes, mobile carrier NAT and anyone on a personal VPN. Build the allowlist before you build the alert, because an unallowlisted version of this will fire on your own infrastructure first.
Catalog pattern
Successful interactive sign-in from T1/T2 network

Okta sign-ins, which already carry the ASNOkta

Okta puts the autonomous system number directly on every System Log event as securityContext.asNumber, so no enrichment step is needed to use this catalog there. That makes it the cheapest place to test whether the list says anything useful about your traffic before you build anything.

Okta expression
eventType eq "user.session.start" and outcome.result eq "SUCCESS" and (securityContext.asNumber eq 62240 or securityContext.asNumber eq 136787 or securityContext.asNumber eq 206728)
Needs
System Log access. The expression is for a targeted check in the Admin Console or the events API, and it is deliberately bare: Okta's filter syntax has no comment form, so anything explanatory pasted with it is rejected. The three numbers are Clouvider, PacketHub and Media Land. For the whole enabled set, ship the System Log to a SIEM and use the lookup approach instead, because several hundred ASNs in a filter expression is not something you will keep up to date.
What it will wrongly catch
The same anonymizer and hosting population as any other surface. Okta also records the ASN of the client as the edge saw it, so a corporate egress through a cloud provider appears exactly as a hosted address would.
Catalog pattern
Successful interactive sign-in from T1/T2 network

Loading the list into the platform you already run

In Microsoft Sentinel, import the Sentinel Watchlist CSV from the download bundle and key it on the ASNumber column. That file exists because the obvious mistake is to ship only the AS-prefixed form, which then fails to join against the integer autonomous system number in the sign-in tables and matches nothing. Keeping the list in a watchlist, instead of inline in each analytics rule, means a weekly refresh costs one import and not an edit to every rule.

Defender XDR advanced hunting has no watchlist feature, so the set has to travel inside the query. The bundle includes paste-ready set literals for that, one for the alerting tiers and one for everything enabled. The cost of this approach is that a literal pasted into a custom detection goes stale the moment the catalog updates, so either refresh it on the same cadence or keep the authoritative copy in Sentinel and treat the XDR rules as hunting.

I have used this catalog in Microsoft Defender for Cloud, where what it mostly buys you is enrichment. A flagged connection reads differently once you know the network on the other end has documented identity-attack history, and that changes how quickly somebody picks it up. The alerting value there is secondary to having the context attached when a human finally looks.

Outside the Microsoft estate the mechanics change and the judgement does not. Splunk and most SIEMs want the Sentinel Watchlist CSV as an ordinary lookup table keyed on the ASN number, which is why that file ships with a bare numeric column alongside the AS-prefixed one. Okta needs no enrichment at all, since every System Log event already carries the autonomous system number. Firewalls and edge devices generally want the plain text file, though feeding an enforcement device directly from any of this is the one use I would argue against without a dependency review first.

For Entra ID Conditional Access, the honest guidance is to be conservative. Named locations and risk policies built from this list can work, and the tier structure matters more here than anywhere else: the alerting tiers are defensible inputs to a step-up requirement, and the review tier should never drive a policy because it contains broad cloud and consumer access networks. Validate against your own sign-in history before enforcing anything, and keep allowlists for your workloads, vendors, SASE egress, VPN concentrators and admin jump hosts. A Conditional Access policy that locks out an administrator is a worse outcome than the sign-in it was meant to stop.

Community feeds, and why four lists are not four witnesses

Public indicator feeds are used here for exact-address enrichment and short-lived hunting. They do not drive tiering, and the overlap figures explain why. Tens of thousands of addresses appear on more than one of these lists, and the reason is shared source lineage between the lists themselves. Those are not separate parties confirming each other. Cross-list presence is frequently one observation reported several times.

One feed in this set is recorded as rejected rather than used, because its contents were byte-identical for over a month across more than a hundred consecutive failed updates. A stale list that looks live is worse than no list, and publishing that rejection is more useful than quietly omitting the feed.

IPsum

Coverage
IPv4 with source-count score; score >=3: 17604; score >=5: 4242
Snapshot
2026-09-29
Unique indicators
121,838
Current state
Tue, 29 Sep 2026 03:00:38 +0200
Use it for
Exact-IP enrichment and short-TTL hunting; preserve score and snapshot date.
Where it falls short
Inputs are not independent. 47,278 IPs overlap Data-Shield, including 14,466 IPsum score >=3 addresses.

mzyui HTTP proxy list

Coverage
IPv4:port endpoints; 53395 unique IPv4
Snapshot
2026-08-29
Unique indicators
63,797
Current state
Rejected: stale and unvalidated
Use it for
Discovery only; reject for enforcement until updater health and independent endpoint validation recover.
Where it falls short
Byte-identical for 31.8 days with 143 consecutive updater failures.

Data-Shield IPv4 Blocklist

Coverage
IPv4; overlap with IPsum: 47278
Snapshot
2026-09-29
Unique indicators
92,896
Current state
2026-09-29 20:05:41
Use it for
Exact-IP corroboration with source/date retention.
Where it falls short
Large overlap with IPsum prevents treating cross-list presence as independent evidence.

Cisco Talos April 2024 brute-force IOCs

Coverage
IPv4 plus credential observations
Snapshot
2024-04-16
Unique indicators
3,926
Current state
Historical snapshot
Use it for
Historical hunting and campaign-time ASN context for VPN, web-authentication, and SSH brute force.
Where it falls short
Keep campaign-time attribution separate from current routing. Source IPs can be reassigned; no ASN-wide provider implication.

Ransomware.live IoCs

Coverage
Heterogeneous group IOCs
Snapshot
2026-09-29
Unique indicators
2,564
Current state
Dynamic page checked 2026-09-29
Use it for
Discovery and corroboration; retain group, type, date, and original provenance where available.
Where it falls short
Network rows mix bare IP, IP:port, and CIDR and lack reliable per-row observation dates/original references. Revalidate exact indicators; never promote an ASN from presence alone.

Current community-feed union

Coverage
IPv4; all-three overlap: 60
Snapshot
2026-09-29
Unique indicators
218,847
Current state
Mixed; see individual rows
Use it for
Prioritize exact indicators aligned with fresh tenant telemetry and observed TTPs.
Where it falls short
Cross-list overlap is not independent corroboration. Feed volume alone does not support ASN-level malicious attribution.
Exact-IP use
Enrich listed IPs to the event-time ASN and retain the feed snapshot date. Do not turn a transient IP hit into permanent ASN-wide reputation.
Overlap
IPsum and Data-Shield share substantial source lineage. A hit in both is not automatically independent corroboration.
Freshness
Proxy lists require age and validation checks. A stale updater or untested endpoint should not drive blocking.
Cloud volume
Large cloud ASNs can dominate raw counts while serving legitimate customers. Treat count as exposure context, not maliciousness.

What changed in this refresh

The page states both the evidence snapshot date and the build date, and they are different on purpose. A rebuild is not new evidence, and presenting the two as one number is how a stale catalog looks current.

Refresh of .

Refresh record 2026-10-09
Catalog 1,148 to 1,151. Routing re-verified for all 1,148 prior catalog ASNs against RIPEstat; every difference was confirmed on a second pass. AS209425 is originating again. AS262909 and AS402170 stopped originating and are held for lifecycle review, not removed. AS212238, AS13335, AS16509 and AS20940 timed out or did not answer on one or both passes and are recorded as unresolved, not changed (AS9009 and AS20940 answered on retry with no change). RIR delegation files for all five registries show AS401109, AS401110, AS401116, AS401120 and AS262909 as reserved with no RDAP object; they stay in the catalog at T4 for lifecycle review because the status is new this week. No new published reporting changed any tier since 2026-10-07. Abuse percentages, IPsum and community feed counts were not re-pulled, and RIPEstat, Spamhaus and RDAP answered while some news sites refused automated requests.
ASN-DROP delta 2026-10-09
Spamhaus changed from 427 to 431 ASNs. Added: AS14956 (ROUTERHOSTING, already catalogued, moved T2 to T1), AS198636 (CAPSULA-AS), AS199457 (SolidCore), AS199804 (TFES-AS), the last three newly catalogued as T1 Critical. Removed: none. Delisting is not exoneration.
Evidence expansion 2026-10-09, campaign ladder applied
Campaign watch is now a ladder: one campaign holds T3 for 180 days, two or more separate campaigns within 12 months hold T2 for 180 days and then T3 for 180 more, then T4 for history. Applied to every row whose only basis is campaign reporting. 21 rows step down to T4: 17 whose newest Akira, Fog or Proofpoint campaign is more than 180 days old and 4 whose cited reporting is exploitation or C2 rather than sign-in abuse. 8 rows are on the ladder at T3: tzulo, Hydra, FranTech and Hivelocity from T2, the three HZ Hosting ASNs on the family's three campaigns, and Global Connectivity Solutions from T4. Datacamp stays T2 as commercial VPN egress. No row was removed.

Earlier refreshes are in the methodology and changelog download.

Methodology and limitations

The catalog is assembled from current machine-readable feeds, published vendor and government reporting, registry and routing data, and incident evidence, with every tiering decision resolving to a numbered source record. The full methodology ships in the bundle. The limitations deserve stating here rather than only in a download, because they are the conditions under which this data will be wrong.

Bring-your-own-IP addressing, suballocation, address reassignment, residential and mobile proxy egress, anycast addressing, compromised legitimate hosts and provider size can each break the link between a network and the activity attributed to it. Routing data shows which network announces a prefix, which is not always the party controlling the addresses inside it. Feed membership changes for reasons that have nothing to do with a network’s behaviour. None of this makes the data unusable, and all of it means the data is an input to a judgement and never a substitute for one.

On provider complicity, the position is the same throughout and it is not a disclaimer added at the end. Several networks here belong to legitimate hosting, transit and commercial VPN businesses. They are listed because reporting or incident evidence placed activity on their infrastructure. Where the research has a view on a provider’s role it is recorded in the provider role field, and for most rows that view is that infrastructure use was observed and no complicity claim is made. A tier is a monitoring priority and reading it as an allegation misreads the file.

The catalog is free to use with attribution under CC BY 4.0. Corrections are welcome and useful, particularly from providers who can show that a row is out of date.

  1. S01 Spamhaus ASN-DROPCurrent machine-readable feed, 2026-10-09Membership and allocations can change. Neither list membership nor removal establishes every address/customer intent or login-source attribution. Update regularly before enforcement.
  2. S02 CISA, NSA, FBI and international partners Bulletproof Defense: Mitigating Risks From Bulletproof Hosting ProvidersJoint government guidance, 2025-11-19Warns that whole-ASN blocking can affect legitimate users and that BPH providers cycle infrastructure.
  3. S03 ipapi.is Most Abusive ASNsCurrent abuse-concentration ranking, 2026-09-29Vendor methodology and labels are prioritization signals, not malicious-login probability. Absence from the top 1,000 is not zero abuse; tied 100% ranks make rank-only movement weak evidence.
  4. S04 Proofpoint Cloud Credential Compromise from Russian InfrastructureCloud credential attack report with 35 IP IOCs, 2022-03-03Proofpoint published IPs, provider labels and domains, not ASNs or CIDRs. ASN mapping is historical analyst enrichment and does not imply provider complicity.
  5. S05 RIPE NCC RIPEstat AS OverviewRegistry/routing enrichment, 2026-09-15Registry identity and routing status can change; country is not actor nationality.
  6. S06 RIPE NCC RIPEstat Routing HistoryHistorical BGP enrichment method, 2026-09-15BGP origin establishes routing at a point in time, not ownership, intent or provider complicity.
  7. S07 Microsoft ACTINIUM targets Ukrainian organizationsThreat research, 2022-02-04Actor infrastructure and C2 evidence, not Microsoft 365 login-source evidence. Microsoft describes REG.RU as legitimate.
  8. S08 Palo Alto Networks Unit 42 Gamaredon (Primitive Bear) Russian APT Group Actively Targeting UkraineThreat research with IP/ASN mappings, 2022-02-03Mostly malware C2/downloader telemetry, not authentication-source evidence. Large shared providers create ASN-wide false positives.
  9. S09 U.S. Department of the Treasury Treasury Sanctions Global Bulletproof Hosting Service Enabling Cybercriminals and Technology TheftOfficial designation, 2025-07-01The press release names the entity but not ASNs; ASN linkage comes from technical research and current registry data.
  10. S10 U.S. Department of the Treasury United States, Australia, and the United Kingdom Jointly Sanction Key Infrastructure that Enables Ransomware AttacksOfficial designation, 2025-02-11The release names the entity, not a complete current ASN inventory.
  11. S11 U.S. Department of Justice Three Russian Nationals and Two Companies Indicted for International Cybercrimes Resulting in More Than $62M in Victim LossesOfficial indictment announcement, 2026-07-14Criminal charges are allegations until proven. The release is not a complete ASN or prefix feed.
  12. S12 Recorded Future Insikt Group One Step Ahead: Stark Industries Solutions Preempts EU SanctionsInfrastructure research, 2025-08-27Infrastructure was already shifting; revalidate current routing and ownership before enforcement.
  13. S13 GreyNoise The Stark Industries Shell GameInfrastructure and scanning research, 2025-11-17Observed scanning does not make every customer or sign-in malicious.
  14. S14 Silent Push IOFA Detects Aeza Group Infrastructure Shift Following OFAC SanctionsInfrastructure research, 2025-07-24Use the source date and routing snapshot; provider infrastructure can move.
  15. S15 Intel 471 Zservers: Bulletproof Hosting for CrimeInfrastructure research, 2025-03-11Historical technical snapshot. AS197414 is currently unannounced in this workbook enrichment.
  16. S16 Team Cymru Exploring Seychelles: Team Cymru’s Tech AdventureInfrastructure research, 2022-09-10Historical family mapping; current routing and current feed membership are shown separately.
  17. S18 Microsoft Midnight Blizzard: Guidance for responders on nation-state attackIdentity-attack guidance, 2024-01-25Publishes no ASN list.
  18. S19 Google Cloud Mandiant APT29 Continues Targeting Microsoft 365Identity-attack research, 2022-08-18Publishes no ASN list; behavior supports combining network and identity signals.
  19. S20 Team Cymru Operationalizing OFAC Sanctions for Financial Defense: MediaLand AS206728Current infrastructure research, 2026-02-04Treat current routes and exact resources as time-sensitive.
  20. X001 Rapid7 Ongoing Social Engineering Campaign Refreshes PayloadsSupporting research or registry record, 2024-08-12Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  21. X002 Silent Push USPS Phishing on a Bulletproof Hosting NetworkSupporting research or registry record, 2024-08-12Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  22. X003 Recorded Future Malicious Infrastructure Finds Stability with aurologic GmbHSupporting research or registry record, 2025-11-06Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  23. X004 Excedo How cybercriminals abuse ASN for bulletproof hostingSupporting research or registry record, 2026-09-15Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  24. X005 bgp.tools bgp.tools AS215208 current registrationSupporting research or registry record, 2025-05-01Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  25. X006 bgp.tools bgp.tools AS215240 current registrationSupporting research or registry record, 2025-05-01Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  26. X007 Team Cymru How Virtual Offices Enable a Facade of LegitimacySupporting research or registry record, 2025-05-01Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  27. X008 Huntress No (Bad) CAP: Inside an Ongoing LSHIY Password Spray AttackPrimary identity threat research with exact infrastructure, 2026-07-15Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  28. X009 bgp.tools bgp.tools AS207569Supporting research or registry recordReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  29. X010 urlhaus.abuse.ch URLhaus malware URL databaseSupporting research or registry recordReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  30. X011 global.ptsecurity.com Lazarus Group Recruitment: Threat Hunters vs Head HuntersSupporting research or registry record, 2024-08-19Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  31. X012 urlhaus.abuse.ch URLhaus ASN report for AS26496Supporting research or registry record, 2024-08-19Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  32. X013 bgp.he.net Hurricane Electric BGP Toolkit AS214943Supporting research or registry record, 2025-10-27Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  33. X014 rdap.arin.net ARIN RDAP lookup (no current object)Supporting research or registry recordReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  34. X015 bgp.tools bgp.tools AS11938Supporting research or registry recordReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  35. X016 halcyon.ai Update: Cloudzy Command and Control Provider ReportSupporting research or registry record, 2026-07-24Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  36. X017 cloudzy.com Cloudzy Official Statement, August 2023Supporting research or registry record, 2026-07-24Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  37. X018 jumpsec.com Inside a DPRK BlueNoroff ClickFix KitSupporting research or registry record, 2026-07-24Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  38. X019 bgp.tools bgp.tools AS22295Supporting research or registry recordReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  39. X020 threatfox.abuse.ch ThreatFox ASN report for AS22295Supporting research or registry recordReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  40. X021 rdap.arin.net ARIN RDAP lookup (no current object)Supporting research or registry recordReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  41. X022 bgp.tools bgp.tools AS26701Supporting research or registry recordReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  42. X023 rdap.arin.net ARIN RDAP lookup (no current object)Supporting research or registry recordReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  43. X024 rdap.arin.net ARIN RDAP lookup (no current object)Supporting research or registry recordReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  44. X025 rdap.arin.net ARIN RDAP lookup (no current object)Supporting research or registry recordReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  45. X026 bgp.tools bgp.tools AS42624 successor contextSupporting research or registry record, 2025-11-06Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  46. X027 bgp.tools bgp.tools AS35346Supporting research or registry recordReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  47. X028 bgp.tools bgp.tools AS35718Supporting research or registry recordReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  48. X029 bgplookingglass.com List of Autonomous System Numbers - 2 (historical identity reference)Supporting research or registry record, 2026-09-15Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  49. X030 ipinfo.io IPinfo AS41947 historical ASN summarySupporting research or registry record, 2026-09-15Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  50. X031 Recorded Future Malicious Infrastructure Finds Stability with aurologic GmbHSupporting research or registry record, 2026-04-23Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  51. X032 bgp.he.net Hurricane Electric BGP Toolkit: AS42624Supporting research or registry record, 2026-04-23Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  52. X033 ipinfo.io IPinfo AS43094 ASN summarySupporting research or registry record, 2026-09-15Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  53. X034 x.com Spamhaus researcher report on suspicious AS44317/AS21738 announcementsSupporting research or registry record, 2024-05-16Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  54. X035 peeringdb.com PeeringDB historical entry: AS44317 Mercury Telecom LLCSupporting research or registry record, 2024-05-16Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  55. X036 krebsonsecurity.com Stark Industries Solutions: An Iron Hammer in the CloudSupporting research or registry record, 2026-05-29Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  56. X037 augursecurity.com European Union Sanctions Force Stark Industries Solutions Ltd. to Rebrand AgainSupporting research or registry record, 2026-05-29Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  57. X038 bgp.he.net Hurricane Electric BGP Toolkit: AS44477Supporting research or registry record, 2026-05-29Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  58. X039 bgp.tools BGP.Tools: AS44589Supporting research or registry record, 2026-09-15Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  59. X040 ipinfo.io IPinfo AS44774 historical ASN summarySupporting research or registry record, 2025-05-20Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  60. X041 Silent Push Infrastructure Laundering: Silent Push Exposes Cloudy Behavior Around FUNNULL CDN Renting IPs from Big TechSupporting research or registry record, 2026-03-25Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  61. X042 greynoise.io Ghost Fleet: Half of All New Scanning IPs Last Week Geolocated to Hong KongSupporting research or registry record, 2026-03-25Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  62. X043 peeringdb.com PeeringDB: AS45753Supporting research or registry record, 2026-03-25Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  63. X044 ipinfo.io IPinfo AS47500 ASN summarySupporting research or registry record, 2026-09-15Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  64. X045 Team Cymru Team Cymru: Jingle Shells - How Virtual Offices Enable a Facade of LegitimacySupporting research or registry record, 2026-09-15Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  65. X046 threatfox.abuse.ch ThreatFox AS49042 tagSupporting research or registry record, 2026-09-15Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  66. X047 urlhaus.abuse.ch URLhaus ASN report for AS49042Supporting research or registry record, 2026-09-15Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  67. X048 bgp.tools BGP.Tools historical profile for AS49042Supporting research or registry record, 2026-09-15Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  68. X049 threatfox.abuse.ch ThreatFox AS49217 tagSupporting research or registry record, 2026-09-15Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  69. X050 bgp.tools BGP.Tools historical profile for AS49217Supporting research or registry record, 2026-09-15Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  70. X051 alfa-inet.net Alfa-inet ISP websiteSupporting research or registry record, 2026-09-15Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  71. X052 rasvtv.md RASV-TV official websiteSupporting research or registry record, 2026-09-15Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  72. X053 pfcloud.io Pfcloud official service catalogSupporting research or registry record, 2026-09-15Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  73. X054 urlhaus.abuse.ch URLhaus ASN report for AS51396Supporting research or registry record, 2026-09-15Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  74. X055 rootlayer.net RootLayer network and hosting pageSupporting research or registry record, 2026-09-15Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  75. X056 ip2location.com IP2Location current AS51490 statusSupporting research or registry record, 2026-09-15Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  76. X057 Recorded Future Recorded Future 2022 Adversary Infrastructure ReportSupporting research or registry record, 2026-09-15Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  77. X058 bgp.tools BGP.Tools profile for AS57678Supporting research or registry record, 2026-09-15Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  78. X059 innetra.com INNETRA official service catalogSupporting research or registry record, 2026-09-15Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  79. X060 peeringdb.com PeeringDB AS58349 profileSupporting research or registry record, 2026-09-15Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  80. X061 xserver.cloud XServer official VPS and dedicated-server siteSupporting research or registry record, 2026-09-15Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  81. X062 bgp.tools BGP.Tools AS48031 profileSupporting research or registry record, 2026-09-15Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  82. X063 docs.hetzner.com Hetzner official documentationSupporting research or registry record, 2026-09-15Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  83. X064 peeringdb.com PeeringDB AS213230 profileSupporting research or registry record, 2026-09-15Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  84. X065 learn.microsoft.com Microsoft Learn: Internet peering and AS8075Supporting research or registry record, 2026-09-15Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  85. X066 azure.microsoft.com Microsoft Azure official siteSupporting research or registry record, 2026-09-15Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  86. X067 serveroffer.lt Serveroffer official hosting pageSupporting research or registry record, 2026-09-15Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  87. X068 m247.com M247 official service catalogSupporting research or registry record, 2026-09-15Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  88. X069 urlhaus.abuse.ch URLhaus ASN report for AS9009Supporting research or registry record, 2026-09-15Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  89. X070 Recorded Future GrayBravo's CastleLoader Activity Clusters Target Multiple IndustriesSupporting research or registry record, 2025-12-09Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  90. X071 infosec.exchange Spamhaus: 49.3 Networking bulletproof-host investigationSupporting research or registry record, 2025-09-26Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  91. X072 infosec.exchange Spamhaus: Bearhost's bulletproof-hosting comebackSupporting research or registry record, 2026-04-29Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  92. X073 infosec.exchange Spamhaus: Netiface bulletproof-hosting infrastructureSupporting research or registry record, 2026-08-24Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  93. X074 infosec.exchange Spamhaus: AS219067 phishing and prefix-hopping infrastructureSupporting research or registry record, 2026-08-24Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  94. X075 infosec.exchange Spamhaus: Virtualine bulletproof hostingSupporting research or registry record, 2025-09-18Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  95. X076 infosec.exchange Spamhaus: infrastructure facilitating bulletproof-host proliferationSupporting research or registry record, 2026-08-24Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
  96. N01 RIPE NCC RIPEstat AS Overview, RIR registration, and routing statusCurrent routing and registration metadata, 2026-10-07RIR country is holder-registration metadata, not user or IP geolocation. A non-originating result can be transit-only, dormant, or below the RIPE visibility threshold; opaque RIR IDs are not stable ownership identifiers.
  97. N02 stamparm IPsum threat-intelligence feedCommunity IP reputation aggregation, 2026-09-29Underlying lists are not statistically independent. Score and ASN concentration are context, not automatic provider-tier evidence.
  98. N03 mzyui HTTP proxy listCommunity open-proxy list, 2026-08-29Artifact remained byte-identical and about 31.8 days stale after 143 consecutive updater failures when checked 2026-09-29; two invalid endpoint rows are excluded.
  99. N04 duggytuxy Data-Shield IPv4 BlocklistCommunity IPv4 blocklist, 2026-09-29Large overlap with IPsum prevents treating cross-list presence as independent corroboration. Use exact-IP context and short review TTLs.
  100. N05 CAIDA RouteViews Prefix-to-AS datasetRouting dataset, 2026-09-13Origin-AS mappings change over time and MOAS routes require separate handling.
  101. N06 Arctic Wolf July 2025 Uptick in Akira Ransomware Activity Targeting SonicWall SSL VPNVendor incident research with IOCs, 2025-08-04The listed hosting networks are not inherently malicious; Arctic Wolf recommends limiting any blocking to VPN authentication.
  102. N07 Arctic Wolf Fog and Akira Ransomware Operations Linked to SonicWall SSL VPNVendor incident research with IOCs, 2024-10-24Historical exact-IP evidence; routing and ownership must be revalidated.
  103. N08 Augur Security Iran 2026 Threat Posture AssessmentThreat assessment with network ranges, 2026Campaign infrastructure does not imply provider complicity or actor nationality for every event.
  104. N09 Arctic Wolf Console Chaos: A Campaign Targeting Publicly Exposed Management Interfaces on Fortinet FortiGate FirewallsVendor incident research with IOCs, 2025-01-10Exact IPs are time-bounded; broad VPS and CDN networks require behavioral corroboration.
  105. N10 eSentire Tycoon 2FA Infrastructure UpdateIdentity threat research, 2026-04-01Infrastructure use does not establish provider complicity.
  106. N11 Okta Human-operated phishing kit targets cryptocurrency firmsIdentity threat research, 2026Shared hosting and proxy infrastructure can have legitimate customers.
  107. N12 Huntress Exploitation of SonicWall VPNVendor incident research, 2025Use with vulnerability, authentication, and post-access telemetry.
  108. N13 The DFIR Report Navigating Through the FogIntrusion report, 2025-04-28Incident-specific infrastructure does not imply all provider space is malicious.
  109. N14 Recorded Future Exposing TAG-53 Credential-Harvesting Infrastructure for Russia-Aligned Espionage OperationsThreat-actor infrastructure report, 2024Attribution applies to campaign infrastructure, not provider ownership.
  110. N15 Coralogix / Snowbit Evil Token: AI-Enabled Device Code Phishing CampaignIdentity threat research with IOC, 2026Exact IP and campaign context are time-bounded.
  111. N16 Resecurity SharePoint Zero-Day Exploit CVE-2025-53770 Network Infrastructure MappingExploitation infrastructure report, 2025IP allocation and current origin can change; no provider complicity is asserted.
  112. N17 Google Threat Intelligence Group UNC6671 Targets Financial Services and Enterprise Cloud EnvironmentsPrimary threat-intelligence report with IOCs, 2026-08-06Most source IPs were commercial VPN nodes and cycle quickly; residential ASNs should not be blocklisted.
  113. N18 Push Security We infiltrated a criminal phishing panel: here is what we foundPrimary phishing-panel research with hashes, 2026-05-07Short-lived domains and operator-gated pages reduce static IOC durability.
  114. N19 Censys Hiding in Plain Sight: Tracking Bulletproof Hosting and Abused RDP InfrastructureInternet-measurement threat research, 2026-02-03Censys distinguishes legitimate VPS abuse from BPH and warns attribution can be uncertain.
  115. N20 Cisco Talos ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365Primary identity-threat research with IOCs, 2026-07-01Cloudflare-hosted indicators do not support adding or blocking the whole Cloudflare ASN.
  116. N21 Team Cymru Validating ShinyHunters Cyber Threat Actors InfrastructureThreat-infrastructure research, 2026-08-05Campaign infrastructure is narrower than provider-wide attribution.
  117. N22 Sophos Malicious Use of Virtual Machine InfrastructureThreat research, 2026-02-04Shared VM infrastructure can create provider-level false positives.
  118. N23 Arctic Wolf Active Cloud Data Theft and Extortion Campaign Targeting Microsoft 365 and SaaS PlatformsVendor security bulletin, 2026-09-03Detection thresholds require tenant baselining.
  119. N24 Google Threat Intelligence Group Disrupting the Largest Residential Proxy NetworkPrimary disruption report, 2026-01-28Residential proxy use makes actor geography and ASN-wide treatment unreliable.
  120. N25 Google Threat Intelligence Group Google Continues Disruption of Residential Proxy NetworksPrimary disruption report, 2026-07-02Residential access ASNs must not be treated as malicious wholesale.
  121. N26 Google Threat Intelligence Group Expansion of ShinyHunters SaaS Data TheftPrimary threat-intelligence report, 2026-01-30TTP correlation is more durable than infrastructure-only matching.
  122. N27 Microsoft Security Passkey-Themed Social Engineering Leads to Identity and Cloud CompromisePrimary identity-threat research with domains, 2026-09-09Domain indicators rotate; monitor authentication and enrollment behavior.
  123. N28 FBI AVrecon Malware-Infected Routers Exploited as Residential Proxies by SocksEscortGovernment cyber alert, 2026-03The subscriber ASN and country can be innocent infrastructure.
  124. N29 PacketHub PacketHub official service siteOfficial provider information, 2026-09-15Provider marketing does not independently establish threat activity.
  125. N30 Netify NordVPN network and infrastructure profileNetwork intelligence profile, 2026-09-15Association is not evidence of corporate ownership or malicious operation.
  126. N31 Qurium Weaponizing Proxy and VPN ProvidersCivil-society network research, 2026-09-15Network relationships can change and do not imply all users are malicious.
  127. N32 Microsoft Security AI-Enabled Device Code Phishing CampaignPrimary identity-threat research, 2026-04-06Focus on OAuth device-code and token behavior, not infrastructure alone.
  128. N33 Ransomware.live Ransomware.live IoCsDynamic multi-group IOC repository, 2026-09-29The IP counter mixes bare IPv4, IPv4:port, and CIDR rows; public rows lack reliable observation dates and original source references. Revalidate exact indicators and do not promote an ASN from presence alone.
  129. N34 Elastic Security Labs Detecting Tycoon 2FA AiTM Attacks Across Entra ID and Google WorkspaceDetection engineering and threat research, 2026-05-26Cloud IP geolocation is unreliable for infrastructure classification; ASN is context, not verdict.
  130. N35 Cisco Talos Large-Scale Brute-Force Activity Targeting VPNs and SSH ServicesPrimary threat advisory with IOC repository, 2024-04-16Source IPs change. Campaign-time RouteViews mapping must be kept separate from current IP-to-AS mapping.
  131. N36 StrongVPN StrongVPN official service siteOfficial provider information, 2026-09-15Official provider information does not establish malicious activity or complicity.
  132. N37 Rapid7 Ongoing Malvertising Campaign Leads to RansomwareVendor incident research, 2024-05-13Historical holder continuity to current KORGRID is unresolved.
  133. N38 Silent Push Silent Push Tracks a Mass Phishing Operation Through Fast FluxPrimary vendor investigation, 2026-09-15Publication explicitly warns not every ASN in the rotation is bulletproof. ASN set is an analytic seed, not a blanket deny list. DNSPod and Keitaro are legitimate shared services.
  134. N39 GreyNoise Open Season on Kapibala: Attacker Steals Over 18,000 Government Records Through WordPress ExploitationPrimary vendor investigation, 2026-09-21Main persistent exploitation IP remains redacted; do not infer or de-redact it. Red Heron relationship and Chinese-speaking attribution are assessed, not proven. Published addresses do not imply provider complicity.
  135. N40 GreyNoise Swarming Against Citrix 0-Day ExploitationPrimary vendor telemetry, 2026-09-28Attempt against the Swarm sensor did not establish a foothold. IOC set is incomplete. Exact IP evidence is strong; same origin ASN alone is not proof of related attack activity.
  136. N41 Huntress Ready, Settra, Go: New Settra Ransomware Variant Deploys MeshAgent RMMPrimary vendor incident research, 2026-09-17Initial access unknown. MeshAgent is legitimate dual-use RMM; detection must correlate its server and behavior. Neither provider is labeled a bulletproof host by Huntress.
  137. N42 Spamhaus Botnet Threat Update January to June 2026Primary anti-abuse report, 2026-07-10Counts are not sign-in attack probabilities and are not normalized by provider size. Newly observed ranking does not measure response speed. Hyperscaler presence does not establish BPH status.
  138. N43 U.S. Department of the Treasury United States, Australia, and United Kingdom Sanction Russian Cybercrime Infrastructure Supporting RansomwareOfficial sanctions designation, 2025-11-19Designated legal entity is not automatically every rented upstream ASN. Requires legal/entity verification and current designation checking before sanctions enforcement.
  139. N44 U.S. Department of the Treasury Treasury Sanctions Malware and Infrastructure Providers Supporting Ransomware Attacks Against AmericansOfficial sanctions designation, 2026-07-131VPNS rents infrastructure under false identities. Sanctioned VPN reseller does not make its unrelated underlying hosting companies sanctioned. No exact ASN is designated here.
  140. N45 FBI First VPN Service Used by Ransomware Actors to Compromise SystemsOfficial FBI FLASH with IOCs, 2026-05-21FBI expressly warns that ephemeral cloud IPs may be reassigned and require current corroboration. Similar-named VPN services are excluded. May-era exit list is historical in September.
  141. N46 Spamhaus Bulletproof Hosting: Cutting off the facilitatorsPrimary anti-abuse methodology, 2026-06-11No named ASN in article. Use to improve methodology and collateral-risk controls, not as evidence to add a specific ASN.
  142. N47 Cisco Talos Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI usePrimary vendor investigation, 2026-09-17No exact public IP/ASN in extracted text. Russian-language attribution is suggestive. Wasabi and dual-use tools are not malicious providers; no ASN addition justified.
  143. N48 eSentire GhostCode: Dissecting a Novel Device Code Phishing KitPrimary incident research with vendor IOC repository, 2026-09-15Single observed incident. Residential addresses may be dynamic. Microsoft broker/resource IDs and scripting user agents are legitimate; correlate behavior. Source timestamp example has a weekday/date inconsistency, so use month-level observation scope.
  144. N49 eSentire GhostCode published IOC listVendor-owned IOC repository, 2026-09-15Lookalike domains are marked possible relations; compromised-site indicators should remain subdomain scoped.
  145. N50 Microsoft Unmasking EvilTokens: Getting to the root of device code phishingPrimary identity threat research, 2026-09-22No exact malicious IPs or new Clouvider/PacketHub attribution. Cloud platforms named are shared infrastructure, not malicious domains. A linked actor-profile label says Storm-2922 while narrative says Storm-2992; retain narrative attribution with discrepancy.
  146. N51 Microsoft DCU Disrupting EvilTokens: The AI Chatbot Built for CybercrimePrimary disruption announcement, 2026-09-22Disruption does not prove all affiliates stopped; no literal IOC list in announcement.
  147. N52 Microsoft Storm-3168: Agentic-driven cloud attacks using compromised service principalsPrimary cloud intrusion research with exact IPs, 2026-09-25Initial access unclear; exposed GitHub secret not confirmed used. No ransom note or successful exfiltration confirmed. Source gives no ASNs.
  148. N53 Microsoft DART Beyond source code: A path to the keys to the kingdomPrimary incident response case study, 2026-09-29No precise infrastructure IOC or ASN in blog. Do not infer vulnerability exploitation from valid-identity abuse.
  149. N54 Kaspersky GERT Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPOPrimary incident response research with exact IOCs, 2026-09-21Credential theft method, lateral movement and IP roles not determined due logging gaps. No ASNs supplied; no live C2 confirmed. Windows impact occurred without encryption.
  150. N55 Microsoft Star Blizzard refines phishing and malware delivery with the RedFlick techniquePrimary threat research with exact IOCs, 2026-09-29Mostly historical delivery infrastructure, not cloud sign-in source evidence. No ASNs supplied.
  151. N56 Microsoft Beyond the ransomware: Tracking Storm-2570's consistent tradecraft across deploymentsPrimary ransomware tradecraft research, 2026-09-24Initial access unconfirmed; no exact network indicators or provider ASN evidence extracted.
  152. N57 Proofpoint Spraying in the Andes: TeamFiltration Returns to Exploit Forgotten Service AccountsPrimary identity threat research with exact infrastructure, 2026-09-22AWS and DataCamp/CDN77 are shared infrastructure. Use the exact ranges, stale user agent, dormant-account pattern, failed-to-success sequence, and rapid ASN switch together; do not block the providers wholesale.
  153. N58 Huntress Railway PaaS abused in Microsoft 365 token replay campaignPrimary identity threat research with exact infrastructure, 2026-03-23Railway is a legitimate PaaS. Use the ranges with device-code and token-replay behavior, not ASN-wide.
  154. N59 Microsoft AI-enabled device code phishing campaignPrimary identity threat research with exact infrastructure, 2026-04-06Ranges given as network addresses without length. Shared hosting; correlate with device-code flow.
  155. N60 GreyNoise Hidden pattern in credential-based attacks on Palo Alto and SonicWallPrimary vendor telemetry, 2025-12-04GreyNoise notes these ASNs are not generally associated with malicious infrastructure.
  156. N61 Check Point Research Iran-nexus password spray campaign targeting cloud environments with a focus on the Middle EastPrimary identity threat research, 2026-03-31Commercial VPN exits are shared by many legitimate users.
  157. N62 FBI and US Secret Service FortiBleed Operations Continue Targeting Exposed Systems Leading to Reports of Lockouts (JCSA-20261006-01)Official joint cybersecurity advisory with IOCs, 2026-10-06The agencies warn the addresses may be reassigned and should be treated as historical within the activity window. ASNs are RIPEstat mappings, not stated in the advisory.
  158. N63 Huntress Two INC ransom notesPrimary vendor incident research, 2026-09-21Initial access vector not determined. Endpoint C2, not sign-in source evidence.
  159. N64 Netify DataCamp hosting profileHosting and application classification, 2026-10-07Undated profile, retrieved 2026-10-07. Shows hosted services, not abuse.

Who built this

I have spent about twenty years building and operating security systems, and I spent a long time before that learning how systems fail instead of how they are documented to work. That is roughly the skill this catalog needs, because the gap between what an autonomous system number is supposed to tell you and what it actually tells you is where all the false positives live. There is more about me on the about page.

This research exists because the generic version of it did not work in environments I was responsible for. The tiering, the review-only set, the separation of holder country from event geolocation and the insistence on recording what would make each row wrong are all consequences of watching the simpler approach fail. It is refreshed weekly, and the page is updated when the data changes, not when the date does.

INFOSTRUCTION

You're about to become an infostruction VIP!

By subscribing, you’ll receive a monthly round-up of the latest news. There’ll be no spam, I promise :)