Most teams that start watching where their traffic comes from build the same rule first, and most of them switch it off within a month. The rule says alert when someone connects from a hosting provider, and it fails for arithmetic reasons, not logical ones. A single large VPS network can carry a corporate VPN concentrator, a vendor’s jump box, a mobile carrier’s NAT egress and an attacker’s rented server on consecutive addresses, and the log shows the same autonomous system number for all four. Alerting on the network alone produces a volume nobody can triage, so the rule gets disabled and the environment ends up with less visibility than before it tried.
This is the catalog I built to make that problem tractable. It separates the networks where a connection genuinely warrants immediate attention from the much larger set where the network is context and nothing more, and it records why each row sits where it does along with what would make that judgement wrong.
An autonomous system number appears in almost every log that records a client address, so nothing here is specific to one vendor or one product. The tiering is the work; where you apply it is your choice.
Evidence and routing snapshot . Catalog rebuilt 2026-10-09.
- 1,151Catalog ASNsEvery researched autonomous system in the current standalone catalog.
- 559Enabled for monitoringRows switched on by default. The rest are disabled pending tenant validation.
- 403T1 CriticalHighest-priority identity and infrastructure risk.
- 60T2 HighDirect campaign, commercial anonymizer, or strong provider evidence.
- 107T3 ContextHosting and VPS context that needs a corroborating anomaly.
- 581T4 ReviewBroad cloud, access ISP and lifecycle-review rows, disabled by default.
- 431On Spamhaus ASN-DROPCurrent membership in the ASN-DROP snapshot for this build.
- 511Published indicatorsExact IPs, CIDRs, domains, hashes and application IDs with observation dates.
- 29Detection patternsIdentity and post-authentication patterns, each tied to its event sources.
- 159Cited sourcesEvery tiering decision resolves to one of these source records.
- 82Holder countries representedRIR holder registration, which is not where a sign-in came from.
- 592Review-only rowsCandidates examined and left disabled, with the reason recorded.
Downloads
If you came for the files, they are here rather than at the foot of the page. The Excel workbook is the fullest version and the one worth opening if you want to understand the work rather than automate against it. Every sheet is filtered and frozen, and the internal tuning columns are removed. The CSV bundle is the better choice for a SIEM import or any scripted analysis, the JSON carries every sheet in one document, and the text files are a plain ASN list for a quick lookup.
- Excel workbookEvery sheet, filtered and frozen, with the internal tuning columns removed.
- Everything, zippedThe workbook, every CSV, the JSON, the text files and the utilities.
- ASN catalog CSVThe full catalog, one row per autonomous system.
- Review-only CSVCandidates examined and left disabled, with the reason.
- Published indicators CSVExact IPs, CIDRs, domains, hashes and application IDs with dates.
- Provider evidence CSVThe named provider records, with role assessment and confidence.
- Detection patterns CSVIdentity and post-authentication patterns with event sources and TTPs.
- Provider families CSVAggregated view for handling a provider rather than one ASN.
- Country summary CSVHolder-registration rollup with the event-country policy column.
- Community feeds CSVThe public feeds used for exact-IP enrichment, with their limits.
- Sources CSVEvery cited source, what it supports and what it does not.
- Full JSONEvery sheet in one document, for automation.
- Enabled ASNs TXTOne ASN per line, for a quick import or a scripted lookup.
- T1 and T2 ASNs TXTThe alerting set only, for teams that want the narrow list.
- Sentinel Watchlist CSVShaped for a Microsoft Sentinel Watchlist keyed on ASNumber.
- KQL set literalsPaste-ready dynamic() sets for Defender XDR advanced hunting.
- Methodology and changelogTier definitions, operating rules, limitations and every cited source.
Free to use with attribution, CC BY 4.0. The internal tuning columns from the research workbook are removed from every file here.
Everything below explains what the tiers mean and how the rows were decided, which is worth reading before the catalog is wired into anything that alerts.
Where this applies
Anything that records the address a request came from can use this catalog, because an autonomous system number is a property of the address rather than of the service being connected to. In practice that covers identity providers and their sign-in logs, VPN concentrators and remote access gateways, firewalls and edge devices, SaaS audit trails, mail gateways, web application firewalls, and the SSH and RDP logs on anything exposed.
The worked examples further down lean on Entra ID and Microsoft 365 because that is where the detection patterns in this release are most developed, and the sign-in telemetry there is rich enough to show what corroboration actually looks like. There are also examples for Splunk against any source-IP index and for Okta, which carries the autonomous system number on every System Log event without any enrichment step. The logic in all of them is the same: find the connection worth looking at, then establish whether anything actually happened.
What the catalog does not do is decide anything on its own, on any platform. That is the next section, and it is the part most watchlists leave out.
An ASN is a risk feature, not attribution
That distinction decides everything else on this page, so it is worth being precise about. When a catalog like this one lists AS62240, it is recording that published reporting and incident evidence placed activity on that network. It is not saying the provider is complicit, that every address there is hostile, or that the operator behind a given sign-in is in the country the number is registered to. Each of those is a separate claim needing separate evidence, and conflating them is how a watchlist turns into an accusation.
What follows from that is a tiering scheme, which is a different artifact from a block list. A tier here answers one question: how much weight can a sign-in from this network carry on its own, before anything else corroborates it. For the top tier the answer is enough to justify looking immediately. For the bottom tier the answer is almost none, which is why those rows ship switched off.
Why a malicious ASN list produces false positives
The false positives are not noise around the edges of a working signal. They are structural. Four distinct causes are worth separating, because each one needs a different response.
Shared infrastructure is the largest. A hosting provider’s business model is renting capacity to anyone who pays, so the same network serves your backup vendor and somebody’s phishing panel simultaneously. The catalog handles this by refusing to promote a commodity hosting network above the context tier without direct evidence tying that specific network to identity attacks, which is why large VPS providers sit at T3 and need a second signal.
Commercial VPN egress is the second, and it is the one that catches organisations out most often. Consumer VPN providers aggregate thousands of unrelated subscribers behind a handful of exit networks. An employee who turns on a personal VPN on a work laptop appears from the same addresses an attacker using the same product would. Whether that is suspicious depends entirely on whether consumer VPN use is expected in your environment, which is a question about your policy, not about the network.
Provider size distorts every count. A network with a million customers generates more abuse reports than one with a thousand, and no feed in this catalog normalises for that. An ASN appearing frequently in indicator lists can simply mean it is large. Nothing here treats volume as evidence of a provider’s character.
Address reassignment breaks the link between history and the present. Prefixes move between holders, registrations get reassigned, and a network that hosted a campaign in 2024 may belong to an unrelated business now. This is why rows get removed on ownership change instead of carrying their old reputation forward, and why every indicator in the download states the window it was observed in. None of them are presented as currently true.
T1 to T4, and what effective enablement means
| Tier | Default | What puts an ASN here | How to handle a match | False-positive risk |
|---|---|---|---|---|
| T1 Critical | Enabled | Current high-confidence risk plus direct identity, BPH, or local critical evidence | Immediate triage of successful interactive sign-ins. Validate dependencies before deny actions. | Medium |
| T2 High | Enabled | Direct credential campaign, commercial anonymizer, or strong threat-infrastructure evidence | High-severity alert on success or failed-to-success sequence. | High |
| T3 Context | Enabled | Commodity VPS, hosting, or point-IOC provider context | Require identity, device, session, travel, MFA, or exfiltration corroboration. | High to very high |
| T4 Review | Disabled | Broad cloud, access ISP, uncertain continuity, or non-originating allocation | Tenant-specific review only. Never use as an ASN-only verdict. | Very high |
The tier sets the posture; the enabled flag decides whether a row is live at all. T1 and T2 are enabled throughout. T3 is enabled with a small number of exceptions where the evidence did not survive review. T4 is disabled throughout, and it is the largest tier in the catalog, which is the most honest thing about the structure. Those rows are broad cloud platforms, consumer access ISPs, allocations that are not currently announcing routes, and candidates whose ownership continuity could not be established. The research examined them, which is why they are in the file at all. They ship switched off because an ASN-only match on any of them is more likely to be an employee on a phone than an intruder.
The research workbook behind this release also carries a local override layer, so a row can be forced on or off for one tenant with the reason recorded next to it. That layer is specific to somebody’s environment and is stripped from every public file. What you are downloading is the researched default. Keep your own override column alongside it rather than editing the defaults in place, because the next refresh will otherwise revert decisions you made deliberately.
There is also a review-only set: candidates examined and left disabled, each with the reason recorded. It ships as its own file. What a catalog considered and rejected tells you more about how it was built than its inclusions do, and it is the part most watchlists never publish.
The high-interest ASNs and provider families
The table below carries every network the research can speak to by name, which means it either has a provider-level evidence record or a named actor or campaign attached. That makes the selection checkable instead of an arbitrary sample. The full catalog is considerably larger and ships in the download, because a table of that length is useful in a spreadsheet and hostile on a web page.
Filter by ASN, provider, country, campaign or category. The tier checkboxes narrow it further.
| ASN | Network | Tier | Holder | FP risk | Evidence |
|---|---|---|---|---|---|
AS8100 | SPLICE-AS-AP - Splice Internet Pty LtdShared hosting / VPS / cloud | T4 Review | AU | Very High | Campaign watch ended; retained for history
|
AS11878 | TZULO - tzulo, inc.Shared hosting / VPS / cloud | T3 Context | US | High | Campaign watch
|
AS12586 | ASGHOSTNET GHOSTnet GmbHShared hosting / VPS / cloud | T4 Review | DE | High | Behavior-correlated enrollment infrastructure
|
AS13335 | CLOUDFLARENET - Cloudflare, Inc.Shared hosting / VPS / cloud | T4 Review | US | Very High | Broad cloud/CDN control row
|
AS13926 | NETPROTECT-PHX - Strong Technology, LLC.Strong Technology / NetProtectCommercial VPN / hosting / proxy | T4 Review | US | High | Commercial VPN provider family expansion
|
AS14061 | DIGITALOCEAN-ASN - DigitalOcean, LLCShared hosting / VPS / cloud | T3 Context | US | Medium | Published campaign infrastructure in shared hosting or VPN space
|
AS14315 | 1GSERVERS - 1GSERVERS, LLCShared hosting / VPS / cloud | T4 Review | US | Very High | Campaign watch ended; retained for history
|
AS14956 | ROUTERHOSTING - RouterHosting LLCCommercial VPS/cloud hosting | T1 Critical | US | Medium | Current Spamhaus ASN-DROP
|
AS16276 | OVH OVH SASOVHcloudLarge shared cloud / VPS | T4 Review | FR | Very High | Broad cloud provider with exact historical IOCs
|
AS19318 | IS-AS-1 - Interserver, IncHosting / VPS / proxy | T3 Context | US | High | Campaign watch
|
AS20473 | AS-VULTR - The Constant Company, LLCUnknown / review | T3 Context | US | High | Broad VPS cloud with exact ransomware and management-interface IOCs
|
AS21249 | RUTIL-BG-AS Rutil Ltd.Shared hosting / VPS / cloud | T4 Review | BG | Very High | Campaign watch ended; retained for history
|
AS22781 | STRTEC - Strong Technology, LLC.Strong Technology / NetProtectCommercial VPN / hosting / proxy | T4 Review | US | High | Commercial VPN provider family expansion
|
AS23470 | RELIABLESITE - ReliableSite.Net LLCShared hosting / VPS / cloud | T4 Review | US | Very High | Campaign watch ended; retained for history
|
AS25369 | BANDWIDTH-AS Hydra Communications LtdShared hosting / VPS / cloud | T3 Context | GB | High | Campaign watch
|
AS25820 | IT7NET - IT7 Networks IncShared hosting / VPS / cloud | T4 Review | CA | High | Point-IOC provider context
|
AS29182 | RU-JSCIOT JSC IOTUnknown / review | T4 Review | RU | Very High | Historical single-IP actor infrastructure
|
AS29802 | HVC-AS - HIVELOCITY, Inc.Shared hosting / VPS / cloud | T3 Context | US | High | Campaign watch
|
AS30633 | LEASEWEB-USA-WDC - Leaseweb USA, Inc.Shared hosting / VPS / cloud | T4 Review | US | Very High | Campaign watch ended; retained for history
|
AS30823 | AUROLOGIC aurologic GmbHcombahton GmbHTransit / upstream carrier context only | T4 Review | DE | Very High | Legitimate upstream carrier, context only
|
AS32167 | LSHIY-USER-CONTENT - LSHIY LLCHosting / VPS / proxy | T3 Context | US | High | Campaign watch
|
AS32613 | IWEB-AS - Leaseweb Canada Inc.Shared hosting / VPS / cloud | T4 Review | CA | Very High | Campaign watch ended; retained for history
|
AS33993 | UFO-AS UFO Hosting LLCStark / PQ.Hosting / THE.Hosting / UFOBulletproof / high-risk hosting family | T1 Critical | RU | Medium | Sanctioned threat-activity-enabler successor (active)
|
AS35758 | HQSERV_NETWORKS Rachamim Aviel TwitoCommercial VPN / hosting / proxy | T4 Review | IL | Very High | Campaign watch ended; retained for history
|
AS36352 | AS-COLOCROSSING - HostPapaShared hosting / VPS / cloud | T4 Review | US | Very High | Campaign watch ended; retained for history
|
AS36680 | NETIFACELLC - Netiface LLCBulletproof / high-risk hosting family | T1 Critical | US | Low | Source-confirmed BPH (active)
|
AS39287 | materialism Materialism s.r.l.NjallaShared hosting / VPS / cloud | T2 High | RO | Medium | Related provider or broad shared-service context
|
AS39798 | MivoCloud MivoCloud SRLHosting / VPS / proxy | T4 Review | MD | Very High | Historical single-IP actor infrastructure
|
AS43350 | NFORCE NForce Entertainment B.V.Hosting / VPS / proxy | T4 Review | NL | Very High | Campaign watch ended; retained for history
|
AS43641 | Sollutium-NL SOLLUTIUM EU Sp z.o.o.Shared hosting / VPS / cloud | T4 Review | PL | Very High | Campaign watch ended; retained for history
|
AS43830 | DIGITALENERGY-AS Basis LLCUnknown / review | T4 Review | RU | Very High | Historical single-IP actor infrastructure
|
AS48721 | FLYSERVERS-ENDCLIENTS Flyservers S.A.Bulletproof / high-risk hosting family | T2 High | PA | Medium-High | Published BPH attribution, older evidence (active)
|
AS49468 | MAGHOST_RO MAGIT'ST SRLShared hosting / VPS / cloud | T4 Review | RO | High | Conditional fast-flux ASN seed
|
AS50867 | ORG-LVA15-AS HOSTKEY B.V.Shared hosting / VPS / cloud | T4 Review | NL | Very High | Campaign watch ended; retained for history
|
AS51396 | PFCLOUD Pfcloud UG (haftungsbeschrankt)Bulletproof / high-risk hosting family | T1 Critical | DE | Medium | BPH facilitator / upstream risk (active)
|
AS51852 | PLI-AS Private Layer INCShared hosting / VPS / cloud | T2 High | PA | Medium | Published campaign infrastructure in shared hosting or VPN space
|
AS53667 | PONYNET - FranTech SolutionsFranTech / BuyVMLow-cost VPS / VPN hosting | T3 Context | US | High | Campaign watch
|
AS54203 | NETPROTECT-SP - Strong Technology, LLC.Strong Technology / NetProtectCommercial VPN / hosting / proxy | T3 Context | US | Medium-High | Commercial VPN / proxy egress observed in brute-force campaign
|
AS55286 | SERVER-MANIA - B2 Net Solutions Inc.Shared VPS / dedicated hosting | T4 Review | CA | Very High | Campaign watch ended; retained for history
|
AS57523 | changway-as Chang Way Technologies Co. LimitedBulletproof / high-risk hosting family | T4 Review | HK | N/A | Unannounced or low-visibility ASN retained for review
|
AS57724 | DDOS-GUARD DDOS-GUARD LTDShared hosting / VPS / cloud | T3 Context | RU | Medium | Published campaign infrastructure in shared hosting or VPN space
|
AS58061 | SCALAXY-AS Scalaxy B.V.Shared hosting / VPS / cloud | T2 High | LV | Medium | Conditional fast-flux and shared-hosting context
|
AS59711 | HZ-EU-AS HZ Hosting LtdShared hosting / VPS / cloud | T3 Context | BG | High | Campaign watch
|
AS60117 | HS Host Sailor LtdBulletproof / high-risk hosting family | T2 High | AE | High | Published BPH attribution, older evidence (active)
|
AS60602 | INOVARE-AS Inovare-Prim SRLShared hosting / VPS / cloud | T4 Review | MD | Very High | Campaign watch ended; retained for history
|
AS61046 | HZ-UK-AS HZ Hosting LtdShared hosting / VPS / cloud | T3 Context | BG | High | Campaign watch
|
AS62005 | BV-EU-AS BlueVPS OUShared hosting / VPS / cloud | T4 Review | EE | Very High | Campaign watch ended; retained for history
|
AS62240 | Clouvider Clouvider LimitedShared hosting / VPS / colocation / proxy-exit ecosystem | T1 Critical | GB | Medium | Local incident plus repeated published identity and intrusion infrastructure
|
AS62651 | NETPROTECT-DP - Strong Technology, LLC.Strong Technology / NetProtectCommercial VPN / hosting / proxy | T3 Context | US | Medium-High | Commercial VPN / proxy egress observed in brute-force campaign
|
AS62904 | AS62904 - Eonix CorporationShared hosting / VPS / cloud | T4 Review | US | Very High | Campaign watch ended; retained for history
|
AS63473 | HOSTHATCH - HostHatch, LLCShared hosting / VPS / cloud | T4 Review | US | Very High | Campaign watch ended; retained for history
|
AS64236 | UNREAL-SERVERS - UnReal Servers, LLCShared hosting / VPS / cloud | T4 Review | US | Very High | Campaign watch ended; retained for history
|
AS131199 | NEXEON-AS-AP - Nexeon Technologies, Inc.Shared hosting / VPS / cloud | T4 Review | US | Very High | Campaign watch ended; retained for history
|
AS136787 | PACKETHUBSA-AS-AP - PacketHub S.A.Commercial VPN / hosting / proxy | T2 High | PA | Medium-High | Commercial VPN / anonymizer infrastructure
|
AS138915 | KAOPU-HK - Kaopu Cloud HK LimitedBulletproof / high-risk hosting family | T1 Critical | HK | Low | Current Spamhaus ASN-DROP
|
AS140952 | STL-AS-AP - Strong Technology, LLCStrong Technology / NetProtectCommercial VPN / hosting / proxy | T4 Review | US | High | Commercial VPN provider family expansion
|
AS141039 | PACKETHUBSA-AS-AP - PacketHub S.A.Commercial VPN / hosting / proxy | T2 High | PA | Medium-High | Commercial VPN / anonymizer infrastructure
|
AS147049 | PACKETHUBSA-AS-AP - PacketHub S.A.Commercial VPN / hosting / proxy | T2 High | AU | Medium-High | Commercial VPN / anonymizer infrastructure
|
AS149440 | EVOXTSDNBHD-AS-AP - Evoxt Sdn. Bhd.Shared hosting / VPS / cloud | T4 Review | MY | Very High | Campaign watch ended; retained for history
|
AS154177 | LIGHT4-AS-AP - LIGHT NODE LIMITEDkaopuyun.comMixed / not independently classified | T1 Critical | HK | Medium | Current Spamhaus ASN-DROP
|
AS197574 | EXPRESSHOST ExpressHost LtdShared hosting / VPS / cloud | T4 Review | GB | High | Conditional fast-flux ASN seed
|
AS197695 | AS-REGRU "Domain names registrar REG.RU", LtdShared hosting / registrar infrastructure | T3 Context | RU | High | Historical actor infrastructure concentration
|
AS198550 | nodehost-as NODE HOST LIMITEDShared hosting / VPS / cloud | T4 Review | GB | High | Conditional fast-flux ASN seed
|
AS200373 | Drei-K-Tech-GmbH 3xK Tech GmbH3xK Tech / Plain ProxiesProxy / BYOIP / transit infrastructure | T1 Critical | DE | Low | Current ASN-DROP + recent Microsoft login spraying
|
AS200651 | FlokiNET FlokiNET ehfShared hosting / VPS / cloud | T2 High | IS | Medium | Source-described bulletproof hosting monolith
|
AS201002 | PebbleHost-Customers PebbleHost LtdHosting / VPS / proxy | T3 Context | GB | High | Campaign watch
|
AS201738 | UFO-TECHNOLOGIES-LIMITED UFO TECHNOLOGIES LIMITEDBearhost-linkedBulletproof / high-risk hosting family | T1 Critical | GB | Low | Source-confirmed BPH (active)
|
AS201814 | Mevspace MEVSPACE sp. z o.o.Shared hosting / VPS / cloud | T2 High | PL | Medium | Published campaign infrastructure in shared hosting or VPN space
|
AS202015 | HZ-US-AS HZ Hosting LtdShared hosting / VPS / cloud | T3 Context | BG | High | Campaign watch
|
AS202412 | OMEGATECH-AS Omegatech LTDVirtualineBulletproof / high-risk hosting family | T1 Critical | SC | Low | Source-confirmed BPH (active)
|
AS203020 | HostRoyale HostRoyale Technologies Pvt LtdShared hosting / VPS / cloud | T4 Review | IN | Very High | Campaign watch ended; retained for history
|
AS204957 | GREENFLOID-AS ROUTE 95 LLCHosting / VPS / proxy | T4 Review | US | Very High | Campaign watch ended; retained for history
|
AS204997 | FIRSTBYTE-AS FIRST SERVER LIMITEDShared hosting / VPS / cloud | T3 Context | GB | Medium | Related provider or broad shared-service context
|
AS205090 | FIRST-SERVER-EUROPE FIRST SERVER LIMITEDShared hosting / VPS / cloud | T3 Context | GB | Medium | Published campaign infrastructure in shared hosting or VPN space
|
AS206728 | MEDIALAND-AS Media Land LLCMedia Land / ML CloudBulletproof / high-risk hosting family | T1 Critical | RU | Medium | Source-confirmed sanctioned BPH (active)
|
AS207137 | PACKETHUBSA PacketHub S.A.Commercial VPN / hosting / proxy | T2 High | PA | Medium-High | Commercial VPN / anonymizer infrastructure
|
AS207461 | host-industry HOSTING INDUSTRY LIMITEDShared hosting / VPS / cloud | T4 Review | GB | High | Point-IOC provider context
|
AS209378 | INIOS-AS Inios OyShared hosting / VPS / cloud | T4 Review | FI | High | Conditional fast-flux ASN seed
|
AS209588 | FLYSERVERS-ASN Flyservers S.A.Bulletproof / high-risk hosting family | T2 High | PA | Medium-High | Published BPH attribution, older evidence (active)
|
AS209847 | THE WorkTitans B.V.Stark / PQ.Hosting / THE.Hosting / UFOBulletproof / high-risk hosting family | T1 Critical | NL | Medium | Sanctioned threat-activity-enabler successor (active)
|
AS210328 | ALMAZ AO ALMAZHosting / VPS / proxy | T3 Context | RU | High | Campaign watch
|
AS210558 | services-1337-gmbh 1337 Services GmbHas210558.netMixed / not independently classified | T1 Critical | DE | Medium | Current Spamhaus ASN-DROP
|
AS210644 | AEZA-AS AEZA GROUP LLCBulletproof / high-risk hosting family | T1 Critical | RU | Medium | Source-confirmed sanctioned BPH (active)
|
AS211632 | ORG-ISI14-RIPE Internet Solutions & Innovations LTD.Hosting / VPS / proxy | T4 Review | SC | Very High | Campaign watch ended; retained for history
|
AS211663 | GALEON-AS GALEON LLCBearhost-linkedBulletproof / high-risk hosting family | T1 Critical | RU | Low | Source-confirmed BPH (active)
|
AS212171 | Local-as Local NCC Ltd.Hosting / VPS / proxy | T3 Context | GB | High | Campaign watch
|
AS212238 | CDNEXT Datacamp LimitedShared hosting / VPS / cloud | T2 High | GB | Medium | Commercial VPN / anonymizer infrastructure
|
AS213250 | ITP-SOLUTIONS Dominic Scholz trading as ITP-Solutions GmbH & Co. KGHosting / VPS / proxy | T3 Context | DE | High | Campaign watch
|
AS213511 | VSVK VSVK Onderhoud B.V.Bulletproof / high-risk hosting family | T4 Review | NL | N/A | Unannounced or low-visibility ASN retained for review
|
AS213929 | UP-NETWORK UP-NETWORK SarlHosting / VPS / proxy | T3 Context | CH | High | Campaign watch
|
AS213999 | THE-CLIENTS WorkTitans B.V.THE.Hosting clientsBulletproof / high-risk hosting family | T4 Review | NL | N/A | Unannounced or low-visibility ASN retained for review
|
AS214238 | iwihost HOST TELECOM LTDCommercial VPN / hosting / proxy | T4 Review | GB | Very High | Campaign watch ended; retained for history
|
AS214351 | FEMOIT FEMO IT SOLUTIONS LIMITEDBulletproof / high-risk hosting family | T1 Critical | GB | Medium | Source-confirmed BPH (active)
|
AS215439 | PLAY2GO-NET PLAY2GO INTERNATIONAL LIMITEDShared hosting / VPS / cloud | T4 Review | GB | High | Conditional fast-flux ASN seed
|
AS215540 | GCS-AS GLOBAL CONNECTIVITY SOLUTIONS LLPHosting / VPS / proxy | T3 Context | GB | High | Campaign watch
|
AS215703 | FREAKHOSTING FREAKHOSTING LTDShared hosting / VPS / cloud | T4 Review | GB | Very High | Campaign watch ended; retained for history
|
AS215929 | datacampus Data Campus LimitedHosting / VPS / proxy | T4 Review | HK | Very High | Campaign watch ended; retained for history
|
AS216246 | RU-AEZA-AS Aeza Group LLCBulletproof / high-risk hosting family | T1 Critical | RU | Medium | Source-confirmed sanctioned BPH (active)
|
AS219067 | CHIARA-AS Chiara ContiBulletproof / high-risk hosting family | T1 Critical | IT | Low | Current malicious prefix-hopping network
|
AS267784 | AS267784 - Flyservers S.A.Bulletproof / high-risk hosting family | T3 Context | PA | High | Campaign watch
|
AS272096 | AS272096 - PACKETHUB S.A.Commercial VPN / hosting / proxy | T2 High | PA | Medium-High | Commercial VPN / anonymizer infrastructure
|
AS394711 | KORGRID - KorGrid, LLCShared hosting / VPS / cloud | T4 Review | US | Critical | Historical LIMENET evidence; current-holder continuity unresolved
|
AS396356 | LATITUDE-SH - Latitude.shShared hosting / VPS / cloud | T4 Review | US | Very High | Campaign watch ended; retained for history
|
AS399629 | BLNWX - BL NetworksShared hosting / VPS / cloud | T4 Review | US | Very High | Campaign watch ended; retained for history
|
AS399979 | AS-493NETWORKING - 49.3 Networking LLCBulletproof / high-risk hosting family | T1 Critical | US | Low | Source-confirmed BPH (active)
|
AS400940 | RAILWAY - RailwayShared hosting / VPS / cloud | T4 Review | US | Very High | Campaign watch ended; retained for history
|
No named ASN matches that. The full catalog is in the download bundle, which carries every row rather than the named ones only.
Clouvider AS62240
Clouvider is a legitimate hosting and transit business, and AS62240 carries the catalog’s top tier. Both of those statements are true at once, which makes it the clearest illustration of what the tiering does and does not claim.
The network appears repeatedly in published reporting across credential replay, phishing authentication, malicious VPN access, ransomware access and command and control, and it also featured in a local compromise reported during 2026. Named activity associated with it in the catalog includes Tycoon 2FA, TAG-53, Akira, Fog and ToolShell. That accumulation of independent sightings is what supports immediate triage of a successful interactive employee sign-in from it.
It does not support a claim about Clouvider’s conduct as a company, and the row says so explicitly in its provider role field. The false-positive risk is recorded as medium, not low, and two related Clouvider networks sit in the review-only set at the context tier precisely because the evidence that justifies AS62240 does not transfer to them by association. A provider’s other networks are a separate question, and treating them as one decision is a common way to generate false positives while feeling thorough.
PacketHub, NordVPN egress and the anonymizer problem
Five active PacketHub networks are classified as commercial VPN and anonymizer infrastructure, and the catalog is deliberate about not calling them bulletproof hosting. These are a consumer VPN product’s exit capacity, which carries a different handling profile entirely.
One of the five carries direct token-replay evidence from device-code phishing activity. The rest are included as provider family rather than on individual evidence, and their confidence field records exactly that weaker basis. All five sit at the high tier with a medium to high false-positive risk, because the thing that makes them worth watching also makes them noisy: a legitimate employee with a NordVPN subscription arrives from the same place.
The operational answer is a policy decision before it is a detection decision. If consumer VPN use on managed devices is not expected in your environment, these networks are worth an alert and the alert will be meaningful. If it is tolerated or common, step-up authentication is the better response, and you will want these rows as context attached to other signals instead of a trigger of their own.
GTHost, and why Spamhaus ASN-DROP delisting is not exoneration
GTHost is a small, useful case study in reading feed membership over time. AS63023 was present in the Spamhaus ASN-DROP snapshot of 15 September 2026 and absent from the snapshot two weeks later. It remains in this catalog at the context tier.
Leaving a feed is a change in that feed. A delisting describes that list’s current contents and says nothing about whether the underlying network changed. Spamhaus reporting in the first half of 2026 separately identified GlobalTeleHost among newly prominent botnet command and control networks, and that observation did not expire when the ASN-DROP entry did. The row is kept at the context tier with a high false-positive risk, which is the honest position: enough to be worth correlating, not enough to alert on alone.
The same reasoning runs in the other direction. Appearing on ASN-DROP is current, high-confidence network risk and it is not proof that every customer of that network is malicious. Membership is a strong input to a tier and it is never the only one.
Bulletproof hosting ASNs and sanctioned networks
A smaller group of networks is in a genuinely different category, where the evidence speaks to the provider’s business and not merely to activity that happened to occur there. Spamhaus described Netiface in provider-level bulletproof-hosting terms directly. Media Land and Aeza are source-confirmed bulletproof hosting under sanctions. UFO Hosting is assessed by Recorded Future with high confidence as a successor to Stark infrastructure, and WorkTitans appears as another sanctioned successor entity. Others in the set are source-confirmed active bulletproof hosting, one is tracked as a current malicious prefix-hopping network, and one is recorded as a facilitator carrying upstream risk rather than hosting the activity itself.
These rows carry the top tier with a low to medium false-positive risk, which is unusually low for this catalog and reflects that very little legitimate enterprise traffic originates there. The confidence field on each one records whether the basis is a direct provider-level assessment or a successor and control relationship. Those are different strengths of claim, and collapsing them would overstate the weaker ones.
Joint guidance from CISA, NSA, FBI and international partners on mitigating bulletproof hosting risk is one of the sources behind this section, and it is also the source of a caution worth repeating: whole-ASN blocking affects legitimate services, so baselining, allowlisting and logging come before any deny decision.
Current credential campaigns and edge device infrastructure
Infrastructure rotates faster than tiers do, so the catalog separates ASN-level risk from exact indicators, each carrying its own observation window. Several campaign families drive the current indicator set.
Adversary-in-the-middle phishing kits remain the dominant credential theft route into Microsoft 365, and the catalog tracks both reverse-proxy infrastructure and the phishing-panel backends behind it. Device-code phishing and token replay are represented by their own detection patterns, because the sequence they produce in the logs is distinctive: the same identity and token appearing across different networks, addresses and user agents within minutes.
Anomalous application identifiers are a particularly clean signal when you have them. The catalog carries specific client and resource identifiers observed in campaign activity, including the broker application identifier abused by Tycoon 2FA. Alerting when an unexpected application identifier appears in your tenant’s authentication logs costs very little and does not depend on any network judgement at all.
Edge devices produce the fastest chains in the whole dataset. SonicWall SSL VPN access associated with Akira ransomware activity, and FortiGate management access followed by account creation, VPN configuration changes and credential access, both move from initial access to impact within hours. The detection patterns for those sequences correlate a hosting or VPN origin login with what happens immediately afterwards, which is the only part of the chain fast enough to matter.
Provider families, because a provider is one decision
A hosting business announcing thirty autonomous systems is one handling decision, not thirty. Working ASN by ASN through a family produces inconsistent coverage, where some of a provider’s networks are monitored and others are not for no reason anyone recorded. The family view is how to avoid that.
It also shows where concentration genuinely sits. The largest single family in the enabled set is a Moldovan hosting operation whose networks are almost entirely top tier, which is a more useful thing to know than any individual row within it.
| Provider family | Enabled | T1 | T2 | T3 | T4 | Holder countries |
|---|---|---|---|---|---|---|
| kontrast.md | 34 | 34 | 0 | 0 | 2 | MD:36 |
| Unclassified | 17 | 0 | 3 | 14 | 114 | BR:33, RU:17, MD:13, UA:12, MX:7, US:6, AR:5, IN:5, GB:3, AL:2, AM:2, CO:2, DE:2, HK:2, ID:2, TR:2, VE:2, AE:1, AT:1, DO:1, EC:1, ES:1, GT:1, IQ:1, IR:1, KE:1, LB:1, RO:1, UZ:1, ZA:1, ZZ:1 |
| bignet.ua | 14 | 14 | 0 | 0 | 3 | UA:11, NL:6 |
| cloudie.hk | 9 | 9 | 0 | 0 | 0 | HK:8, US:1 |
| pitline.net | 9 | 9 | 0 | 0 | 0 | UA:6, CH:1, FR:1, RU:1 |
| ipswat.com | 6 | 6 | 0 | 0 | 0 | US:6 |
| serverion.com | 6 | 6 | 0 | 0 | 0 | NL:4, US:2 |
| bunnycommunications.com | 5 | 5 | 0 | 0 | 0 | US:4, JP:1 |
| fineproxy.org | 5 | 5 | 0 | 0 | 0 | ZA:3, IL:1, RU:1 |
| PacketHub | 5 | 0 | 5 | 0 | 0 | PA:4, AU:1 |
| 62yun.com | 4 | 4 | 0 | 0 | 1 | US:3, KG:1, NG:1 |
| bunea.eu | 4 | 4 | 0 | 0 | 0 | RO:3, GB:1 |
| centralnic.com | 4 | 0 | 4 | 0 | 0 | GB:4 |
| globaltelehost.com | 4 | 0 | 0 | 4 | 1 | CA:4, US:1 |
| lordvps.net | 4 | 4 | 0 | 0 | 0 | IR:3, ZA:1 |
| netinnovation.net | 4 | 4 | 0 | 0 | 0 | US:4 |
| almaseabi.net | 3 | 3 | 0 | 0 | 0 | GB:1, IR:1, RS:1 |
| alphainfolab.com | 3 | 3 | 0 | 0 | 0 | US:2, IN:1 |
| chosting.solutions | 3 | 3 | 0 | 0 | 0 | GB:3 |
| eksenbilisim.com.tr | 3 | 3 | 0 | 0 | 0 | TR:3 |
| ipconnect.services | 3 | 3 | 0 | 0 | 0 | SC:3 |
| ithostline.com | 3 | 3 | 0 | 0 | 0 | IN:2, CY:1 |
| net-gate.ro | 3 | 3 | 0 | 0 | 0 | RO:3 |
| netiface.co.uk | 3 | 3 | 0 | 0 | 0 | US:2, GB:1 |
| qwins.co | 3 | 3 | 0 | 0 | 0 | GB:1, LV:1, UA:1 |
| rapidoserver.com | 3 | 3 | 0 | 0 | 0 | IR:3 |
| ryzehosting.com | 3 | 3 | 0 | 0 | 0 | AT:3 |
| sunucun.com.tr | 3 | 3 | 0 | 0 | 0 | TR:2, BR:1 |
| xor.sc | 3 | 3 | 0 | 0 | 0 | SC:3 |
| Flyservers | 3 | 0 | 2 | 1 | 0 | PA:3 |
| Aeza Group | 2 | 2 | 0 | 0 | 0 | RU:2 |
| Bearhost-linked | 2 | 2 | 0 | 0 | 0 | GB:1, RU:1 |
| berdiev-ruslan-mukhabatovich | 2 | 2 | 0 | 0 | 0 | RU:2 |
| changway.hk | 2 | 2 | 0 | 0 | 0 | HK:2 |
| cognetcloud.com | 2 | 2 | 0 | 0 | 0 | US:2 |
| ddps.jp | 2 | 2 | 0 | 0 | 0 | JP:2 |
| dedik.io | 2 | 2 | 0 | 0 | 0 | GB:2 |
| ekoiniciative.pp.ua | 2 | 2 | 0 | 0 | 0 | UA:2 |
| FIRST SERVER | 2 | 0 | 0 | 2 | 0 | GB:2 |
| globtelgroup.com | 2 | 2 | 0 | 0 | 0 | US:2 |
Holder country against event-time IP geolocation
The country field in this catalog records where an autonomous system’s holder is registered with its regional internet registry. That is useful for understanding provider ownership context. For deciding where a sign-in came from it is close to useless, and treating it as a location is the single most common way to misread data of this kind.
The catalog’s own numbers make the point better than an argument does. The United States holds more top-tier networks in this catalog than any other country, by a clear margin. Brazil has a large number of catalog entries and very few enabled ones, because almost all of them are broad access networks that sit in the disabled review tier. A country-based filter built on holder registration would miss most of the first case and generate noise on the second.
For geography-based rules, use event-time IP geolocation and apply the event-country policy column to that, marking each country as expected, no employees, or prohibited according to where your people actually are. Then correlate a match with user history, managed device state, anonymizer classification, travel feasibility and authentication method. A United States exit address can carry a foreign operator’s traffic, and a foreign-registered server can be a compromised host belonging to anyone.
| Holder country | In catalog | Enabled | T1 | T2 | T3 | T4 |
|---|---|---|---|---|---|---|
| United States US | 146 | 94 | 61 | 10 | 23 | 52 |
| United Kingdom GB | 80 | 55 | 39 | 6 | 19 | 16 |
| Ukraine UA | 82 | 47 | 43 | 0 | 4 | 35 |
| India IN | 73 | 47 | 44 | 1 | 2 | 26 |
| Moldova MD | 51 | 36 | 35 | 0 | 1 | 15 |
| Russia RU | 96 | 27 | 20 | 1 | 7 | 68 |
| Türkiye TR | 47 | 25 | 9 | 13 | 3 | 22 |
| Hong Kong SAR China HK | 27 | 23 | 18 | 0 | 5 | 4 |
| Germany DE | 29 | 19 | 10 | 2 | 7 | 10 |
| Seychelles SC | 20 | 17 | 16 | 0 | 1 | 3 |
| Netherlands NL | 24 | 12 | 10 | 0 | 3 | 11 |
| Iran IR | 12 | 11 | 10 | 0 | 1 | 1 |
| Brazil BR | 97 | 9 | 2 | 3 | 4 | 88 |
| Vietnam VN | 16 | 9 | 4 | 3 | 2 | 7 |
| Romania RO | 12 | 9 | 7 | 1 | 1 | 3 |
| Panama PA | 9 | 9 | 0 | 7 | 2 | 0 |
| Bangladesh BD | 33 | 7 | 7 | 0 | 0 | 26 |
| Bulgaria BG | 11 | 7 | 4 | 0 | 3 | 4 |
| Indonesia ID | 20 | 6 | 6 | 0 | 0 | 14 |
| South Africa ZA | 8 | 6 | 6 | 0 | 0 | 2 |
| Kazakhstan KZ | 9 | 5 | 3 | 2 | 0 | 4 |
| Japan JP | 8 | 5 | 5 | 0 | 0 | 3 |
| Lithuania LT | 5 | 5 | 1 | 0 | 4 | 0 |
| Poland PL | 28 | 4 | 0 | 3 | 1 | 24 |
| France FR | 11 | 4 | 1 | 2 | 1 | 7 |
| Pakistan PK | 11 | 4 | 4 | 0 | 0 | 7 |
| Canada CA | 9 | 4 | 0 | 1 | 3 | 5 |
| Israel IL | 5 | 4 | 4 | 0 | 0 | 1 |
| China CN | 8 | 3 | 3 | 0 | 0 | 5 |
| Austria AT | 5 | 3 | 3 | 0 | 0 | 2 |
Detection patterns, including Entra ID risky sign-in monitoring
The patterns below are the logic, recorded with the event sources each one needs, what has to corroborate it, and the ATT&CK techniques involved. Most are written against identity telemetry because that is where the evidence in this release is deepest, and the shape of each one carries over to any system that logs an address alongside an account. They are stated as logic and not as finished rules, deliberately. Thresholds that work in one tenant are wrong in another, and a rule presented as universal invites being deployed without tuning.
The ones marked critical share a shape worth noticing. Almost none of them fire on a sign-in. They fire on what happens after it: an authentication method being registered, a token appearing from a second network, a scripted client reading files in bulk, a device registration following suspected session theft. Sign-in infrastructure is how you find the session worth looking at, and post-authentication behaviour is how you establish that something actually happened.
Anonymizer plus high-volume exfiltrationCritical
- Logic
- VPN/proxy/anonymizer source plus at least 5 GB or 1,000 file events in 2 hours.
- Event sources
- File events, bytes, ASN/anonymizer class, user/session
- What has to corroborate it
- Use a slower companion rule to catch low-and-slow theft.
- Response
- Suspend session and investigate data scope.
- ATT&CK
- T1530; T1567
- Sources
- N23, N26
Device-code phishing or token replayCritical
- Logic
- Unexpected OAuth device-code flow, token replay, or the same identity/session across different IP, ASN, user-agent, and interactive/non-interactive token streams.
- Event sources
- OAuth/device-code events, token/session IDs, IP, UA, app ID
- What has to corroborate it
- Validate approved CLI and device-code workflows.
- Response
- Revoke tokens, remove consent/persistence, reset account, and hunt post-authentication actions.
- ATT&CK
- T1528; T1550.001; T1078.004
- Sources
- N15, N20, N32, N48, N50
Edge exploitation exact-IOC and artifact correlationCritical
- Logic
- Exact Kapibala or Citrix source, C2, webshell path/hash, or wildcard domain appears with exploit requests, configuration change, process execution, or credential access.
- Event sources
- Citrix/FortiGate/web logs; EDR; DNS and network telemetry
- What has to corroborate it
- Exact IOC alone starts a retro-hunt; containment requires target-side evidence or a confirmed malicious session.
- Response
- Isolate the appliance or host, preserve volatile evidence, rotate exposed credentials, and search for persistence.
- ATT&CK
- T1190; T1505.003; T1059
- Sources
- N39, N40
FortiGate Console Chaos chainCritical
- Logic
- jsconsole or management access followed by account creation, VPN configuration change, or DCSync behavior.
- Event sources
- FortiGate config/admin logs, VPN changes, AD replication
- What has to corroborate it
- Sequence is higher confidence than any source ASN alone.
- Response
- Contain appliance and identity plane; rotate credentials and inspect domain compromise.
- ATT&CK
- T1190; T1136; T1003.006
- Sources
- N09, N54
PRT or rogue-device persistenceCritical
- Logic
- New device registration or PRT-capable enrollment after suspected AiTM or token theft.
- Event sources
- Device registration, PRT indicators, sign-in and audit logs
- What has to corroborate it
- Session revocation alone may not remove device-backed persistence.
- Response
- For confirmed compromise, inspect and disable every rogue device, revoke tokens and sessions, reset credentials, remove inbox or consent persistence, and consider temporary account disablement.
- ATT&CK
- T1098; T1550.001
- Sources
- N20, N27, N34, N48, N50
SSPR takeover to pipeline and Kubernetes credentialsCritical
- Logic
- Unexpected self-service password reset or auth-method registration followed by Azure DevOps enumeration, pipeline or service-connection edits, kubeconfig collection, or tunnel/RMM deployment.
- Event sources
- Entra audit; Azure DevOps audit; repository and Kubernetes logs
- What has to corroborate it
- Correlate recovery event, identity novelty, pipeline access, and credential retrieval. Legitimate recovery and engineering administration require allowlists.
- Response
- Revoke identity, pipeline, cloud, and cluster credentials; remove persistence and inspect downstream deployments.
- ATT&CK
- T1098; T1552; T1078
- Sources
- N53
Separated auth, recon, and exfil sourcesCritical
- Logic
- Correlate one identity across different source IPs/ASNs for authentication, Graph reconnaissance, and data exfiltration.
- Event sources
- Identity/session IDs across sign-in, Graph, and file audit
- What has to corroborate it
- Do not require one source IP across the attack chain.
- Response
- Treat as coordinated session theft unless validated.
- ATT&CK
- T1078; T1090; T1530
- Sources
- N17, N23, N34, N48, N50
SonicWall VPN rapid-impact chainCritical
- Logic
- Hosting/VPN-origin login followed within hours by lateral movement, credential access, remote tools, exfiltration, or encryption.
- Event sources
- SonicWall auth, EDR, SMB/RDP, AnyDesk/FileZilla, file encryption
- What has to corroborate it
- Arctic Wolf observed rapid impact; exact timing varies by intrusion.
- Response
- Contain VPN session and endpoints; inspect credential exposure and ransomware staging.
- ATT&CK
- T1133; T1078; T1021; T1486
- Sources
- N06, N07, N12, N54, N56, N47
Suspicious login followed by authenticator enrollmentCritical
- Logic
- Unexpected device-code or token use followed within about 15 minutes by passkey, phone, software-token, Intune, Device Registration Service, PRT-capable, or burst multi-device enrollment, including non-interactive sign-ins.
- Event sources
- Sign-in, authentication-method change, device registration audit
- What has to corroborate it
- Approved onboarding should be allowlisted by workflow and device.
- Response
- Remove rogue method/device, reset account, then revoke sessions.
- ATT&CK
- T1098; T1556
- Sources
- N23, N27, N34, N48, N50
Unauthorized MeshAgent or tunnel plus ransomware behaviorCritical
- Logic
- Unapproved MeshAgent, Atera, ngrok, Cloudflared, Chisel, or Ligolo activity correlated with exact C2, BYOVD, credential access, recovery inhibition, log deletion, or bulk exfiltration.
- Event sources
- EDR; network telemetry; RMM inventory; Windows event logs
- What has to corroborate it
- Dual-use tools require inventory and behavioral corroboration.
- Response
- Contain the endpoint and remote-management channel, rotate credentials, restore recovery controls, and scope exfiltration.
- ATT&CK
- T1219; T1562.001; T1490; T1567
- Sources
- N41, N47, N56
VPS-origin management HTTPS anomalyCritical
- Logic
- Management HTTPS from hosting/VPS source lasting over 100 seconds and transferring over 1 MB.
- Event sources
- Firewall flow, URL, bytes, duration, source ASN
- What has to corroborate it
- Tune for approved administrators and scanners.
- Response
- Isolate management plane, collect configuration/audit logs, and hunt account/VPN changes.
- ATT&CK
- T1190
- Sources
- N09
Valid VPN account to domain-root GPO impactCritical
- Logic
- Novel or unexpected VPN valid-account access followed by domain-root GPO creation or gPLink changes, non-replication SYSVOL writes, and firewall or security-policy weakening.
- Event sources
- FortiGate VPN; Windows 5137/5136/4663/4657; Sysmon 11; SYSVOL integrity
- What has to corroborate it
- Do not require encryptor execution. Baseline approved GPO deployment, replication, and emergency administration.
- Response
- Contain the VPN session and account, disable malicious GPOs, restore SYSVOL and security policy, and scope extortion activity.
- ATT&CK
- T1133; T1078; T1484.001; T1562.004
- Sources
- N54
Workload identity ARM credential and destruction sequenceCritical
- Logic
- Novel service-principal source or enumeration burst followed by Storage ListKeys, resource deletion, or recovery/backup-lock deletion attempts.
- Event sources
- Entra service-principal sign-ins; Azure Activity and ARM logs
- What has to corroborate it
- Require workload-identity novelty, privilege context, and destructive or credential-access operations; shared cloud sources and scripting agents are not sufficient alone.
- Response
- Disable or rotate the service-principal credential, contain affected resources, restore protections, and scope accessed keys.
- ATT&CK
- T1078.004; T1526; T1485
- Sources
- N52
Conditional multi-ASN fast-flux phishingHigh
- Logic
- Domain delegates through the reported DNS pattern and rotates across at least four ASNs and four IPs, with at least three ASNs from the source seed set, plus phishing or credential-capture evidence.
- Event sources
- Passive DNS; DNS logs; web telemetry; identity sign-ins
- What has to corroborate it
- Require the full diversity/delegation pattern or brand/identity behavior. DNSPod and every seed ASN are not malicious by themselves.
- Response
- Block the malicious domain and session, preserve DNS history, and pivot across the rotating infrastructure.
- ATT&CK
- T1566; T1583.001; T1090
- Sources
- N38
Cross-ASN same-user session sequenceHigh
- Logic
- Same user or token appears from different ASNs within minutes, especially cloud VPS followed by residential or commercial VPN.
- Event sources
- Sign-in, token/session ID, ASN, IP, user agent
- What has to corroborate it
- Legitimate mobile/VPN changes can occur; session continuity raises confidence.
- Response
- Inspect token/session IDs, revoke confirmed replay, and hunt related activity.
- ATT&CK
- T1550.001; T1090
- Sources
- N17, N34
Distributed password sprayHigh
- Logic
- Aggregate failures by tenant/account set/password pattern/time window rather than per source IP.
- Event sources
- Authentication failures, account set, timestamps, source ASN/family
- What has to corroborate it
- Residential and commercial proxy rotation defeats per-IP thresholds.
- Response
- Rate-limit, block proven exact IPs, and investigate any success.
- ATT&CK
- T1110.003
- Sources
- N35
Dormant service-account spray and rapid source switchHigh
- Logic
- Stale TeamFiltration user agent or distributed failures against dormant service accounts followed by success and a rapid switch from AWS EC2 spray infrastructure to a different VPN/hosting ASN.
- Event sources
- Entra sign-ins; service-account inventory; user-agent and ASN history
- What has to corroborate it
- Require account dormancy or unusual use, failed-to-success sequence, user-agent match, or post-access behavior. Do not alert on AWS ranges alone.
- Response
- Disable or rotate the forgotten credential, revoke sessions, review service dependencies, and hunt tenant-wide spray targets.
- ATT&CK
- T1110.003; T1078; T1090
- Sources
- N57
Exact IOC match with time scopeHigh
- Logic
- Exact IP, CIDR, domain, hash, or app ID matches a published indicator within its review TTL.
- Event sources
- IOC type/value, source, observed dates, current mapping
- What has to corroborate it
- Stale IP mappings and shared infrastructure are common.
- Response
- Validate current routing/ownership and campaign context before blocking or attribution.
- ATT&CK
- Indicator lifecycle
- Sources
- S02, N33, N39, N40, N41, N45, N48, N49, N52, N54, N55, N57
Graph reconnaissance burstHigh
- Logic
- After unusual sign-in, at least 10 requests spanning 3 object categories or 6 Graph paths within 30 minutes.
- Event sources
- Graph audit, application ID, user, paths, timestamps
- What has to corroborate it
- Tune for administrators and automation accounts.
- Response
- Investigate identity, app, and data access; revoke confirmed malicious sessions.
- ATT&CK
- T1087; T1526
- Sources
- N17, N23, N34, N48, N50
Historical First VPN Service activityHigh
- Logic
- Historical match to FBI-listed 1VPNS IPs or domains during the relevant period, especially with failed-to-success access, unfamiliar device/MFA/session, scanning, malware deployment, or exfiltration.
- Event sources
- VPN, identity, edge, DNS, and proxy logs
- What has to corroborate it
- The May and older exit IPs may be reassigned. Require time alignment and current ownership/service validation for present-day action.
- Response
- Use for retro-hunting and incident scoping; block current infrastructure only after revalidation.
- ATT&CK
- T1090; T1133; T1078; T1046; T1110
- Sources
- N44, N45
Hosting or VPN sign-in plus noveltyHigh
- Logic
- Hosting/VPN/proxy ASN plus new ASN for user, new device, unmanaged device, or unusual event country.
- Event sources
- Sign-in, device compliance, user baseline, event-time geolocation
- What has to corroborate it
- Travel and approved VPN use can explain novelty.
- Response
- Step up authentication or investigate; contain only with corroboration.
- ATT&CK
- T1078.004; T1090
- Sources
- N17, N34
Impossible travel with infrastructure changeHigh
- Logic
- Same identity succeeds from distant geographies or incompatible ASNs within an infeasible interval.
- Event sources
- Sign-in times, event IP countries, ASN, device/session ID
- What has to corroborate it
- Cloud and VPN geolocation can be noisy; weigh device and session continuity.
- Response
- Revoke suspicious sessions and validate both events.
- ATT&CK
- T1078.004
- Sources
- N17, N34
Known malicious or anomalous application IDHigh
- Logic
- Observed client/resource IDs 9199bf20-a13f-4107-85dc-02114787ef48, c999ed3e-27ae-4cb3-b3a2-46b056af63d3, or campaign-linked application IDs.
- Event sources
- Sign-in, service principal, consent, Graph audit
- What has to corroborate it
- Application IDs can be reused in legitimate testing; validate tenant inventory.
- Response
- Validate consent and expected use; revoke and investigate if unauthorized.
- ATT&CK
- T1528
- Sources
- N23
Low-and-slow SaaS exfiltrationHigh
- Logic
- Unusual identity or anonymizer steadily accesses multiple sensitive repositories below burst thresholds.
- Event sources
- FileAccessed, repository/category count, time series, ASN
- What has to corroborate it
- Tenant baselines and job role are essential.
- Response
- Compare with role baseline and investigate unexplained cross-repository access.
- ATT&CK
- T1530; T1119
- Sources
- N17, N23, N26
No-employee or prohibited event countryHigh
- Logic
- Successful employee sign-in where event-time IP country is marked No Employees or Prohibited.
- Event sources
- Event IP geolocation, user HR/location policy, ASN and anonymizer flags
- What has to corroborate it
- Use event IP country, not ASN registration country. VPN exits can mask actor location.
- Response
- Block or step up according to policy; investigate exceptions.
- ATT&CK
- T1078.004
- Sources
- N01, N24, N25
Password spray then successHigh
- Logic
- Multiple failures across accounts followed by success from related proxy, VPN, or hosting infrastructure.
- Event sources
- Failure and success logs, source ASN/family, targeted accounts
- What has to corroborate it
- Aggregate across rotating IPs and provider families.
- Response
- Reset or protect affected account; inspect source cluster and subsequent access.
- ATT&CK
- T1110.003; T1078
- Sources
- N06, N07, N35
Scripting user agent with broad file accessHigh
- Logic
- python-requests/2.28.1 or 2.34.2, python-httpx, PowerShell, curl, or other rare scripting agents access at least 100 files in 2 hours or follow token/device enrollment.
- Event sources
- FileAccessed, user agent, app ID, file count, ASN
- What has to corroborate it
- Known backup and migration tools require allowlists.
- Response
- Validate automation owner; investigate and contain unexplained access.
- ATT&CK
- T1119; T1530
- Sources
- N23, N34, N48, N50
Successful interactive sign-in from T1/T2 networkHigh
- Logic
- Successful employee interactive login where ASN tier is T1 or T2 and the ASN is enabled.
- Event sources
- Entra/Google sign-in, ASN, IP, auth type, device, user agent
- What has to corroborate it
- ASN match is high-priority context, not automatic proof.
- Response
- Triage immediately; verify user intent, device, MFA, session, and post-authentication behavior.
- ATT&CK
- T1078.004
- Sources
- S02, N17, N34
Broad cloud or CDN ASN-only matchInformational
- Logic
- Sign-in or traffic only matches a disabled broad cloud/CDN ASN without other anomalies.
- Event sources
- ASN, exact IOC, device, user baseline, application
- What has to corroborate it
- Prevents false positives from AWS, Google, Microsoft, Cloudflare, Akamai, and similar networks.
- Response
- Record as context; do not alert or block without exact IOC or behavior.
- ATT&CK
- Context-only control
- Sources
- N17, N20, N34
Worked examples for Sentinel, Defender XDR, Splunk and Okta
These queries implement some of the patterns above. Each one states what it needs and what it will wrongly catch, because a detection shipped without its false-positive mode is a detection somebody disables in week two, and the reason they disable it is that nobody told them what to allowlist first.
The Splunk example is the generic one worth reading even if you do not run Splunk, because it shows the whole pattern in four lines: enrich an address with its autonomous system number, join the catalog, filter on tier. Every other query here is a variation on that with a vendor’s field names.
They are correct against the documented schemas as far as review establishes, and they have not been executed against a live tenant as part of this release. Check the Entra audit operation names in the enrollment query against your own environment before trusting it: those operations have been renamed before, and a stale string matches nothing while looking perfectly healthy.
Successful interactive sign-in from a T1 or T2 networkMicrosoft Sentinel
The base case. A real employee account authenticated successfully, interactively, from infrastructure the catalog has direct identity, campaign, anonymizer or bulletproof-hosting evidence for. This is a triage queue, not an alert you can act on blind.
// Needs a Watchlist named CloudASNRiskWatchlist, built from
// utilities/sentinel-watchlist.csv. _GetWatchlist returns every column as a
// string, which is why ASNumber is cast before the join.
let watch =
_GetWatchlist('CloudASNRiskWatchlist')
| where Enabled == "Yes" and Tier in ("T1 Critical", "T2 High")
| project ASNumber = toint(ASNumber), Tier, ProviderFamily, Category, FPRisk;
SigninLogs
| where TimeGenerated > ago(7d)
| where ResultType == 0
| where IsInteractive == true
| join kind=inner watch on $left.AutonomousSystemNumber == $right.ASNumber
| project
TimeGenerated,
UserPrincipalName,
IPAddress,
AutonomousSystemNumber,
Tier,
ProviderFamily,
Category,
FPRisk,
EventCountry = tostring(LocationDetails.countryOrRegion),
AppDisplayName,
ClientAppUsed,
UserAgent,
Device = tostring(DeviceDetail.displayName),
Compliant = tostring(DeviceDetail.isCompliant)
| order by TimeGenerated desc- Needs
- A Sentinel Watchlist named CloudASNRiskWatchlist, imported from utilities/sentinel-watchlist.csv with ASNumber as the key.
- What it will wrongly catch
- Anyone using a personal VPN, a vendor working from a hosted jump box, or a mobile carrier that backhauls through a hosting ASN. Expect to allowlist your own SASE and admin jump hosts before this is quiet enough to watch.
- Catalog pattern
- Successful interactive sign-in from T1/T2 network
Watchlist ASN that is new for this userMicrosoft Sentinel
The ASN match on its own is weak. Pairing it with a fourteen-day per-user baseline is what turns it into a signal, because the employee who always connects through the same hosting ASN stops generating noise while a first appearance surfaces.
let lookback = 14d;
let watch =
_GetWatchlist('CloudASNRiskWatchlist')
| where Enabled == "Yes"
| project ASNumber = toint(ASNumber), Tier, ProviderFamily;
// The baseline deliberately stops at ago(1d) so today's activity cannot
// baseline itself and disappear.
let baseline =
SigninLogs
| where TimeGenerated between (ago(lookback) .. ago(1d))
| where ResultType == 0
| summarize KnownAsns = make_set(AutonomousSystemNumber, 1000)
by UserPrincipalName;
SigninLogs
| where TimeGenerated > ago(1d)
| where ResultType == 0
| where IsInteractive == true
| join kind=inner watch on $left.AutonomousSystemNumber == $right.ASNumber
| join kind=leftouter baseline on UserPrincipalName
| where isnull(KnownAsns) or not(set_has_element(KnownAsns, AutonomousSystemNumber))
| project
TimeGenerated,
UserPrincipalName,
IPAddress,
AutonomousSystemNumber,
Tier,
ProviderFamily,
NoBaseline = isnull(KnownAsns),
Device = tostring(DeviceDetail.displayName),
Compliant = tostring(DeviceDetail.isCompliant),
EventCountry = tostring(LocationDetails.countryOrRegion)
| order by TimeGenerated desc- Needs
- The same Watchlist, plus at least fourteen days of SigninLogs retention for the baseline to mean anything.
- What it will wrongly catch
- A genuinely new but legitimate network: a new office, a new VPN vendor, the first week of a new starter. The baseline is also empty for anyone who has not signed in during the lookback, which is why the null case is kept visible rather than dropped.
- Catalog pattern
- Hosting or VPN sign-in plus novelty
Device-code authentication and token replayMicrosoft Sentinel
Device-code flow has a narrow legitimate footprint in most tenants, so an unexpected success is worth reading on its own. The ASN is attached as context rather than used as a filter, because the interesting cases include the ones from networks the catalog has never seen.
let watch =
_GetWatchlist('CloudASNRiskWatchlist')
| where Enabled == "Yes"
| project ASNumber = toint(ASNumber), Tier, ProviderFamily;
SigninLogs
| where TimeGenerated > ago(7d)
| where ResultType == 0
| where AuthenticationProtocol =~ "deviceCode"
or OriginalTransferMethod =~ "deviceCodeFlow"
// leftouter: an unlisted ASN is still worth seeing here.
| join kind=leftouter watch on $left.AutonomousSystemNumber == $right.ASNumber
| project
TimeGenerated,
UserPrincipalName,
IPAddress,
AutonomousSystemNumber,
Tier = coalesce(Tier, "not in catalog"),
ProviderFamily,
AppDisplayName,
ResourceDisplayName,
UserAgent,
CorrelationId
| order by TimeGenerated desc- Needs
- SigninLogs. The Watchlist join is leftouter on purpose, so a device-code success from an unlisted network still appears.
- What it will wrongly catch
- Legitimate device-code use does exist: shared or kiosk devices, some CLI tooling, and PowerShell modules that fall back to it. Establish which applications in your tenant use it before treating a hit as an incident.
- Catalog pattern
- Device-code phishing or token replay
Watchlist sign-in followed by an authentication-method changeMicrosoft Sentinel
This is the sequence that turns a stolen session into persistence, and it is the highest-value query here. An attacker who registers their own passkey, phone or device keeps access after the password is reset, so the enrollment matters more than the sign-in that preceded it. Non-interactive sign-ins are included because token replay often is.
let window = 15m;
let watch =
_GetWatchlist('CloudASNRiskWatchlist')
| where Enabled == "Yes" and Tier in ("T1 Critical", "T2 High")
| project ASNumber = toint(ASNumber), Tier, ProviderFamily;
let risky =
union SigninLogs, AADNonInteractiveUserSignInLogs
| where TimeGenerated > ago(7d)
| where ResultType == 0
| join kind=inner watch on $left.AutonomousSystemNumber == $right.ASNumber
| project
SignInTime = TimeGenerated,
UserPrincipalName,
IPAddress,
AutonomousSystemNumber,
Tier,
ProviderFamily;
let enrolment =
AuditLogs
| where TimeGenerated > ago(7d)
// Verify these against your tenant. Entra has renamed them before.
| where OperationName has_any (
"User registered security info",
"User registered all required security info",
"Admin registered security info",
"User changed default security info",
"Add strong authentication method",
"Add registered device",
"Register device")
| extend Actor = tostring(InitiatedBy.user.userPrincipalName)
| where isnotempty(Actor)
| project
EnrolTime = TimeGenerated,
UserPrincipalName = Actor,
OperationName,
AuditResult = tostring(Result);
risky
| join kind=inner enrolment on UserPrincipalName
| where EnrolTime between (SignInTime .. (SignInTime + window))
| project
SignInTime,
EnrolTime,
Gap = EnrolTime - SignInTime,
UserPrincipalName,
IPAddress,
AutonomousSystemNumber,
Tier,
ProviderFamily,
OperationName,
AuditResult
| order by SignInTime desc- Needs
- SigninLogs, AADNonInteractiveUserSignInLogs and AuditLogs. Check the OperationName list against your own tenant: Entra has renamed these operations before and a stale string silently matches nothing.
- What it will wrongly catch
- A user who travels, connects through a VPN, and then legitimately enrols a new phone. The fifteen-minute window is tight enough that this is uncommon, and the response is a phone call rather than a lockout.
- Catalog pattern
- Suspicious login followed by authenticator enrollment
One identity succeeding from several networks in the same windowMicrosoft Sentinel
A token used from two unrelated networks inside half an hour is hard to explain innocently, and it does not need the catalog at all. The watchlist is joined afterwards only to say whether any of the networks involved was already known.
let window = 30m;
union SigninLogs, AADNonInteractiveUserSignInLogs
| where TimeGenerated > ago(1d)
| where ResultType == 0
| where isnotempty(UserPrincipalName) and AutonomousSystemNumber > 0
// bin() is a fixed bucket, not a sliding window: a sequence that straddles a
// boundary is split in two and will not be caught here.
| summarize
Asns = make_set(AutonomousSystemNumber, 100),
Ips = make_set(IPAddress, 100),
Agents = make_set(UserAgent, 50),
Events = count()
by UserPrincipalName, Window = bin(TimeGenerated, window)
| where array_length(Asns) > 1
| extend AsnCount = array_length(Asns), IpCount = array_length(Ips)
| order by AsnCount desc, Events desc- Needs
- SigninLogs and AADNonInteractiveUserSignInLogs.
- What it will wrongly catch
- bin() cuts fixed thirty-minute buckets, so a genuine sequence straddling a boundary is split and missed, and a user roaming between a corporate network and a phone will sometimes land in two ASNs legitimately. Treat the ASN count as a sorting key rather than a verdict.
- Catalog pattern
- Cross-ASN same-user session sequence
The same first query in Defender XDR advanced huntingMicrosoft Defender XDR
Advanced hunting has no watchlist feature, so the list has to travel inside the query as a set literal. That is what utilities/asn-sets.kql in the download is for: paste the AsnT1T2 block in place of the short sample below.
// Replace this sample with the full AsnT1T2 block from
// utilities/asn-sets.kql in the download bundle. Three entries shown so the
// query is runnable as pasted.
let AsnT1T2 = dynamic([62240, 136787, 206728]);
AADSignInEventsBeta
| where Timestamp > ago(7d)
| where ErrorCode == 0
| where set_has_element(AsnT1T2, AutonomousSystemNumber)
| project
Timestamp,
AccountUpn,
IPAddress,
AutonomousSystemNumber,
Country,
Application,
ClientAppUsed,
UserAgent,
DeviceName,
IsManaged,
IsCompliant
| order by Timestamp desc- Needs
- AADSignInEventsBeta, which needs Microsoft Defender for Identity or Entra ID P2 data in the workspace.
- What it will wrongly catch
- The same as the Sentinel version, with one addition: a set literal pasted into a rule goes stale the moment the catalog is updated, so either refresh it on the same cadence or keep the authoritative copy in Sentinel.
- Catalog pattern
- Successful interactive sign-in from T1/T2 network
Scripting user agent reading files in bulkMicrosoft Defender XDR
What happens after the sign-in is usually more decisive than the sign-in. A scripted client reading a hundred files in two hours is the collection stage, and it is visible without any reference to the ASN at all. Run it alongside the sign-in queries rather than instead of them.
let agents = dynamic(["python-requests", "python-httpx", "aiohttp", "curl",
"Go-http-client", "PowerShell", "WinHttp"]);
CloudAppEvents
| where Timestamp > ago(7d)
| where ActionType == "FileAccessed"
| extend Ua = tostring(RawEventData.UserAgent)
| where isnotempty(Ua) and Ua has_any (agents)
| summarize
Files = dcount(tostring(RawEventData.ObjectId)),
Events = count(),
Ips = make_set(IPAddress, 20)
by AccountDisplayName, Ua, Window = bin(Timestamp, 2h)
| where Files >= 100
| order by Files desc- Needs
- CloudAppEvents, which carries SharePoint and OneDrive file activity in Defender XDR. The Sentinel equivalent is OfficeActivity with different column names.
- What it will wrongly catch
- Backup agents, migration tooling, eDiscovery exports and any sanctioned integration that uses a generic HTTP client. Inventory those first, because they will each trip this and they will each look identical to collection.
- Catalog pattern
- Scripting user agent with broad file access
Any source-IP log against the catalogSplunk
The catalog is a list of networks, so it applies to anything that records a source address. This is the generic shape: enrich whatever index already holds your authentication, VPN, firewall or SaaS audit events with the tier, then filter. Nothing about it is identity-specific, and the same join works against a proxy log or a mail gateway.
``` Generic shape. Replace the index and the field names with your own. ```
``` src_asn has to come from the event or from a lookup. Splunk's iplocation
command does NOT provide an ASN, only geo fields, so if your source does
not carry the number already, uncomment the GeoLite2-ASN line below. ```
index=auth action=success
``` | lookup geolite2_asn ip AS src_ip OUTPUT autonomous_system_number AS src_asn ```
| lookup asn_watchlist ASNumber AS src_asn
OUTPUT Tier, ProviderFamily, Category, FPRisk, Enabled
| where Enabled="Yes" AND Tier IN ("T1 Critical", "T2 High")
| stats count,
values(Tier) AS tier,
values(ProviderFamily) AS provider,
values(FPRisk) AS fp_risk,
dc(src_ip) AS distinct_ips
BY user, src_asn
| sort - count- Needs
- Two lookups. The catalog itself, defined from utilities/sentinel-watchlist.csv and keyed on ASNumber. And a source of the ASN for each address, because Splunk resolves none on its own: the built-in iplocation command adds City, Country, Region and coordinates and nothing else. Many log sources already carry the number (Okta, Cloudflare and AWS VPC flow logs among them); where yours does not, a GeoLite2-ASN lookup supplies it.
- What it will wrongly catch
- Exactly the same population as everywhere else: corporate VPN egress, vendor jump boxes, mobile carrier NAT and anyone on a personal VPN. Build the allowlist before you build the alert, because an unallowlisted version of this will fire on your own infrastructure first.
- Catalog pattern
- Successful interactive sign-in from T1/T2 network
Okta sign-ins, which already carry the ASNOkta
Okta puts the autonomous system number directly on every System Log event as securityContext.asNumber, so no enrichment step is needed to use this catalog there. That makes it the cheapest place to test whether the list says anything useful about your traffic before you build anything.
eventType eq "user.session.start" and outcome.result eq "SUCCESS" and (securityContext.asNumber eq 62240 or securityContext.asNumber eq 136787 or securityContext.asNumber eq 206728)- Needs
- System Log access. The expression is for a targeted check in the Admin Console or the events API, and it is deliberately bare: Okta's filter syntax has no comment form, so anything explanatory pasted with it is rejected. The three numbers are Clouvider, PacketHub and Media Land. For the whole enabled set, ship the System Log to a SIEM and use the lookup approach instead, because several hundred ASNs in a filter expression is not something you will keep up to date.
- What it will wrongly catch
- The same anonymizer and hosting population as any other surface. Okta also records the ASN of the client as the edge saw it, so a corporate egress through a cloud provider appears exactly as a hosted address would.
- Catalog pattern
- Successful interactive sign-in from T1/T2 network
Loading the list into the platform you already run
In Microsoft Sentinel, import the Sentinel Watchlist CSV from the download bundle and key it on the ASNumber column. That file exists because the obvious mistake is to ship only the AS-prefixed form, which then fails to join against the integer autonomous system number in the sign-in tables and matches nothing. Keeping the list in a watchlist, instead of inline in each analytics rule, means a weekly refresh costs one import and not an edit to every rule.
Defender XDR advanced hunting has no watchlist feature, so the set has to travel inside the query. The bundle includes paste-ready set literals for that, one for the alerting tiers and one for everything enabled. The cost of this approach is that a literal pasted into a custom detection goes stale the moment the catalog updates, so either refresh it on the same cadence or keep the authoritative copy in Sentinel and treat the XDR rules as hunting.
I have used this catalog in Microsoft Defender for Cloud, where what it mostly buys you is enrichment. A flagged connection reads differently once you know the network on the other end has documented identity-attack history, and that changes how quickly somebody picks it up. The alerting value there is secondary to having the context attached when a human finally looks.
Outside the Microsoft estate the mechanics change and the judgement does not. Splunk and most SIEMs want the Sentinel Watchlist CSV as an ordinary lookup table keyed on the ASN number, which is why that file ships with a bare numeric column alongside the AS-prefixed one. Okta needs no enrichment at all, since every System Log event already carries the autonomous system number. Firewalls and edge devices generally want the plain text file, though feeding an enforcement device directly from any of this is the one use I would argue against without a dependency review first.
For Entra ID Conditional Access, the honest guidance is to be conservative. Named locations and risk policies built from this list can work, and the tier structure matters more here than anywhere else: the alerting tiers are defensible inputs to a step-up requirement, and the review tier should never drive a policy because it contains broad cloud and consumer access networks. Validate against your own sign-in history before enforcing anything, and keep allowlists for your workloads, vendors, SASE egress, VPN concentrators and admin jump hosts. A Conditional Access policy that locks out an administrator is a worse outcome than the sign-in it was meant to stop.
Community feeds, and why four lists are not four witnesses
Public indicator feeds are used here for exact-address enrichment and short-lived hunting. They do not drive tiering, and the overlap figures explain why. Tens of thousands of addresses appear on more than one of these lists, and the reason is shared source lineage between the lists themselves. Those are not separate parties confirming each other. Cross-list presence is frequently one observation reported several times.
One feed in this set is recorded as rejected rather than used, because its contents were byte-identical for over a month across more than a hundred consecutive failed updates. A stale list that looks live is worse than no list, and publishing that rejection is more useful than quietly omitting the feed.
IPsum
- Coverage
- IPv4 with source-count score; score >=3: 17604; score >=5: 4242
- Snapshot
- 2026-09-29
- Unique indicators
- 121,838
- Current state
- Tue, 29 Sep 2026 03:00:38 +0200
- Use it for
- Exact-IP enrichment and short-TTL hunting; preserve score and snapshot date.
- Where it falls short
- Inputs are not independent. 47,278 IPs overlap Data-Shield, including 14,466 IPsum score >=3 addresses.
mzyui HTTP proxy list
- Coverage
- IPv4:port endpoints; 53395 unique IPv4
- Snapshot
- 2026-08-29
- Unique indicators
- 63,797
- Current state
- Rejected: stale and unvalidated
- Use it for
- Discovery only; reject for enforcement until updater health and independent endpoint validation recover.
- Where it falls short
- Byte-identical for 31.8 days with 143 consecutive updater failures.
Data-Shield IPv4 Blocklist
- Coverage
- IPv4; overlap with IPsum: 47278
- Snapshot
- 2026-09-29
- Unique indicators
- 92,896
- Current state
- 2026-09-29 20:05:41
- Use it for
- Exact-IP corroboration with source/date retention.
- Where it falls short
- Large overlap with IPsum prevents treating cross-list presence as independent evidence.
Cisco Talos April 2024 brute-force IOCs
- Coverage
- IPv4 plus credential observations
- Snapshot
- 2024-04-16
- Unique indicators
- 3,926
- Current state
- Historical snapshot
- Use it for
- Historical hunting and campaign-time ASN context for VPN, web-authentication, and SSH brute force.
- Where it falls short
- Keep campaign-time attribution separate from current routing. Source IPs can be reassigned; no ASN-wide provider implication.
Ransomware.live IoCs
- Coverage
- Heterogeneous group IOCs
- Snapshot
- 2026-09-29
- Unique indicators
- 2,564
- Current state
- Dynamic page checked 2026-09-29
- Use it for
- Discovery and corroboration; retain group, type, date, and original provenance where available.
- Where it falls short
- Network rows mix bare IP, IP:port, and CIDR and lack reliable per-row observation dates/original references. Revalidate exact indicators; never promote an ASN from presence alone.
Current community-feed union
- Coverage
- IPv4; all-three overlap: 60
- Snapshot
- 2026-09-29
- Unique indicators
- 218,847
- Current state
- Mixed; see individual rows
- Use it for
- Prioritize exact indicators aligned with fresh tenant telemetry and observed TTPs.
- Where it falls short
- Cross-list overlap is not independent corroboration. Feed volume alone does not support ASN-level malicious attribution.
- Exact-IP use
- Enrich listed IPs to the event-time ASN and retain the feed snapshot date. Do not turn a transient IP hit into permanent ASN-wide reputation.
- Overlap
- IPsum and Data-Shield share substantial source lineage. A hit in both is not automatically independent corroboration.
- Freshness
- Proxy lists require age and validation checks. A stale updater or untested endpoint should not drive blocking.
- Cloud volume
- Large cloud ASNs can dominate raw counts while serving legitimate customers. Treat count as exposure context, not maliciousness.
What changed in this refresh
The page states both the evidence snapshot date and the build date, and they are different on purpose. A rebuild is not new evidence, and presenting the two as one number is how a stale catalog looks current.
Refresh of .
- Refresh record 2026-10-09
- Catalog 1,148 to 1,151. Routing re-verified for all 1,148 prior catalog ASNs against RIPEstat; every difference was confirmed on a second pass. AS209425 is originating again. AS262909 and AS402170 stopped originating and are held for lifecycle review, not removed. AS212238, AS13335, AS16509 and AS20940 timed out or did not answer on one or both passes and are recorded as unresolved, not changed (AS9009 and AS20940 answered on retry with no change). RIR delegation files for all five registries show AS401109, AS401110, AS401116, AS401120 and AS262909 as reserved with no RDAP object; they stay in the catalog at T4 for lifecycle review because the status is new this week. No new published reporting changed any tier since 2026-10-07. Abuse percentages, IPsum and community feed counts were not re-pulled, and RIPEstat, Spamhaus and RDAP answered while some news sites refused automated requests.
- ASN-DROP delta 2026-10-09
- Spamhaus changed from 427 to 431 ASNs. Added: AS14956 (ROUTERHOSTING, already catalogued, moved T2 to T1), AS198636 (CAPSULA-AS), AS199457 (SolidCore), AS199804 (TFES-AS), the last three newly catalogued as T1 Critical. Removed: none. Delisting is not exoneration.
- Evidence expansion 2026-10-09, campaign ladder applied
- Campaign watch is now a ladder: one campaign holds T3 for 180 days, two or more separate campaigns within 12 months hold T2 for 180 days and then T3 for 180 more, then T4 for history. Applied to every row whose only basis is campaign reporting. 21 rows step down to T4: 17 whose newest Akira, Fog or Proofpoint campaign is more than 180 days old and 4 whose cited reporting is exploitation or C2 rather than sign-in abuse. 8 rows are on the ladder at T3: tzulo, Hydra, FranTech and Hivelocity from T2, the three HZ Hosting ASNs on the family's three campaigns, and Global Connectivity Solutions from T4. Datacamp stays T2 as commercial VPN egress. No row was removed.
Earlier refreshes are in the methodology and changelog download.
Methodology and limitations
The catalog is assembled from current machine-readable feeds, published vendor and government reporting, registry and routing data, and incident evidence, with every tiering decision resolving to a numbered source record. The full methodology ships in the bundle. The limitations deserve stating here rather than only in a download, because they are the conditions under which this data will be wrong.
Bring-your-own-IP addressing, suballocation, address reassignment, residential and mobile proxy egress, anycast addressing, compromised legitimate hosts and provider size can each break the link between a network and the activity attributed to it. Routing data shows which network announces a prefix, which is not always the party controlling the addresses inside it. Feed membership changes for reasons that have nothing to do with a network’s behaviour. None of this makes the data unusable, and all of it means the data is an input to a judgement and never a substitute for one.
On provider complicity, the position is the same throughout and it is not a disclaimer added at the end. Several networks here belong to legitimate hosting, transit and commercial VPN businesses. They are listed because reporting or incident evidence placed activity on their infrastructure. Where the research has a view on a provider’s role it is recorded in the provider role field, and for most rows that view is that infrastructure use was observed and no complicity claim is made. A tier is a monitoring priority and reading it as an allegation misreads the file.
The catalog is free to use with attribution under CC BY 4.0. Corrections are welcome and useful, particularly from providers who can show that a row is out of date.
- S01 Spamhaus ASN-DROPMembership and allocations can change. Neither list membership nor removal establishes every address/customer intent or login-source attribution. Update regularly before enforcement.
- S02 CISA, NSA, FBI and international partners Bulletproof Defense: Mitigating Risks From Bulletproof Hosting ProvidersWarns that whole-ASN blocking can affect legitimate users and that BPH providers cycle infrastructure.
- S03 ipapi.is Most Abusive ASNsVendor methodology and labels are prioritization signals, not malicious-login probability. Absence from the top 1,000 is not zero abuse; tied 100% ranks make rank-only movement weak evidence.
- S04 Proofpoint Cloud Credential Compromise from Russian InfrastructureProofpoint published IPs, provider labels and domains, not ASNs or CIDRs. ASN mapping is historical analyst enrichment and does not imply provider complicity.
- S05 RIPE NCC RIPEstat AS OverviewRegistry identity and routing status can change; country is not actor nationality.
- S06 RIPE NCC RIPEstat Routing HistoryBGP origin establishes routing at a point in time, not ownership, intent or provider complicity.
- S07 Microsoft ACTINIUM targets Ukrainian organizationsActor infrastructure and C2 evidence, not Microsoft 365 login-source evidence. Microsoft describes REG.RU as legitimate.
- S08 Palo Alto Networks Unit 42 Gamaredon (Primitive Bear) Russian APT Group Actively Targeting UkraineMostly malware C2/downloader telemetry, not authentication-source evidence. Large shared providers create ASN-wide false positives.
- S09 U.S. Department of the Treasury Treasury Sanctions Global Bulletproof Hosting Service Enabling Cybercriminals and Technology TheftThe press release names the entity but not ASNs; ASN linkage comes from technical research and current registry data.
- S10 U.S. Department of the Treasury United States, Australia, and the United Kingdom Jointly Sanction Key Infrastructure that Enables Ransomware AttacksThe release names the entity, not a complete current ASN inventory.
- S11 U.S. Department of Justice Three Russian Nationals and Two Companies Indicted for International Cybercrimes Resulting in More Than $62M in Victim LossesCriminal charges are allegations until proven. The release is not a complete ASN or prefix feed.
- S12 Recorded Future Insikt Group One Step Ahead: Stark Industries Solutions Preempts EU SanctionsInfrastructure was already shifting; revalidate current routing and ownership before enforcement.
- S13 GreyNoise The Stark Industries Shell GameObserved scanning does not make every customer or sign-in malicious.
- S14 Silent Push IOFA Detects Aeza Group Infrastructure Shift Following OFAC SanctionsUse the source date and routing snapshot; provider infrastructure can move.
- S15 Intel 471 Zservers: Bulletproof Hosting for CrimeHistorical technical snapshot. AS197414 is currently unannounced in this workbook enrichment.
- S16 Team Cymru Exploring Seychelles: Team Cymru’s Tech AdventureHistorical family mapping; current routing and current feed membership are shown separately.
- S18 Microsoft Midnight Blizzard: Guidance for responders on nation-state attackPublishes no ASN list.
- S19 Google Cloud Mandiant APT29 Continues Targeting Microsoft 365Publishes no ASN list; behavior supports combining network and identity signals.
- S20 Team Cymru Operationalizing OFAC Sanctions for Financial Defense: MediaLand AS206728Treat current routes and exact resources as time-sensitive.
- X001 Rapid7 Ongoing Social Engineering Campaign Refreshes PayloadsReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X002 Silent Push USPS Phishing on a Bulletproof Hosting NetworkReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X003 Recorded Future Malicious Infrastructure Finds Stability with aurologic GmbHReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X004 Excedo How cybercriminals abuse ASN for bulletproof hostingReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X005 bgp.tools bgp.tools AS215208 current registrationReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X006 bgp.tools bgp.tools AS215240 current registrationReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X007 Team Cymru How Virtual Offices Enable a Facade of LegitimacyReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X008 Huntress No (Bad) CAP: Inside an Ongoing LSHIY Password Spray AttackReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X009 bgp.tools bgp.tools AS207569Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X010 urlhaus.abuse.ch URLhaus malware URL databaseReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X011 global.ptsecurity.com Lazarus Group Recruitment: Threat Hunters vs Head HuntersReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X012 urlhaus.abuse.ch URLhaus ASN report for AS26496Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X013 bgp.he.net Hurricane Electric BGP Toolkit AS214943Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X014 rdap.arin.net ARIN RDAP lookup (no current object)Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X015 bgp.tools bgp.tools AS11938Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X016 halcyon.ai Update: Cloudzy Command and Control Provider ReportReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X017 cloudzy.com Cloudzy Official Statement, August 2023Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X018 jumpsec.com Inside a DPRK BlueNoroff ClickFix KitReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X019 bgp.tools bgp.tools AS22295Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X020 threatfox.abuse.ch ThreatFox ASN report for AS22295Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X021 rdap.arin.net ARIN RDAP lookup (no current object)Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X022 bgp.tools bgp.tools AS26701Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X023 rdap.arin.net ARIN RDAP lookup (no current object)Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X024 rdap.arin.net ARIN RDAP lookup (no current object)Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X025 rdap.arin.net ARIN RDAP lookup (no current object)Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X026 bgp.tools bgp.tools AS42624 successor contextReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X027 bgp.tools bgp.tools AS35346Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X028 bgp.tools bgp.tools AS35718Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X029 bgplookingglass.com List of Autonomous System Numbers - 2 (historical identity reference)Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X030 ipinfo.io IPinfo AS41947 historical ASN summaryReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X031 Recorded Future Malicious Infrastructure Finds Stability with aurologic GmbHReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X032 bgp.he.net Hurricane Electric BGP Toolkit: AS42624Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X033 ipinfo.io IPinfo AS43094 ASN summaryReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X034 x.com Spamhaus researcher report on suspicious AS44317/AS21738 announcementsReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X035 peeringdb.com PeeringDB historical entry: AS44317 Mercury Telecom LLCReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X036 krebsonsecurity.com Stark Industries Solutions: An Iron Hammer in the CloudReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X037 augursecurity.com European Union Sanctions Force Stark Industries Solutions Ltd. to Rebrand AgainReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X038 bgp.he.net Hurricane Electric BGP Toolkit: AS44477Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X039 bgp.tools BGP.Tools: AS44589Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X040 ipinfo.io IPinfo AS44774 historical ASN summaryReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X041 Silent Push Infrastructure Laundering: Silent Push Exposes Cloudy Behavior Around FUNNULL CDN Renting IPs from Big TechReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X042 greynoise.io Ghost Fleet: Half of All New Scanning IPs Last Week Geolocated to Hong KongReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X043 peeringdb.com PeeringDB: AS45753Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X044 ipinfo.io IPinfo AS47500 ASN summaryReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X045 Team Cymru Team Cymru: Jingle Shells - How Virtual Offices Enable a Facade of LegitimacyReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X046 threatfox.abuse.ch ThreatFox AS49042 tagReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X047 urlhaus.abuse.ch URLhaus ASN report for AS49042Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X048 bgp.tools BGP.Tools historical profile for AS49042Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X049 threatfox.abuse.ch ThreatFox AS49217 tagReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X050 bgp.tools BGP.Tools historical profile for AS49217Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X051 alfa-inet.net Alfa-inet ISP websiteReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X052 rasvtv.md RASV-TV official websiteReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X053 pfcloud.io Pfcloud official service catalogReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X054 urlhaus.abuse.ch URLhaus ASN report for AS51396Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X055 rootlayer.net RootLayer network and hosting pageReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X056 ip2location.com IP2Location current AS51490 statusReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X057 Recorded Future Recorded Future 2022 Adversary Infrastructure ReportReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X058 bgp.tools BGP.Tools profile for AS57678Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X059 innetra.com INNETRA official service catalogReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X060 peeringdb.com PeeringDB AS58349 profileReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X061 xserver.cloud XServer official VPS and dedicated-server siteReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X062 bgp.tools BGP.Tools AS48031 profileReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X063 docs.hetzner.com Hetzner official documentationReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X064 peeringdb.com PeeringDB AS213230 profileReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X065 learn.microsoft.com Microsoft Learn: Internet peering and AS8075Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X066 azure.microsoft.com Microsoft Azure official siteReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X067 serveroffer.lt Serveroffer official hosting pageReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X068 m247.com M247 official service catalogReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X069 urlhaus.abuse.ch URLhaus ASN report for AS9009Review the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X070 Recorded Future GrayBravo's CastleLoader Activity Clusters Target Multiple IndustriesReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X071 infosec.exchange Spamhaus: 49.3 Networking bulletproof-host investigationReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X072 infosec.exchange Spamhaus: Bearhost's bulletproof-hosting comebackReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X073 infosec.exchange Spamhaus: Netiface bulletproof-hosting infrastructureReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X074 infosec.exchange Spamhaus: AS219067 phishing and prefix-hopping infrastructureReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X075 infosec.exchange Spamhaus: Virtualine bulletproof hostingReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- X076 infosec.exchange Spamhaus: infrastructure facilitating bulletproof-host proliferationReview the source scope and date. Inclusion does not imply every customer or the provider is malicious.
- N01 RIPE NCC RIPEstat AS Overview, RIR registration, and routing statusRIR country is holder-registration metadata, not user or IP geolocation. A non-originating result can be transit-only, dormant, or below the RIPE visibility threshold; opaque RIR IDs are not stable ownership identifiers.
- N02 stamparm IPsum threat-intelligence feedUnderlying lists are not statistically independent. Score and ASN concentration are context, not automatic provider-tier evidence.
- N03 mzyui HTTP proxy listArtifact remained byte-identical and about 31.8 days stale after 143 consecutive updater failures when checked 2026-09-29; two invalid endpoint rows are excluded.
- N04 duggytuxy Data-Shield IPv4 BlocklistLarge overlap with IPsum prevents treating cross-list presence as independent corroboration. Use exact-IP context and short review TTLs.
- N05 CAIDA RouteViews Prefix-to-AS datasetOrigin-AS mappings change over time and MOAS routes require separate handling.
- N06 Arctic Wolf July 2025 Uptick in Akira Ransomware Activity Targeting SonicWall SSL VPNThe listed hosting networks are not inherently malicious; Arctic Wolf recommends limiting any blocking to VPN authentication.
- N07 Arctic Wolf Fog and Akira Ransomware Operations Linked to SonicWall SSL VPNHistorical exact-IP evidence; routing and ownership must be revalidated.
- N08 Augur Security Iran 2026 Threat Posture AssessmentCampaign infrastructure does not imply provider complicity or actor nationality for every event.
- N09 Arctic Wolf Console Chaos: A Campaign Targeting Publicly Exposed Management Interfaces on Fortinet FortiGate FirewallsExact IPs are time-bounded; broad VPS and CDN networks require behavioral corroboration.
- N10 eSentire Tycoon 2FA Infrastructure UpdateInfrastructure use does not establish provider complicity.
- N11 Okta Human-operated phishing kit targets cryptocurrency firmsShared hosting and proxy infrastructure can have legitimate customers.
- N12 Huntress Exploitation of SonicWall VPNUse with vulnerability, authentication, and post-access telemetry.
- N13 The DFIR Report Navigating Through the FogIncident-specific infrastructure does not imply all provider space is malicious.
- N14 Recorded Future Exposing TAG-53 Credential-Harvesting Infrastructure for Russia-Aligned Espionage OperationsAttribution applies to campaign infrastructure, not provider ownership.
- N15 Coralogix / Snowbit Evil Token: AI-Enabled Device Code Phishing CampaignExact IP and campaign context are time-bounded.
- N16 Resecurity SharePoint Zero-Day Exploit CVE-2025-53770 Network Infrastructure MappingIP allocation and current origin can change; no provider complicity is asserted.
- N17 Google Threat Intelligence Group UNC6671 Targets Financial Services and Enterprise Cloud EnvironmentsMost source IPs were commercial VPN nodes and cycle quickly; residential ASNs should not be blocklisted.
- N18 Push Security We infiltrated a criminal phishing panel: here is what we foundShort-lived domains and operator-gated pages reduce static IOC durability.
- N19 Censys Hiding in Plain Sight: Tracking Bulletproof Hosting and Abused RDP InfrastructureCensys distinguishes legitimate VPS abuse from BPH and warns attribution can be uncertain.
- N20 Cisco Talos ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365Cloudflare-hosted indicators do not support adding or blocking the whole Cloudflare ASN.
- N21 Team Cymru Validating ShinyHunters Cyber Threat Actors InfrastructureCampaign infrastructure is narrower than provider-wide attribution.
- N22 Sophos Malicious Use of Virtual Machine InfrastructureShared VM infrastructure can create provider-level false positives.
- N23 Arctic Wolf Active Cloud Data Theft and Extortion Campaign Targeting Microsoft 365 and SaaS PlatformsDetection thresholds require tenant baselining.
- N24 Google Threat Intelligence Group Disrupting the Largest Residential Proxy NetworkResidential proxy use makes actor geography and ASN-wide treatment unreliable.
- N25 Google Threat Intelligence Group Google Continues Disruption of Residential Proxy NetworksResidential access ASNs must not be treated as malicious wholesale.
- N26 Google Threat Intelligence Group Expansion of ShinyHunters SaaS Data TheftTTP correlation is more durable than infrastructure-only matching.
- N27 Microsoft Security Passkey-Themed Social Engineering Leads to Identity and Cloud CompromiseDomain indicators rotate; monitor authentication and enrollment behavior.
- N28 FBI AVrecon Malware-Infected Routers Exploited as Residential Proxies by SocksEscortThe subscriber ASN and country can be innocent infrastructure.
- N29 PacketHub PacketHub official service siteProvider marketing does not independently establish threat activity.
- N30 Netify NordVPN network and infrastructure profileAssociation is not evidence of corporate ownership or malicious operation.
- N31 Qurium Weaponizing Proxy and VPN ProvidersNetwork relationships can change and do not imply all users are malicious.
- N32 Microsoft Security AI-Enabled Device Code Phishing CampaignFocus on OAuth device-code and token behavior, not infrastructure alone.
- N33 Ransomware.live Ransomware.live IoCsThe IP counter mixes bare IPv4, IPv4:port, and CIDR rows; public rows lack reliable observation dates and original source references. Revalidate exact indicators and do not promote an ASN from presence alone.
- N34 Elastic Security Labs Detecting Tycoon 2FA AiTM Attacks Across Entra ID and Google WorkspaceCloud IP geolocation is unreliable for infrastructure classification; ASN is context, not verdict.
- N35 Cisco Talos Large-Scale Brute-Force Activity Targeting VPNs and SSH ServicesSource IPs change. Campaign-time RouteViews mapping must be kept separate from current IP-to-AS mapping.
- N36 StrongVPN StrongVPN official service siteOfficial provider information does not establish malicious activity or complicity.
- N37 Rapid7 Ongoing Malvertising Campaign Leads to RansomwareHistorical holder continuity to current KORGRID is unresolved.
- N38 Silent Push Silent Push Tracks a Mass Phishing Operation Through Fast FluxPublication explicitly warns not every ASN in the rotation is bulletproof. ASN set is an analytic seed, not a blanket deny list. DNSPod and Keitaro are legitimate shared services.
- N39 GreyNoise Open Season on Kapibala: Attacker Steals Over 18,000 Government Records Through WordPress ExploitationMain persistent exploitation IP remains redacted; do not infer or de-redact it. Red Heron relationship and Chinese-speaking attribution are assessed, not proven. Published addresses do not imply provider complicity.
- N40 GreyNoise Swarming Against Citrix 0-Day ExploitationAttempt against the Swarm sensor did not establish a foothold. IOC set is incomplete. Exact IP evidence is strong; same origin ASN alone is not proof of related attack activity.
- N41 Huntress Ready, Settra, Go: New Settra Ransomware Variant Deploys MeshAgent RMMInitial access unknown. MeshAgent is legitimate dual-use RMM; detection must correlate its server and behavior. Neither provider is labeled a bulletproof host by Huntress.
- N42 Spamhaus Botnet Threat Update January to June 2026Counts are not sign-in attack probabilities and are not normalized by provider size. Newly observed ranking does not measure response speed. Hyperscaler presence does not establish BPH status.
- N43 U.S. Department of the Treasury United States, Australia, and United Kingdom Sanction Russian Cybercrime Infrastructure Supporting RansomwareDesignated legal entity is not automatically every rented upstream ASN. Requires legal/entity verification and current designation checking before sanctions enforcement.
- N44 U.S. Department of the Treasury Treasury Sanctions Malware and Infrastructure Providers Supporting Ransomware Attacks Against Americans1VPNS rents infrastructure under false identities. Sanctioned VPN reseller does not make its unrelated underlying hosting companies sanctioned. No exact ASN is designated here.
- N45 FBI First VPN Service Used by Ransomware Actors to Compromise SystemsFBI expressly warns that ephemeral cloud IPs may be reassigned and require current corroboration. Similar-named VPN services are excluded. May-era exit list is historical in September.
- N46 Spamhaus Bulletproof Hosting: Cutting off the facilitatorsNo named ASN in article. Use to improve methodology and collateral-risk controls, not as evidence to add a specific ASN.
- N47 Cisco Talos Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI useNo exact public IP/ASN in extracted text. Russian-language attribution is suggestive. Wasabi and dual-use tools are not malicious providers; no ASN addition justified.
- N48 eSentire GhostCode: Dissecting a Novel Device Code Phishing KitSingle observed incident. Residential addresses may be dynamic. Microsoft broker/resource IDs and scripting user agents are legitimate; correlate behavior. Source timestamp example has a weekday/date inconsistency, so use month-level observation scope.
- N49 eSentire GhostCode published IOC listLookalike domains are marked possible relations; compromised-site indicators should remain subdomain scoped.
- N50 Microsoft Unmasking EvilTokens: Getting to the root of device code phishingNo exact malicious IPs or new Clouvider/PacketHub attribution. Cloud platforms named are shared infrastructure, not malicious domains. A linked actor-profile label says Storm-2922 while narrative says Storm-2992; retain narrative attribution with discrepancy.
- N51 Microsoft DCU Disrupting EvilTokens: The AI Chatbot Built for CybercrimeDisruption does not prove all affiliates stopped; no literal IOC list in announcement.
- N52 Microsoft Storm-3168: Agentic-driven cloud attacks using compromised service principalsInitial access unclear; exposed GitHub secret not confirmed used. No ransom note or successful exfiltration confirmed. Source gives no ASNs.
- N53 Microsoft DART Beyond source code: A path to the keys to the kingdomNo precise infrastructure IOC or ASN in blog. Do not infer vulnerability exploitation from valid-identity abuse.
- N54 Kaspersky GERT Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPOCredential theft method, lateral movement and IP roles not determined due logging gaps. No ASNs supplied; no live C2 confirmed. Windows impact occurred without encryption.
- N55 Microsoft Star Blizzard refines phishing and malware delivery with the RedFlick techniqueMostly historical delivery infrastructure, not cloud sign-in source evidence. No ASNs supplied.
- N56 Microsoft Beyond the ransomware: Tracking Storm-2570's consistent tradecraft across deploymentsInitial access unconfirmed; no exact network indicators or provider ASN evidence extracted.
- N57 Proofpoint Spraying in the Andes: TeamFiltration Returns to Exploit Forgotten Service AccountsAWS and DataCamp/CDN77 are shared infrastructure. Use the exact ranges, stale user agent, dormant-account pattern, failed-to-success sequence, and rapid ASN switch together; do not block the providers wholesale.
- N58 Huntress Railway PaaS abused in Microsoft 365 token replay campaignRailway is a legitimate PaaS. Use the ranges with device-code and token-replay behavior, not ASN-wide.
- N59 Microsoft AI-enabled device code phishing campaignRanges given as network addresses without length. Shared hosting; correlate with device-code flow.
- N60 GreyNoise Hidden pattern in credential-based attacks on Palo Alto and SonicWallGreyNoise notes these ASNs are not generally associated with malicious infrastructure.
- N61 Check Point Research Iran-nexus password spray campaign targeting cloud environments with a focus on the Middle EastCommercial VPN exits are shared by many legitimate users.
- N62 FBI and US Secret Service FortiBleed Operations Continue Targeting Exposed Systems Leading to Reports of Lockouts (JCSA-20261006-01)The agencies warn the addresses may be reassigned and should be treated as historical within the activity window. ASNs are RIPEstat mappings, not stated in the advisory.
- N63 Huntress Two INC ransom notesInitial access vector not determined. Endpoint C2, not sign-in source evidence.
- N64 Netify DataCamp hosting profileUndated profile, retrieved 2026-10-07. Shows hosted services, not abuse.
Who built this
I have spent about twenty years building and operating security systems, and I spent a long time before that learning how systems fail instead of how they are documented to work. That is roughly the skill this catalog needs, because the gap between what an autonomous system number is supposed to tell you and what it actually tells you is where all the false positives live. There is more about me on the about page.
This research exists because the generic version of it did not work in environments I was responsible for. The tiering, the review-only set, the separation of holder country from event geolocation and the insistence on recording what would make each row wrong are all consequences of watching the simpler approach fail. It is refreshed weekly, and the page is updated when the data changes, not when the date does.