IPASIS - IP Reputation and Risk Intelligence API

⚠️ High-Risk ASNs & Threat Sources

Explore Autonomous System Numbers (ASNs) frequently associated with abuse, VPN/proxy services, and malicious activity based on our threat intelligence feeds.

Note: Being listed as "high-risk" doesn't mean all IPs from these ASNs are malicious. These networks often host legitimate services alongside potentially abusive ones. Always verify individual IP reputation.

High-Risk Autonomous Systems

AS14061DigitalOcean
HIGH RISK

Common VPS provider used for abuse due to easy provisioning

AS16509Amazon.com (AWS)
MEDIUM RISK

Large cloud provider frequently used for hosting malicious infrastructure

Sample IPs from this ASN

AS20473Vultr Holdings
HIGH RISK

VPS provider with streamlined signup often abused by threat actors

AS63949Linode
MEDIUM RISK

Popular VPS provider for both legitimate and malicious use

AS24940Hetzner Online
MEDIUM RISK

European hosting provider often used for bulletproof hosting

Sample IPs from this ASN

AS16276OVH
MEDIUM RISK

Large European hosting provider with diverse abuse patterns

Sample IPs from this ASN

AS45102Alibaba Cloud
MEDIUM RISK

Chinese cloud provider with global presence

Sample IPs from this ASN

AS60068Datacamp Limited
HIGH RISK

Hosting provider associated with VPN and proxy services

AS9009M247 Ltd
HIGH RISK

Known for hosting VPN exit nodes and proxy services

Sample IPs from this ASN

AS62567DigitalOcean Amsterdam
HIGH RISK

Amsterdam datacenter commonly used for European abuse operations

Sample IPs from this ASN

AS60729Aeza Network
HIGH RISK

Russian hosting provider frequently associated with Tor nodes and proxy services

AS15169Google LLC
MEDIUM RISK

GCP infrastructure used for bot hosting, credential stuffing, and scraping

AS13335Cloudflare Inc
LOW RISK

CDN and proxy service — traffic origin is masked behind Cloudflare IPs

AS54113Fastly Inc
LOW RISK

CDN provider — IPs may mask origin of automated traffic

AS396982Google Cloud Platform
MEDIUM RISK

GCP compute instances frequently used for automated attacks and scraping

AS8075Microsoft Azure
MEDIUM RISK

Large cloud platform used for hosting malicious infrastructure at scale

Sample IPs from this ASN

AS36352ColoCrossing
HIGH RISK

Budget hosting provider popular with spammers and botnet operators

AS46562Performive LLC
HIGH RISK

Hosting provider associated with scan and abuse traffic

Sample IPs from this ASN

AS4134China Telecom
MEDIUM RISK

Major Chinese ISP — source of large-scale scanning and brute force activity

AS4837China Unicom
MEDIUM RISK

Chinese ISP frequently associated with automated scanning activity

Sample IPs from this ASN

AS4766Korea Telecom
LOW RISK

Korean ISP — occasional source of credential stuffing campaigns

Sample IPs from this ASN

AS13238Yandex LLC
MEDIUM RISK

Russian tech company — Yandex bot and cloud infrastructure

AS47583Hostinger International
HIGH RISK

Budget hosting provider with high abuse rates due to easy signup

Sample IPs from this ASN

AS51167Contabo GmbH
HIGH RISK

Affordable VPS provider frequently used for proxy and bot infrastructure

AS19871Network Solutions LLC
MEDIUM RISK

Hosting provider with mixed legitimate and malicious traffic

Sample IPs from this ASN

AS49981WorldStream B.V.
HIGH RISK

Dutch hosting provider associated with bulletproof hosting services

Sample IPs from this ASN

AS58061Kaopu Cloud
HIGH RISK

Chinese cloud provider with limited abuse controls

Sample IPs from this ASN

AS211680Private Layer Inc
HIGH RISK

Privacy-focused hosting provider popular with anonymity services

Sample IPs from this ASN

AS174Cogent Communications
LOW RISK

Major transit provider — source of diverse traffic including abuse

Sample IPs from this ASN

AS6939Hurricane Electric
MEDIUM RISK

Internet backbone and tunnel broker — used for IPv6 tunneled abuse

Sample IPs from this ASN

AS206264Amarutu Technology Ltd
HIGH RISK

Hosting provider associated with VPN exit nodes and proxy services

Sample IPs from this ASN

AS4785xTom GmbH
HIGH RISK

European hosting provider known for Tor relay hosting

AS213151TradeLayer One LLC
HIGH RISK

Hosting provider associated with proxy and VPN services

Sample IPs from this ASN

AS3356Level 3 / Lumen
LOW RISK

Major backbone provider — carries diverse traffic including botnet C2

Sample IPs from this ASN

AS209CenturyLink / Lumen
LOW RISK

US telecom — residential IPs occasionally used in credential stuffing

Sample IPs from this ASN

AS212238Datacamp Limited (Tor)
HIGH RISK

Known Tor exit node hosting ASN under Datacamp umbrella

AS208323AdGuard Software Ltd
LOW RISK

Ad-blocking DNS provider — signals non-standard DNS configuration

Sample IPs from this ASN

AS132203Tencent Cloud Computing
MEDIUM RISK

Major Chinese cloud provider — source of large-scale scraping and bot traffic

AS55990Huawei Cloud Service
MEDIUM RISK

Chinese cloud provider with growing global footprint — used for automated attacks

AS51396Pfcloud UG
HIGH RISK

German hosting provider known for Tor relay and VPN exit node hosting

AS42708Portlane AB
HIGH RISK

Swedish hosting provider frequently used for Tor relays and proxy services

Sample IPs from this ASN

AS44477Stark Industries Solutions
HIGH RISK

Hosting provider associated with bulletproof hosting and cybercrime infrastructure

AS396356The Tor Project
HIGH RISK

Dedicated ASN for Tor relay and exit node infrastructure

AS53667FranTech Solutions (BuyVM)
HIGH RISK

Privacy-focused VPS provider popular for Tor relays and anonymity services

AS12876Scaleway (Online S.A.S.)
MEDIUM RISK

French cloud provider with affordable instances frequently used for abuse infrastructure

AS21859Zenlayer Inc
MEDIUM RISK

Chinese CDN and hosting provider with global edge — used for automated scraping and bot traffic

Sample IPs from this ASN

AS199524G-Core Labs S.A.
MEDIUM RISK

Luxembourg-based global hosting and CDN — proxy and VPN exit node hosting

Sample IPs from this ASN

AS41436Kamatera Inc
HIGH RISK

Cloud VPS provider with easy provisioning — abused for credential stuffing and scraping

Sample IPs from this ASN

AS62240Clouvider Limited
HIGH RISK

UK hosting provider known for VPN exit node and proxy infrastructure hosting

Sample IPs from this ASN

AS57523Chang Way Technologies
HIGH RISK

Hosting provider associated with bulletproof hosting and phishing infrastructure

Sample IPs from this ASN

AS50245Serverius Holding B.V.
HIGH RISK

Dutch hosting provider with abuse-tolerant policies — proxy and botnet infrastructure

Sample IPs from this ASN

AS38365Baidu Inc
LOW RISK

Chinese search and cloud giant — operates public DNS (180.76.76.76) and cloud infrastructure

AS398101GoDaddy.com LLC
LOW RISK

Largest domain registrar and hosting provider — mixed legitimate and abuse traffic

Sample IPs from this ASN

Threat Categories

Our threat intelligence covers multiple categories of potentially risky IP addresses.

Understanding Risk Levels

HIGH

Networks with significant abuse history, often used for VPN/proxy services with minimal verification.

MEDIUM

Large cloud providers where abuse occurs but represents a small fraction of overall traffic.

LOW

Networks with occasional abuse reports but generally good reputation and responsive abuse handling.