Skip to content

Geolocation Mismatch or High-Risk Region

It indicates that the ASN shows geolocation anomalies, such as a mismatch between registry country and observed country or continent, or that it is associated with a country known for elevated abuse or weak hosting controls.

Analyst Q&A

What this signal answers

Three questions every analyst asks before acting on this signal.

What it detects01

What does the 'Geolocation Mismatch or High-Risk Region' signal indicate?

It indicates that the ASN shows geolocation anomalies, such as a mismatch between registry country and observed country or continent, or that it is associated with a country known for elevated abuse or weak hosting controls.

Why it matters02

How are different geolocation risk factors represented?

Individual conditions such as registry-versus-observed country mismatch, continent mismatch and high-risk country flags are exposed as key–value fields in the evidence details instead of separate sublabels, so analysts can see exactly which geo anomalies are present.

How analysts use it03

How should SOC analysts interpret this ASN geolocation risk profile?

It is a contextual malicious indicator that strengthens suspicion when combined with other signals such as blacklist hits, domain churn or suspicious hosting patterns. On its own it does not prove compromise, but it increases the likelihood that the ASN participates in risky or evasive infrastructure.

Often paired with:alert_only
Evidence shape

What Geolocation Mismatch or High-Risk Region looks like in the response

A realistic shape of the entry the engine appends to the risk_signals array when this signal fires. Evidence keys are subgroup-default; per-signal overrides documented in the API reference.

json
{
  "slug": "asn_geo_risk_profile",
  "name": "Geolocation Mismatch or High-Risk Region",
  "group": "dns_history",
  "subgroup": "asn_infrastructure_profile",
  "direction": "malicious",
  "evidence": {
    "asn": "AS13335",
    "asn_org": "Cloudflare, Inc.",
    "asn_allocation_year": 2010,
    "asn_geo_risk": "low",
    "hosted_domain_count": 18420315
  }
}
See in API reference
Siblings

Peers in ASN Infrastructure Profile

13 other signals share the same subgroup. They detect related behaviors and often co-fire on the same IOC.

Low-Control General Hosting Network

It indicates that the ASN belongs to hosting environments statistically associated with higher abuse rates, weak onboard

MaliciousCore
Malicious Infrastructure Observed in ASN

It indicates that domains hosted under this ASN have been involved in malware distribution, payload hosting, or command-

MaliciousCore
ASN Allocated Long Time Ago

It means that the ASN was allocated many years ago and has a long operational history. Older ASNs tend to be more stable

Safe
High-Risk TLD Usage Observed in ASN

It indicates that one or more domains hosted under the ASN use top-level domains statistically associated with abuse, su

Malicious
Show 9 more in ASN Infrastructure Profile
In the wild

See Geolocation Mismatch or High-Risk Region fire on real IOCs

The Verdict Gallery is a curated stream of real verdicts. Filter by this signal to see exactly which IOCs it caught, what other signals fired alongside it, and what the engine recommended.

Open Verdict Gallery
Pre-filtered to Geolocation Mismatch or High-Risk Region. See real IOCs this signal caught and the verdicts the engine returned.
Verdicts ✓

Start free, in five minutes

100 IOCs/day on the free tier, LLM layer included. No card required.