Skip to content

Low-Control General Hosting Network

It indicates that the ASN belongs to hosting environments statistically associated with higher abuse rates, weak onboarding controls, or historically malicious operations. These networks frequently appear in phishing, malware hosting, and botnet infrastructure.

Analyst Q&A

What this signal answers

Three questions every analyst asks before acting on this signal.

What it detects01

What does 'ASN Risky Network' mean?

It indicates that the ASN belongs to hosting environments statistically associated with higher abuse rates, weak onboarding controls, or historically malicious operations. These networks frequently appear in phishing, malware hosting, and botnet infrastructure.

Why it matters02

What do the subtypes of risky ASN networks represent?

They differentiate the severity of infrastructure abuse: low-control hosting environments often lack vetting and allow disposable malicious deployments; high-abuse entertainment networks show repeated historical misuse; bulletproof hosting providers intentionally ignore abuse reports and enable persistent malicious activity.

How analysts use it03

How should SOC analysts interpret the 'as_risky_network' label?

This label is a strong contextual risk amplifier. When a domain or IP resides on a risky ASN, analysts should prioritize investigation and correlate with additional indicators such as blacklist hits, DNS churn, hosting rotations, or newly activated infrastructure.

Often paired with:block_domain
Evidence shape

What Low-Control General Hosting Network looks like in the response

A realistic shape of the entry the engine appends to the risk_signals array when this signal fires. Evidence keys are subgroup-default; per-signal overrides documented in the API reference.

json
{
  "slug": "asn_risky_network",
  "name": "Low-Control General Hosting Network",
  "group": "dns_history",
  "subgroup": "asn_infrastructure_profile",
  "direction": "malicious",
  "evidence": {
    "asn": "AS13335",
    "asn_org": "Cloudflare, Inc.",
    "asn_allocation_year": 2010,
    "asn_geo_risk": "low",
    "hosted_domain_count": 18420315
  }
}
See in API reference
Siblings

Peers in ASN Infrastructure Profile

13 other signals share the same subgroup. They detect related behaviors and often co-fire on the same IOC.

Malicious Infrastructure Observed in ASN

It indicates that domains hosted under this ASN have been involved in malware distribution, payload hosting, or command-

MaliciousCore
ASN Allocated Long Time Ago

It means that the ASN was allocated many years ago and has a long operational history. Older ASNs tend to be more stable

Safe
Geolocation Mismatch or High-Risk Region

It indicates that the ASN shows geolocation anomalies, such as a mismatch between registry country and observed country

Malicious
High-Risk TLD Usage Observed in ASN

It indicates that one or more domains hosted under the ASN use top-level domains statistically associated with abuse, su

Malicious
Show 9 more in ASN Infrastructure Profile
In the wild

See Low-Control General Hosting Network fire on real IOCs

The Verdict Gallery is a curated stream of real verdicts. Filter by this signal to see exactly which IOCs it caught, what other signals fired alongside it, and what the engine recommended.

Open Verdict Gallery
Pre-filtered to Low-Control General Hosting Network. See real IOCs this signal caught and the verdicts the engine returned.
Verdicts ✓

Start free, in five minutes

100 IOCs/day on the free tier, LLM layer included. No card required.