AS112
Operated by AS112-PROJECT - DNS-OARC.
Summary
- // analyst note
- Seeing AS112 in traceroutes/firewall logs/IDS alerts is normal and benign — a private-address reverse-DNS query leaked and was correctly sinkholed by the nearest node. RFC 6305 exists to reassure operators it is not an attack. Never assign abuse/threat scoring.
- // security note
- NEUTRAL — benign critical infrastructure, explicitly NOT a security concern.
About this ASN.
AS112 is benign, special-use infrastructure — not a commercial operator. It is a distributed, community-operated anycast DNS sinkhole that answers reverse-DNS (PTR) and dynamic-update queries for private and non-globally-unique address space — RFC 1918 ranges (10/8, 172.16/12, 192.168/16), link-local 169.254/16, IPv6 ULA, and similar — that should be answered locally but instead leak onto the public Internet. By absorbing this "junk" traffic near its source, AS112 reduces load on the DNS root and IN-ADDR.ARPA authoritative servers. It is governed by RFC 7534 (nameserver operations) and RFC 7535 (DNAME redirection), with the address resources stewarded by DNS-OARC since 2009 and the anycast cloud run by a loosely coordinated, diverse set of independent volunteer operators worldwide, including RIPE NCC, Cloudflare, and many Internet exchanges. Each node is an independent BGP speaker that originates AS112 and announces the service prefixes 192.175.48.0/24 and 192.31.196.0/24 (IPv4) and 2620:4f:8000::/48 and 2001:4:112::/48 (IPv6) while running an authoritative DNS server. The crucial point for triage is that seeing AS112 in traceroutes, firewall logs, or IDS alerts is normal and expected, not a security event: it means a reverse-DNS query for a private address leaked out of a network and was correctly sinkholed by the nearest node. RFC 6305 ("I'm Being Attacked by PRISONER.IANA.ORG!") exists specifically to reassure operators that AS112 responses are not an attack, so this ASN should never be assigned abuse or threat scoring.
- Operator
- No single operator — address resources stewarded by DNS-OARC (ARIN OrgId OARCI, Indianapolis, IN) since 2009; anycast cloud run by many independent volunteer operators [Confirmed] — RFC 7534 §7.1, as112.net
- Country / RIR
- global anycast; resources registered via ARIN (US) [Confirmed]
- Allocated
- 2002-03-19 (ARIN ASN RegDate; ASName AS112-PROJECT; Updated 2024-03-12) [Confirmed] — ARIN RDAP
- Org status
- special-use; active; stewarded by DNS-OARC since 2009 [Confirmed]
Security/abuse context (NEUTRAL — benign infrastructure)
explicitly NOT a security concern. Inbound traffic from AS112 addresses is the expected result of private-address reverse-DNS leakage (see RFC 6305). The one residual privacy note (RFC 7534 security section) is that leaked queries may expose internal naming to whichever node answers — an argument for answering such queries locally, not evidence of malice — datatracker.ietf.org/doc/html/rfc7534, ftp.ripe.net/rfc/rfc6304.html
Network & routing
- Network type
- special-use / anycast DNS sink infrastructure [Confirmed]
- Size / prefixes
- 192.175.48.0/24, 192.31.196.0/24, 2620:4f:8000::/48, 2001:4:112::/48 [Confirmed]
- Routing/peering
- ~209 peers and ~16 upstreams from one vantage (varies widely because every node originates the same ASN/prefixes); RPKI partial/Unknown — multiple independent originators of the same prefixes is BY DESIGN, not a hijack — bgp.he.net, RFC 7534
- Notable usage
- community-operated anycast DNS sinkhole for reverse-DNS/dynamic-update queries for private/non-unique address space (RFC 1918, 169.254/16, IPv6 ULA); serves via Direct Delegation (prisoner.iana.org / blackhole-1 / blackhole-2) and, since RFC 7535, DNAME redirection (empty.as112.arpa → blackhole.as112.arpa) — as112.net
- Related ASNs
- single shared anycast ASN by design; no "sibling" commercial ASN [Confirmed]
- Prefix-in-service note
- service prefix 192.175.48.0/24 has been in the IANA IPv4 Special-Purpose registry since allocation 1996-01 — distinct from the ASN allocation date [Confirmed] — IANA
- Assignment class
- special-use — IANA "Special-Purpose AS Numbers" registry (RFC 7249): "Used by the AS112 project to sink misdirected DNS queries; see RFC 7534" [Confirmed]
- Analyst note
- Seeing AS112 in traceroutes/firewall logs/IDS alerts is normal and benign — a private-address reverse-DNS query leaked and was correctly sinkholed by the nearest node. RFC 6305 exists to reassure operators it is not an attack. Treat as expected infrastructure, never a threat indicator.
What this network routes.
- 192.31.196.0/24
- 192.175.48.0/24
- 2001:4:112::/48
- 2620:4f:8000::/48
Who it talks to.
| ASN | Operator | Role |
|---|---|---|
| AS13335 | CLOUDFLARENET - Cloudflare, Inc. | upstream |
| AS6939 | HURRICANE - Hurricane Electric LLC | upstream |
| AS36236 | NETACTUATE - NetActuate, Inc | upstream |
| AS29670 | IN-BERLIN-AS Individual Network Berlin ("IN-Berlin") e.V. | upstream |
| AS7195 | AS7195 - EDGEUNO S.A.S | upstream |
| AS1103 | SURFNET-NL SURF B.V. | upstream |
| AS8298 | IPNG IPng Networks GmbH | upstream |
| AS917 | MISAKA - Misaka Network, Inc. | upstream |
| AS34019 | HIVANE Hivane Association | upstream |
| AS58057 | SECUREBIT Securebit AG | upstream |
| AS215685 | Nexus Maik Sussdorf | upstream |
| AS30781 | JAGUAR-AS Free Pro SAS | upstream |
| AS49673 | TRUENETWORK Truenetwork LLC | upstream |
| AS9002 | RETN-AS RETN Limited | upstream |
| AS12637 | SEEWEB SEEWEB s.r.l. | upstream |
| AS15954 | Tecnocratica Tecnocratica Centro de Datos, S.L. | upstream |
| AS22548 | AS22548 - Nucleo de Inf. e Coord. do Ponto BR - NIC.BR | upstream |
| AS31287 | IPACCT-AS IPACCT CABLE Ltd | upstream |
| AS53046 | AS53046 - UNIVERSIDADE ESTADUAL DE PONTA GROSSA | upstream |
| AS56740 | DATAHATA-AS DataHata Ltd | upstream |