Autonomous system detail

AS112

Announced

Operated by The AS112 Project.

Summary

// analyst note
Seeing AS112 in traceroutes/firewall logs/IDS alerts is normal and benign — a private-address reverse-DNS query leaked and was correctly sinkholed by the nearest node. RFC 6305 exists to reassure operators it is not an attack. Never assign abuse/threat scoring.
// security note
NEUTRAL — benign critical infrastructure, explicitly NOT a security concern.
IPv4 prefixes
2
~512 addresses
IPv6 prefixes
2
announced
Peer networks
14
7 up · 0 down
IANA block
1-1876
Assigned by ARIN
[ 01 ] — Context

About this ASN.

Updated  ·  Confidence: High  ·  6 sources  ·  How this page is checked

AS112 is benign, special-use infrastructure — not a commercial operator. It is a distributed, community-operated anycast DNS sinkhole that answers reverse-DNS (PTR) and dynamic-update queries for private and non-globally-unique address space — RFC 1918 ranges (10/8, 172.16/12, 192.168/16), link-local 169.254/16, IPv6 ULA, and similar — that should be answered locally but instead leak onto the public Internet. By absorbing this "junk" traffic near its source, AS112 reduces load on the DNS root and IN-ADDR.ARPA authoritative servers. It is governed by RFC 7534 (nameserver operations) and RFC 7535 (DNAME redirection), with the address resources stewarded by DNS-OARC since 2009 and the anycast cloud run by a loosely coordinated, diverse set of independent volunteer operators worldwide, including RIPE NCC, Cloudflare, and many Internet exchanges. Each node is an independent BGP speaker that originates AS112 and announces the service prefixes 192.175.48.0/24 and 192.31.196.0/24 (IPv4) and 2620:4f:8000::/48 and 2001:4:112::/48 (IPv6) while running an authoritative DNS server. The crucial point for triage is that seeing AS112 in traceroutes, firewall logs, or IDS alerts is normal and expected, not a security event: it means a reverse-DNS query for a private address leaked out of a network and was correctly sinkholed by the nearest node. RFC 6305 ("I'm Being Attacked by PRISONER.IANA.ORG!") exists specifically to reassure operators that AS112 responses are not an attack, so this ASN should never be assigned abuse or threat scoring.

Operator
No single operator — address resources stewarded by DNS-OARC (ARIN OrgId OARCI, Indianapolis, IN) since 2009; anycast cloud run by many independent volunteer operators [Confirmed] — RFC 7534 §7.1, as112.net
Country / RIR
global anycast; resources registered via ARIN (US) [Confirmed]
Allocated
2002-03-19 (ARIN ASN RegDate; ASName AS112-PROJECT; Updated 2024-03-12) [Confirmed] — ARIN RDAP
Org status
special-use; active; stewarded by DNS-OARC since 2009 [Confirmed]

Security/abuse context (NEUTRAL — benign infrastructure)

explicitly NOT a security concern. Inbound traffic from AS112 addresses is the expected result of private-address reverse-DNS leakage (see RFC 6305). The one residual privacy note (RFC 7534 security section) is that leaked queries may expose internal naming to whichever node answers — an argument for answering such queries locally, not evidence of malice — datatracker.ietf.org/doc/html/rfc7534, ftp.ripe.net/rfc/rfc6304.html

Network & routing

Network type
special-use / anycast DNS sink infrastructure [Confirmed]
Size / prefixes
192.175.48.0/24, 192.31.196.0/24, 2620:4f:8000::/48, 2001:4:112::/48 [Confirmed]
Routing/peering
~209 peers and ~16 upstreams from one vantage (varies widely because every node originates the same ASN/prefixes); RPKI partial/Unknown — multiple independent originators of the same prefixes is BY DESIGN, not a hijack — bgp.he.net, RFC 7534
Notable usage
community-operated anycast DNS sinkhole for reverse-DNS/dynamic-update queries for private/non-unique address space (RFC 1918, 169.254/16, IPv6 ULA); serves via Direct Delegation (prisoner.iana.org / blackhole-1 / blackhole-2) and, since RFC 7535, DNAME redirection (empty.as112.arpa → blackhole.as112.arpa) — as112.net
Related ASNs
single shared anycast ASN by design; no "sibling" commercial ASN [Confirmed]
Prefix-in-service note
service prefix 192.175.48.0/24 has been in the IANA IPv4 Special-Purpose registry since allocation 1996-01 — distinct from the ASN allocation date [Confirmed] — IANA
Assignment class
special-use — IANA "Special-Purpose AS Numbers" registry (RFC 7249): "Used by the AS112 project to sink misdirected DNS queries; see RFC 7534" [Confirmed]
Analyst note
Seeing AS112 in traceroutes/firewall logs/IDS alerts is normal and benign — a private-address reverse-DNS query leaked and was correctly sinkholed by the nearest node. RFC 6305 exists to reassure operators it is not an attack. Treat as expected infrastructure, never a threat indicator.
[ 02 ] — Announced prefixes

What this network routes.

4 prefixes total · as observed by RouteViews at 2026-09-20 · one collector view, not a global census
// IPv4 prefixes2
  1. 192.175.48.0/24/24
  2. 192.31.196.0/24/24
// IPv6 prefixes2
  1. 2001:4:112::/48/48
  2. 2620:4f:8000::/48/48
[ 03 ] — Notable peers & upstreams

Who it talks to.

14 observed neighbours
// Notable connections14 of 14 observed

Neighbours observed by RouteViews at 2026-09-20, lowest ASN first. Relationships are inferences from the CAIDA AS Relationships Dataset, 2026-08-01, and establish no commercial arrangement; a dash means the inference did not resolve.

ASNOperatorRole
AS1103 — upstream
AS3320 Deutsche Telekom AG upstream
AS6939 Hurricane Electric LLC upstream
AS7500 — upstream
AS13335 Cloudflare, Inc. upstream
AS31287 — upstream
AS36236 — upstream
AS3303 — peer
AS12552 — —
AS20912 — peer
AS47778 — —
AS53767 — peer
AS57866 — peer
AS61138 — —
Neighbours observed via public BGP collectors; not a complete peering list.