Autonomous system detail

AS112

Announced

Operated by AS112-PROJECT - DNS-OARC.

Summary

// analyst note
Seeing AS112 in traceroutes/firewall logs/IDS alerts is normal and benign — a private-address reverse-DNS query leaked and was correctly sinkholed by the nearest node. RFC 6305 exists to reassure operators it is not an attack. Never assign abuse/threat scoring.
// security note
NEUTRAL — benign critical infrastructure, explicitly NOT a security concern.
IPv4 prefixes
2
~512 addresses
IPv6 prefixes
2
announced
Peer networks
167
54 up · 0 down
IANA block
1-1876
Assigned by ARIN
[ 01 ] — Context

About this ASN.

Updated  ·  Confidence: High

AS112 is benign, special-use infrastructure — not a commercial operator. It is a distributed, community-operated anycast DNS sinkhole that answers reverse-DNS (PTR) and dynamic-update queries for private and non-globally-unique address space — RFC 1918 ranges (10/8, 172.16/12, 192.168/16), link-local 169.254/16, IPv6 ULA, and similar — that should be answered locally but instead leak onto the public Internet. By absorbing this "junk" traffic near its source, AS112 reduces load on the DNS root and IN-ADDR.ARPA authoritative servers. It is governed by RFC 7534 (nameserver operations) and RFC 7535 (DNAME redirection), with the address resources stewarded by DNS-OARC since 2009 and the anycast cloud run by a loosely coordinated, diverse set of independent volunteer operators worldwide, including RIPE NCC, Cloudflare, and many Internet exchanges. Each node is an independent BGP speaker that originates AS112 and announces the service prefixes 192.175.48.0/24 and 192.31.196.0/24 (IPv4) and 2620:4f:8000::/48 and 2001:4:112::/48 (IPv6) while running an authoritative DNS server. The crucial point for triage is that seeing AS112 in traceroutes, firewall logs, or IDS alerts is normal and expected, not a security event: it means a reverse-DNS query for a private address leaked out of a network and was correctly sinkholed by the nearest node. RFC 6305 ("I'm Being Attacked by PRISONER.IANA.ORG!") exists specifically to reassure operators that AS112 responses are not an attack, so this ASN should never be assigned abuse or threat scoring.

Operator
No single operator — address resources stewarded by DNS-OARC (ARIN OrgId OARCI, Indianapolis, IN) since 2009; anycast cloud run by many independent volunteer operators [Confirmed] — RFC 7534 §7.1, as112.net
Country / RIR
global anycast; resources registered via ARIN (US) [Confirmed]
Allocated
2002-03-19 (ARIN ASN RegDate; ASName AS112-PROJECT; Updated 2024-03-12) [Confirmed] — ARIN RDAP
Org status
special-use; active; stewarded by DNS-OARC since 2009 [Confirmed]

Security/abuse context (NEUTRAL — benign infrastructure)

explicitly NOT a security concern. Inbound traffic from AS112 addresses is the expected result of private-address reverse-DNS leakage (see RFC 6305). The one residual privacy note (RFC 7534 security section) is that leaked queries may expose internal naming to whichever node answers — an argument for answering such queries locally, not evidence of malice — datatracker.ietf.org/doc/html/rfc7534, ftp.ripe.net/rfc/rfc6304.html

Network & routing

Network type
special-use / anycast DNS sink infrastructure [Confirmed]
Size / prefixes
192.175.48.0/24, 192.31.196.0/24, 2620:4f:8000::/48, 2001:4:112::/48 [Confirmed]
Routing/peering
~209 peers and ~16 upstreams from one vantage (varies widely because every node originates the same ASN/prefixes); RPKI partial/Unknown — multiple independent originators of the same prefixes is BY DESIGN, not a hijack — bgp.he.net, RFC 7534
Notable usage
community-operated anycast DNS sinkhole for reverse-DNS/dynamic-update queries for private/non-unique address space (RFC 1918, 169.254/16, IPv6 ULA); serves via Direct Delegation (prisoner.iana.org / blackhole-1 / blackhole-2) and, since RFC 7535, DNAME redirection (empty.as112.arpa → blackhole.as112.arpa) — as112.net
Related ASNs
single shared anycast ASN by design; no "sibling" commercial ASN [Confirmed]
Prefix-in-service note
service prefix 192.175.48.0/24 has been in the IANA IPv4 Special-Purpose registry since allocation 1996-01 — distinct from the ASN allocation date [Confirmed] — IANA
Assignment class
special-use — IANA "Special-Purpose AS Numbers" registry (RFC 7249): "Used by the AS112 project to sink misdirected DNS queries; see RFC 7534" [Confirmed]
Analyst note
Seeing AS112 in traceroutes/firewall logs/IDS alerts is normal and benign — a private-address reverse-DNS query leaked and was correctly sinkholed by the nearest node. RFC 6305 exists to reassure operators it is not an attack. Treat as expected infrastructure, never a threat indicator.
[ 02 ] — Announced prefixes

What this network routes.

4 prefixes total · RIPEstat data · cached, not real-time
// IPv4 prefixes2
  1. 192.31.196.0/24/24
  2. 192.175.48.0/24/24
// IPv6 prefixes2
  1. 2001:4:112::/48/48
  2. 2620:4f:8000::/48/48
[ 03 ] — Notable peers & upstreams

Who it talks to.

167 observed neighbours
// Notable connectionsTop 20 of 167
ASNOperatorRole
AS13335 CLOUDFLARENET - Cloudflare, Inc. upstream
AS6939 HURRICANE - Hurricane Electric LLC upstream
AS36236 NETACTUATE - NetActuate, Inc upstream
AS29670 IN-BERLIN-AS Individual Network Berlin ("IN-Berlin") e.V. upstream
AS7195 AS7195 - EDGEUNO S.A.S upstream
AS1103 SURFNET-NL SURF B.V. upstream
AS8298 IPNG IPng Networks GmbH upstream
AS917 MISAKA - Misaka Network, Inc. upstream
AS34019 HIVANE Hivane Association upstream
AS58057 SECUREBIT Securebit AG upstream
AS215685 Nexus Maik Sussdorf upstream
AS30781 JAGUAR-AS Free Pro SAS upstream
AS49673 TRUENETWORK Truenetwork LLC upstream
AS9002 RETN-AS RETN Limited upstream
AS12637 SEEWEB SEEWEB s.r.l. upstream
AS15954 Tecnocratica Tecnocratica Centro de Datos, S.L. upstream
AS22548 AS22548 - Nucleo de Inf. e Coord. do Ponto BR - NIC.BR upstream
AS31287 IPACCT-AS IPACCT CABLE Ltd upstream
AS53046 AS53046 - UNIVERSIDADE ESTADUAL DE PONTA GROSSA upstream
AS56740 DATAHATA-AS DataHata Ltd upstream
Neighbours observed via public BGP collectors; not a complete peering list.