AS252
Operated by DNIC-AS-00252 - Headquarters, USAISC.
Summary
- // analyst note
- Actively-routed legacy military stub AS. Allocated_date is the ARIN autnum TOP-LEVEL registration event (1988-11-02), NOT the nested org/contact events (HEADQU-3 1990-03-26, REGIS10-ARIN 2009-06-24) which are decoys. CAIDA cliqueMember:true noted but may reflect a dataset quirk for military ASNs rather than literal clique membership.
- // security note
- NEUTRAL/DATED: no notable public abuse signal found as of 2026-06-20; absent from Spamhaus DROP/ASN-DROP, FireHOL, and community ASN blacklists.
About this ASN.
AS252 is a legacy autonomous system number registered under ARIN to "Headquarters, USAISC" — the U.S. Army Information Systems Command — and held today under the administrative stewardship of DISA-Columbus on behalf of the U.S. Army. The ARIN handle is AS252 with AS name DNIC-AS-00252, reflecting its origin in the Defense Network Information Center numbering scheme. It is one of the oldest ASNs in service: ARIN RDAP records a top-level registration event of 1988-11-02 (last changed 2011-08-24), and RIPEstat routing history first observed it announcing prefixes in August 2000. Unlike the dormant legacy ASNs sometimes found in this number range, AS252 is actively routed: RIPEstat reports five IPv4 prefixes (128.47.0.0/16, 155.29.152.0/21, 192.70.236.0/24, 204.37.16.0/21, 204.37.24.0/24) totalling roughly 70,144 addresses, plus one IPv6 prefix (2001:480:34::/48), with near-universal global visibility (326/327 IPv4 RIS peers; 324/324 IPv6). CAIDA classifies it as a stub AS — one upstream provider, zero peers, zero customers — ranked 13,508 with a singleton customer cone. The named registrant USAISC is organizationally defunct, inactivated 1 October 1996 and realigned under U.S. Army CECOM; its successor lineage runs U.S. Army Signal Command (1996) then NETCOM (2002). No notable public abuse signal was found as of June 2026 — absent from Spamhaus DROP/ASN-DROP, FireHOL, and community ASN blacklists — consistent with a closed U.S. military government network. A single historical note (May 2017 WannaCry C2 contact from a Fort Huachuca IP) was disputed by U.S. Army Cyber Command as research activity, and the ASN attribution to AS252 specifically was not confirmed.
- Operator
- Headquarters, USAISC (U.S. Army Information Systems Command); ASN administratively held under DISA-Columbus on behalf of the U.S. Army [Confirmed] — ARIN RDAP autnum/252, registrant HEADQU-3
- Country / RIR
- US, ARIN [Confirmed] — RIPEstat abuse-contact-finder (authoritative_rir: arin); ARIN RDAP autnum/252
- Allocated
- 1988-11-02 (ARIN autnum top-level registration event, NOT an IEEE date — IEEE publishes no ASN registration dates); last changed 2011-08-24 [Confirmed] — ARIN RDAP autnum top-level events
- Org status
- named registrant USAISC is defunct (inactivated 1 October 1996, realigned under U.S. Army CECOM); the ASN remains active (ARIN status "active"); admin stewardship transferred to DISA-Columbus; successor network org is NETCOM (active since 2002)[Confirmed] — ARIN RDAP autnum/252, en.wikipedia.org/wiki/Army_Network_Enterprise_Technology_Command
- Contacts
- abuse / registration disa.columbus.ns.mbx.arin-registrations@mail.mil; registrant Fort Huachuca, AZ 85613; admin DISA-Columbus, 300 North James Road, Whitehall, OH 43213 [Confirmed] — ARIN RDAP autnum/252, RIPEstat abuse-contact-finder
Security/abuse context (NEUTRAL, DATED)
no notable public abuse signal found as of 2026-06-20 — absent from Spamhaus DROP/ASN-DROP, FireHOL blocklist-ipsets, and community ASN blacklists; CleanTalk stats page exists but returned HTTP 403 (unverified); no AS252 mentions in NANOG archives
Network & routing
- Network type
- U.S. Department of Defense / U.S. Army government military network; internal DoD infrastructure; single upstream connectivity via AS668 (DoD HPC / DREN) [Confirmed for type via RDAP/bgp.tools; Likely for upstream identity — CAIDA confirms one upstream but does not name it] — bgp.tools/as/252, bgp.he.net/AS252
- Size
- 5 IPv4 prefixes / ~70,144 IPv4 addresses and 1 IPv6 prefix (2001:480:34::/48); customer cone = 1 ASN (itself), 5 prefixes, 70,144 addresses [Confirmed] — RIPEstat routing-status & announced-prefixes / CAIDA AS Rank (2026-06)
- Routing/peering
- announced — 326/327 IPv4 RIS peers, 324/324 IPv6; CAIDA degree total 1 (customer 0, peer 0, provider 1) = stub AS; PeeringDB net/22228 lists Open peering policy (no contract/ratio/location requirement), no active IXP, traffic Not Disclosed [Confirmed for routing/visibility; Confirmed for PeeringDB policy] — RIPEstat routing-status, peeringdb.com/net/22228
- RPKI
- not assessable from canonical data — RIPEstat rpki-validation skipped (no prefix supplied); bgp.he.net noted possible bogon/IRR origin mismatches but no ROA status confirmed [Unknown] — RIPEstat rpki-validation, bgp.he.net/AS252
- Notable usage
- supports U.S. Army internal communications and information-systems infrastructure; registrant address NETC-ANC CONUS TNOSC, Fort Huachuca, AZ; routing first observed 2000-08-18 (192.35.75.0/24), last seen 2026-06-20 (204.37.24.0/24) — RIPEstat routing-status, ARIN RDAP autnum/252
- Related ASNs
- AS668 (DoD HPC / DREN — sole upstream); AS749 (DoD-adjacent block referenced in 2017 incident attribution ambiguity) [Likely — upstream per bgp.he.net/bgp.tools; AS749 named only as attribution caveat] — bgp.he.net/AS252
- Historical incident (DATED, DISPUTED)
- May 2017 — a Fort Huachuca / USAISC-block IP contacted WannaCry C2 infrastructure on 2017-05-12; U.S. Army Cyber Command disputed the "infection" framing as security-research activity; attribution to AS252 specifically vs. other DoD blocks (e.g. AS749) not confirmed[Likely] — cyberscoop.com/wannacry-ransomware-u-s-army-research-lab-fort-huachuca
- Analyst note
- actively-routed legacy military stub AS; registrant org (USAISC) is defunct since 1996 but the ASN is live under DISA-Columbus stewardship. Allocated_date is the autnum top-level event (1988-11-02), NOT the nested org/contact events (HEADQU-3 1990-03-26, REGIS10-ARIN 2009-06-24), which are decoys.
What this network routes.
- 128.47.0.0/16
- 204.37.16.0/21
- 204.37.24.0/24
- 192.70.236.0/24
- 2001:480:34::/48
Who it talks to.
| ASN | Operator | Role |
|---|---|---|
| AS668 | DNIC-AS-00668 - United States Department of Defense (DoD) | upstream |