AS44477
Last known operator PQ HOSTING PLUS S.R.L. (formerly Stark Industries Solutions Ltd). RIPEstat has no current registration record for this AS number.
Summary
- // analyst note
- One of the most heavily documented 'bulletproof'-characterized networks; specific abuse attaches to tenants/dated incidents, not the operator wholesale. Note heavy IP rotation, post-sanctions migration to AS209847, and that AS44477 itself is now unrouted with no live RIPE holder.
- // security note
- NEUTRAL/DATED/SOURCED: 2024-05-23 KrebsOnSecurity reported Stark used as a global proxy network concealing sources of cyberattacks/disinformation against opponents of Russia; Kentik observed Iran as top NetFlow destination (35.1%); cites NoName057(16) DDoS and a Correctiv report linking Stark to RRN [attributed].
About this ASN.
AS44477 is the network registered under RIPE that operated for several years as Stark Industries Solutions and was most recently held by PQ HOSTING PLUS S.R.L. under the AS name THE-HOSTING. As of June 2026 the ASN has no live holder binding in the RIPE registry — RIPEstat reports the holder as "None" / "-Reserved AS-" with zero announced prefixes — and it has not been visible in the global routing table since 16 April 2026; cached aut-num data on third-party mirrors still shows the PQ Hosting binding, but that is stale. Stark Industries Solutions materialized on 10 February 2022 — two weeks before Russia's invasion of Ukraine — offering VPS, proxy, and VPN services, and is characterized in EU and US government instruments and multiple security-vendor reports as a "bulletproof" host. As of the May 2024 KrebsOnSecurity reporting, Spur found the network home to at least 74 VPN services and 40 proxy services. On 20 May 2025 the Council of the EU sanctioned Stark Industries Solutions Ltd and its principals (Iurie and Ivan Neculiti), stating they acted as enablers of Russian state-sponsored and affiliated actors conducting information manipulation and cyber-attacks against the Union and third countries. The ASN was transferred to a new RIPE org under parent PQ Hosting around May 2025, rebranded THE-HOSTING, and went operationally invisible in the global routing table after 16 April 2026; security vendors documented a parallel migration to AS209847 (WorkTitans B.V.). An analyst encountering historical AS44477 IPs is most often triaging proxy/VPN, DDoS, malware C2, or disinformation infrastructure per those reports — but specific malicious activity attaches to specific tenants and dated incidents, not to a blanket characterization, and the network was heavily rotated.
- Operator
- PQ HOSTING PLUS S.R.L. (RIPE org ORG-PHPS1-RIPE); previously Stark Industries Solutions Ltd [Last-known — RIPE WHOIS; aut-num object no longer live, holder now "None"/Reserved in RIPEstat]
- Country / RIR
- Moldova (Chisinau); Stark was UK-registered; RIPE [Last-known]
- Allocated
- 2020-03-17 [Last-known/Historical — from cached RIPE aut-num created date; NOT confirmable against a live RIPE object, which no longer exists] — bgpview.io/2ip.io cached RPSL; reflects original aut-num creation under earlier custody, not the 2022 Stark rebrand
- Org status
- sanctioned (EU, 2025-05-20); migrated/rebranded; AS44477 withdrawn from routing after 2026-04-16 and no longer holds a live RIPE registry binding [Confirmed]
Security/abuse context (NEUTRAL, DATED, SOURCED)
2024-05-23 KrebsOnSecurity ("An Iron Hammer in the Cloud") reported Stark used as a global proxy network concealing the source of cyberattacks/disinformation against opponents of Russia; Kentik's Doug Madory observed Iran as top NetFlow destination (35.1%); cites NoName057(16) DDoS and a Correctiv report linking Stark to disinformation outlet RRN [attributed]. EU sanctions 2025-05-20: Council sanctioned Stark Industries Solutions Ltd and principals Iurie Neculiti (CEO) and Ivan Neculiti (owner) as enablers of Russian state-sponsored destabilising activities (Council Decision (CFSP) 2025/966 and 2025/963; package = 21 individuals + 6 entities) [Confirmed — EU Council]. Recorded Future/Insikt (Sept 2025) documented pre-sanctions evasion incl. PQ Hosting Plus registration and AS209847 rebrand [attributed]. GreyNoise (2025) confirmed migration of malicious infrastructure from AS44477 to AS209847 Aug–Nov 2025 [attributed]. 2026-05-18 Dutch FIOD seized 800+ servers and arrested two men over the Stark/MIRhosting infrastructure (both presumed innocent) [Confirmed — FIOD]. Tenant/incident-level attribution; US persons prohibited from transacting with EU-/US-designated parties — krebsonsecurity.com, consilium.europa.eu, recordedfuture.com
Network & routing
- Network type
- hosting-VPS / "bulletproof hosting" (per EU/Treasury and vendor characterization) [Confirmed designation context]
- Size
- ~128 IPv4 prefixes pre-withdrawal; AS44477 withdrawn from global routing after 2026-04-16; 0 prefixes now — bgpview.io, bgp.he.net
- Routing/peering
- upstreams pre-withdrawal incl. MIRhosting (AS52000), Atman (AS15694), others; RPKI unknown (withdrawn) — bgp.he.net
- Notable usage
- VPS/proxy/VPN host live since 2022-02-10; Spur found ≥74 VPN + 40 proxy services on AS44477 [Spur via KrebsOnSecurity, 2024-05-23] — krebsonsecurity.com
- Related ASNs
- lineage PQ Hosting (AS43624) → Weiss Hosting Group (AS44774) → Stark (AS44477) → PQ Hosting Plus (AS44477); post-sanctions rebrand to "THE.Hosting" on new AS209847 (WorkTitans B.V., created 2025-06-24); supporting AS48031 [Confirmed — Augur Security / Recorded Future]
- Live registry status
- as of 2026-06-07, AS44477 has NO live holder binding in the RIPE registry — RIPEstat holder = "None"/"-Reserved AS-", 0 announced prefixes. This is distinct from (and in addition to) being withdrawn from the global routing table after 2026-04-16 [Confirmed] — stat.ripe.net/resource/AS44477
- Analyst note
- One of the most heavily documented "bulletproof"-characterized networks; specific abuse attaches to tenants/dated incidents, not the operator wholesale. Note heavy IP rotation, post-sanctions migration to AS209847, and that AS44477 itself is now unrouted with no live RIPE holder.