DROP These Hosting Networks Before They Get the Drop on You
Dave Piscitello
In a previous post, I shared the results of experiments where I used Claude AI to join publicly available data with hosting networks (ASN) data published by Interisle at the Cybercrime Information Center’s records repository. I began with a simple prompt, and Claude responded with the information I requested but also provided additional insights relating to bulletproof hosting operators among the ASNs it returned. By challenging Claude to elaborate and identify sources, and by joining more external and our internal data, I was able to obtain a clearer picture of ASNs that exhibited characteristics associated with bulletproof hosting (BPH).
For this article, I’ve prompted Claude to look at more sets of ASN data, again cross-referenced these with the Spamhaus ASN DROP list, to continue to expand our understanding of the bulletproof hosting space.
Cross-referencing Interisle’s Cybercrime Data with Spamhaus ASN DROP List
For this experiment, I created a Claude project and uploaded three CSV files from the Cybercrime Information Center: Spam-HostingStats-Mar2026-May2026, Malware-Hostingstats-Apr2026-Jun2026, and Phishing-HostingStats-May2026-Jul2026. I then prompted Claude with
Which ASNs in the Spam-HostingStats-Mar2026-May2026, Malware-Hostingstats-Apr2026-Jun2026,and Phishing-HostingStats-May2026-Jul2026 are listed in the https://www.spamhaus.org/drop/asndrop.json
Claude provided a complete cross-reference along with a summary of matching entries.
Claude’s found 42 ASNs appearing in all 3 reports. Six ASNs operators identify Russian Federation as their country in RIR contact data. Five operators identify their country as US and five as Hong Kong, and four as United Kingdom.
I asked Claude to filter the Spam, Phishing, and Malware hosting stats CSV files to only include ASNs that also appear in the ASN-DROP list.
Networks with small IP address blocks that have large spam, malware, or phishing activity exhibit BPH characteristics, so I next asked Claude to find ASNs with small IP blocks (fewer than 1048 addresses) among the 42 ASNs, and to create a table of the criminal activities found in these ASNs.
Measure Twice. Cut (Drop?) Once
I could stop here but as I found in my prior exercise, are all of these truly bulletproof networks? So let’s again look beyond the inclusion of these ASNs on the Spamhaus ASN-DROP list to increase our confidence that all these ASNs offer bulletproof hosting.
PROSPERO (AS200593) and Proton66 (AS198953). A February 2025 Brian Krebs article outed the Russia-based Prospero autonomous system as “One of the most notorious providers of abuse-friendly bulletproof web hosting for cybercriminals”. An earlier investigation by Intrinsec[i] found that the Proton66 AS, also Russia-based, shared a St. Petersburg exchange, appeared to be operated by a common individual, and were “endorsed” by Russian-speaking dark forums as 100% bulletproof. Interisle’s data shows that both of these hosting networks continue to harbor significant cybercriminal activity.
Four autonomous Systems lie in the aurologic nexus. Recorded Future’s report, Malicious Infrastructure Finds Stability with aurologic GmbHm, exposes this German hosting provider as “a central nexus within the global malicious infrastructure ecosystem”. The nexus list from their 2025 report included Slayer Group (AS213441), Femo IT Solutions (AS 214351), SWISSNET (AS209373). Interisle’s data shows that these hosting networks host even more cybercriminal activity than Prospero and Proton66.
NEON CORE NETWORK LLC (AS205775). I could not find confirmation that this US-based autonomous system is used for bulletproof hosting. However, it does peer with aurologic (AS30823). In addition to the alarming numbers of phishing malware and spam reports that Interisle’s gathered, BGP.tools tags AS205775 as hosting malicious Tor exits or relays, ThreatFox database associates multiple IOCS with addresses in this ASN, and Spamhaus reports multiple active botnet c2 servers in one of Neon’s IP blocks. You decide if this is sufficient to DROP.
How Aggressively Should You DROP?
Today, I’ve walked through an AI-assisted exercise that used Interisle’s published cybercrime data and publicly available “don’t route or peer (DROP)” lists to identify hosting networks that are associated with extraordinary malicious hosting activity. I’ve also shown how we corroborate findings to gain confidence beyond our own data when we prepare policy recommendations and recommended practices.
You can use these same data and exercises to reduce your threat surface by employing route filtering at the autonomous system level.
If your organization is not familiar with the concept or the Spamhaus DROP lists, or if it has not previously applied route filtering, we caution you to make an effort to avoid bulletproof hosters:
Slow start. DROP the 7 autonomous systems that we investigated in this article.
Accelerate. DROP the 42 autonomous systems that Claude cross-referenced as appearing in our spam, phishing and malware hosting networks data and also in the Spamhaus ASN-DROP list.
Pedal to the metal. Use the full ASN-DROP list.
We encourage you to consider experimenting with an AI of your choice, use our data, complement it with other sources you trust, and make a bespoke DROP list that satisfies your risk tolerance.
If you have difficulty accessing the Intersec report URL, Security Online published a summary.
Note: Claude AI responses provided an initial set of findings and inferences for my post. I also used ChatGPT and Gemini to compare responses and prompt further. I make no endorsement of any single AI but suggest you use several, much as you’d confer with a team or reach out to other subject matter experts or researchers.



I can say that the DROP (and Extended DROP when it was separate) is extremely low in false positives, as in I don't recall a customer ever reporting one that was not caused by a temporary hijacking of an IP subnet. We recommend that our customers block it for IP and DNS firewalls and most do.
It is worth pointing out the DROP list is not the definitive list of Bulletproof hosting. There are quite a few ASNs that are not in the DROP list that I consider to be Bulletproof hosts