XiaTools

How to Investigate Phishing Campaigns Using IP ASN Tracking

Updated 11 Oct 2026

Investigating phishing campaigns using IP ASN tracking allows cybersecurity analysts to map out attacker infrastructure by identifying the Autonomous System Numbers (ASNs) and network blocks hosting malicious domains and landing pages. By tracing the routing ownership of suspicious IP addresses, security teams can uncover broader hosting patterns, anticipate threat actor behavior, and block entire malicious subnets before new phishing domains go live. Attackers frequently rotate domains while reusing the same resilient or bulletproof hosting providers, making ASN intelligence a critical pivot point for modern threat hunting.

To kickstart your investigation when analyzing a suspicious IP address tied to a phishing link, use the IP Lookup tool to instantly reveal the assigned ASN, registry, netblock owner, and geographic routing data.

Understanding ASNs in Threat Intelligence

An Autonomous System Number (ASN) is a unique identifier assigned to a network or group of networks under a single, clearly defined routing policy. Operated by Internet Service Providers (ISPs), cloud hosting companies, content delivery networks (CDNs), and enterprise organizations, ASNs form the building blocks of the Border Gateway Protocol (BGP) routing backbone of the internet.

Why ASNs Matter for Phishing Investigations

When a threat actor launches a phishing campaign, they need to host their credential harvesting forms, redirect scripts, and payload delivery servers somewhere. While they frequently change domain names and registrar accounts to evade basic reputation filters, they are often constrained by cost, availability, or operational security choices when selecting hosting providers.

By tracking the ASN of a phishing server, you can answer critical questions:

  • Is the infrastructure hosted on a reputable cloud provider (e.g., AWS, DigitalOcean) or an autonomous system known for ignoring abuse complaints?
  • Are multiple unrelated phishing campaigns utilizing the same upstream provider or routing block?
  • Does the netblock owner align with legitimate corporate networks, indicating a compromised infrastructure rather than dedicated attacker infrastructure?

Step-by-Step Guide to ASN-Based Phishing Investigation

Conducting a thorough investigation requires moving from a specific artifact—such as a phishing URL or an IP address found in email headers—to broader infrastructure analysis.

Step 1: Extract Artifacts from the Phishing Email

Begin by analyzing the raw headers and the landing page of the phishing email. Do not click links directly from your primary workstation; instead, use an isolated sandbox or headless browser.

  1. Open the raw email source in your mail client or gateway.
  2. Look at the Received: headers to trace the originating IP address of the sending server.
  3. Extract any links pointing to external sites by hovering over buttons or inspecting the anchor text URL.

Step 2: Resolve Domains to IP Addresses

Once you have extracted the phishing domain name, resolve it to its current IPv4 or IPv6 address using command-line utilities like dig or nslookup.

dig +short login.example-phishing-domain.com A

Sample output:

198.51.100.45

If the domain is protected by a reverse proxy or CDN, the resulting IP will belong to the CDN provider rather than the backend hosting server. In such cases, you may need to check historical DNS records or review SSL/TLS certificate transparency logs to find the true origin IP.

Step 3: Identify the ASN and Routing Information

With the raw IP address identified, query routing registries to determine the ASN. You can use command-line WHOIS tools or query network databases directly.

whois 198.51.100.45

Sample output snippet:

NetRange:     198.51.100.0 - 198.51.100.255
CIDR:         198.51.100.0/24
NetName:      EXAMPLE-HOSTING-ASN
OriginAS:     AS64500
Organization: Example Cloud Services LLC (ECS-ORG)

Here, AS64500 is the Autonomous System Number associated with the hosting provider.

Step 4: Enumerate the ASN for Related Phishing Infrastructure

Once you identify the offending ASN, you can pivot to discover other IP blocks or active servers operated by the same entity. Threat intelligence platforms and routing databases allow you to list all IP prefixes assigned to a specific ASN.

For example, if you find that AS64500 hosts a disproportionate number of phishing sites targeting your industry, you can monitor or temporarily block traffic originating from that specific ASN, or flag requests containing credentials directed toward it.

Practical Investigation Techniques and Queries

To deepen your analysis, combine IP ASN tracking with other digital forensics methods.

Analyzing SSL/TLS Certificates via OpenSSL

Phishing sites frequently use automated certificate authorities to provision free TLS certificates for HTTPS phishing pages. You can inspect the certificate of a phishing site to find alternative domain names sharing the same certificate.

openssl s_client -connect 198.51.100.45:443 -servername login.example-phishing-domain.com </dev/null 2>/dev/null | openssl x509 -noout -text

Look for the Subject Alternative Name (SAN) extension in the output. Threat actors often generate a single certificate covering multiple unrelated phishing domains, allowing you to uncover an entire cluster of active campaigns tied to the same hosting setup.

Querying Abuse Contacts

When you identify malicious infrastructure within an ASN, you must report it to the appropriate network operations center (NOC) or abuse desk. Use whois or registry data to find the abuse email address associated with the netblock:

Abuse Contact: abuse@example-hosting.com

When reporting, include complete logs, timestamps in UTC, exact URLs, and evidence of malicious activity to ensure rapid takedown by the hosting provider.

Comparing Investigation Methods

Investigation Method Primary Focus Best Used For Limitation
WHOIS Domain Lookup Registrar and administrative contact Finding domain registration details Often masked by privacy protection services
DNS History Historical IP resolutions Finding previous hosting providers Can be outdated or obscured by CDNs
IP ASN Tracking Routing ownership and network blocks Identifying malicious hosting infrastructure and providers Shared hosting environments mix malicious and legitimate sites
SSL/TLS Certificate Analysis Cryptographic bindings Linking multiple domains sharing a cert Attackers can use unique certificates per domain

Common Mistakes and How to Fix Them

Investigating phishing campaigns requires precision. Avoid these common pitfalls during your analysis:

  • Mistake: Blocking an entire legitimate CDN or cloud provider ASN due to a single malicious IP.
    • Fix: Always scope your blocks to the specific /24 or /32 prefix unless malicious activity is pervasive across the entire autonomous system.
  • Mistake: Relying solely on current DNS records when an attacker has already shifted infrastructure.
    • Fix: Utilize historical DNS and passive DNS databases to trace where the domain pointed during the peak of the campaign.
  • Mistake: Assuming the hosting provider ASN is the ultimate threat actor.
    • Fix: Remember that cloud ASNs house thousands of innocent customers; always investigate the specific tenant account or droplet rather than blaming the parent provider.

Phishing Campaign Investigation Checklist

Use this quick checklist to ensure a thorough investigation of any suspected phishing campaign:

  • Isolate the phishing URL in a secure sandbox or analysis environment.
  • Extract the sending IP from email headers and resolve the landing page domain.
  • Query the IP address to identify its ASN, netblock, and organization.
  • Inspect SSL/TLS certificates for alternative domain names (SANs).
  • Check passive DNS and routing history for related infrastructure.
  • Document IOCs (IPs, domains, ASNs, hashes) for your SIEM or firewall.
  • Submit abuse reports to the responsible network provider or registrar.

Frequently asked questions

What is the difference between an IP address and an ASN in phishing investigations?

An IP address points to a specific server hosting the phishing site, while an ASN represents a larger network or collection of IP routing blocks managed by a single organization, such as an ISP or cloud hosting provider. Tracking the ASN helps security analysts identify broader hosting patterns and infrastructure used by threat actors across multiple campaigns.

Can threat actors hide their true ASN when hosting phishing sites?

Yes, threat actors frequently use content delivery networks, reverse proxies, and multi-layered routing services to mask their true origin IP and hosting ASN. However, misconfigurations, direct-to-IP connections, and analysis of SSL/TLS certificate transparency logs can often reveal the underlying infrastructure.

Should I block an entire ASN when I find a phishing site hosted there?

Blocking an entire ASN is rarely recommended unless the autonomous system is explicitly known as a bulletproof host with zero abuse response. Major cloud providers and ISPs host millions of legitimate websites, so blocking an entire ASN will cause significant collateral damage and disrupt legitimate business traffic.

How do I find the correct abuse contact for a malicious IP address?

You can query the IP address using a WHOIS tool or check regional internet registries such as ARIN, RIPE, or APNIC. The registry record will list a dedicated abuse email address or web portal where you can report malicious activity and request infrastructure takedowns.

What tools are essential for conducting an IP and ASN-based investigation?

Essential tools include command-line utilities like dig, whois, and openssl, alongside online lookup utilities that aggregate BGP routing data, ASN ownership, and threat intelligence feeds. Combining these technical lookups with passive DNS databases provides a comprehensive view of the attacker's footprint.

Related articles

Free tools