How to Investigate Phishing Campaigns Using IP ASN Tracking
Investigating phishing campaigns using IP ASN tracking allows cybersecurity analysts to map out attacker infrastructure by identifying the Autonomous System Numbers (ASNs) and network blocks hosting malicious domains and landing pages. By tracing the routing ownership of suspicious IP addresses, security teams can uncover broader hosting patterns, anticipate threat actor behavior, and block entire malicious subnets before new phishing domains go live. Attackers frequently rotate domains while reusing the same resilient or bulletproof hosting providers, making ASN intelligence a critical pivot point for modern threat hunting.
To kickstart your investigation when analyzing a suspicious IP address tied to a phishing link, use the IP Lookup tool to instantly reveal the assigned ASN, registry, netblock owner, and geographic routing data.
Understanding ASNs in Threat Intelligence
An Autonomous System Number (ASN) is a unique identifier assigned to a network or group of networks under a single, clearly defined routing policy. Operated by Internet Service Providers (ISPs), cloud hosting companies, content delivery networks (CDNs), and enterprise organizations, ASNs form the building blocks of the Border Gateway Protocol (BGP) routing backbone of the internet.
Why ASNs Matter for Phishing Investigations
When a threat actor launches a phishing campaign, they need to host their credential harvesting forms, redirect scripts, and payload delivery servers somewhere. While they frequently change domain names and registrar accounts to evade basic reputation filters, they are often constrained by cost, availability, or operational security choices when selecting hosting providers.
By tracking the ASN of a phishing server, you can answer critical questions:
- Is the infrastructure hosted on a reputable cloud provider (e.g., AWS, DigitalOcean) or an autonomous system known for ignoring abuse complaints?
- Are multiple unrelated phishing campaigns utilizing the same upstream provider or routing block?
- Does the netblock owner align with legitimate corporate networks, indicating a compromised infrastructure rather than dedicated attacker infrastructure?
Step-by-Step Guide to ASN-Based Phishing Investigation
Conducting a thorough investigation requires moving from a specific artifact—such as a phishing URL or an IP address found in email headers—to broader infrastructure analysis.
Step 1: Extract Artifacts from the Phishing Email
Begin by analyzing the raw headers and the landing page of the phishing email. Do not click links directly from your primary workstation; instead, use an isolated sandbox or headless browser.
- Open the raw email source in your mail client or gateway.
- Look at the
Received:headers to trace the originating IP address of the sending server. - Extract any links pointing to external sites by hovering over buttons or inspecting the anchor text URL.
Step 2: Resolve Domains to IP Addresses
Once you have extracted the phishing domain name, resolve it to its current IPv4 or IPv6 address using command-line utilities like dig or nslookup.
dig +short login.example-phishing-domain.com A
Sample output:
198.51.100.45
If the domain is protected by a reverse proxy or CDN, the resulting IP will belong to the CDN provider rather than the backend hosting server. In such cases, you may need to check historical DNS records or review SSL/TLS certificate transparency logs to find the true origin IP.
Step 3: Identify the ASN and Routing Information
With the raw IP address identified, query routing registries to determine the ASN. You can use command-line WHOIS tools or query network databases directly.
whois 198.51.100.45
Sample output snippet:
NetRange: 198.51.100.0 - 198.51.100.255
CIDR: 198.51.100.0/24
NetName: EXAMPLE-HOSTING-ASN
OriginAS: AS64500
Organization: Example Cloud Services LLC (ECS-ORG)
Here, AS64500 is the Autonomous System Number associated with the hosting provider.
Step 4: Enumerate the ASN for Related Phishing Infrastructure
Once you identify the offending ASN, you can pivot to discover other IP blocks or active servers operated by the same entity. Threat intelligence platforms and routing databases allow you to list all IP prefixes assigned to a specific ASN.
For example, if you find that AS64500 hosts a disproportionate number of phishing sites targeting your industry, you can monitor or temporarily block traffic originating from that specific ASN, or flag requests containing credentials directed toward it.
Practical Investigation Techniques and Queries
To deepen your analysis, combine IP ASN tracking with other digital forensics methods.
Analyzing SSL/TLS Certificates via OpenSSL
Phishing sites frequently use automated certificate authorities to provision free TLS certificates for HTTPS phishing pages. You can inspect the certificate of a phishing site to find alternative domain names sharing the same certificate.
openssl s_client -connect 198.51.100.45:443 -servername login.example-phishing-domain.com </dev/null 2>/dev/null | openssl x509 -noout -text
Look for the Subject Alternative Name (SAN) extension in the output. Threat actors often generate a single certificate covering multiple unrelated phishing domains, allowing you to uncover an entire cluster of active campaigns tied to the same hosting setup.
Querying Abuse Contacts
When you identify malicious infrastructure within an ASN, you must report it to the appropriate network operations center (NOC) or abuse desk. Use whois or registry data to find the abuse email address associated with the netblock:
Abuse Contact: abuse@example-hosting.com
When reporting, include complete logs, timestamps in UTC, exact URLs, and evidence of malicious activity to ensure rapid takedown by the hosting provider.
Comparing Investigation Methods
| Investigation Method | Primary Focus | Best Used For | Limitation |
|---|---|---|---|
| WHOIS Domain Lookup | Registrar and administrative contact | Finding domain registration details | Often masked by privacy protection services |
| DNS History | Historical IP resolutions | Finding previous hosting providers | Can be outdated or obscured by CDNs |
| IP ASN Tracking | Routing ownership and network blocks | Identifying malicious hosting infrastructure and providers | Shared hosting environments mix malicious and legitimate sites |
| SSL/TLS Certificate Analysis | Cryptographic bindings | Linking multiple domains sharing a cert | Attackers can use unique certificates per domain |
Common Mistakes and How to Fix Them
Investigating phishing campaigns requires precision. Avoid these common pitfalls during your analysis:
- Mistake: Blocking an entire legitimate CDN or cloud provider ASN due to a single malicious IP.
- Fix: Always scope your blocks to the specific
/24or/32prefix unless malicious activity is pervasive across the entire autonomous system.
- Fix: Always scope your blocks to the specific
- Mistake: Relying solely on current DNS records when an attacker has already shifted infrastructure.
- Fix: Utilize historical DNS and passive DNS databases to trace where the domain pointed during the peak of the campaign.
- Mistake: Assuming the hosting provider ASN is the ultimate threat actor.
- Fix: Remember that cloud ASNs house thousands of innocent customers; always investigate the specific tenant account or droplet rather than blaming the parent provider.
Phishing Campaign Investigation Checklist
Use this quick checklist to ensure a thorough investigation of any suspected phishing campaign:
- Isolate the phishing URL in a secure sandbox or analysis environment.
- Extract the sending IP from email headers and resolve the landing page domain.
- Query the IP address to identify its ASN, netblock, and organization.
- Inspect SSL/TLS certificates for alternative domain names (SANs).
- Check passive DNS and routing history for related infrastructure.
- Document IOCs (IPs, domains, ASNs, hashes) for your SIEM or firewall.
- Submit abuse reports to the responsible network provider or registrar.