Phishing Activity in Hosting Networks (ASNs)
February 1, 2021 - April 30, 2021

To see where phishing sites were being hosted, we collected the IP addresses that phishing domains and phishing URLs were resolving to when phishing activity was detected and added to a threat or block list. We then identified the ASN where the IP prefix containing the IP address of the phish is allocated and this number identifies the hosting network where phishing attacks were reported.

For the February 1, 2021 to April 30, 2021 period, we identified

- 161 hosting networks with 100 or more reported phishing attacks.

- 54 hosting networks with 500 or more reported phishing attacks. and

- 27 hosting networks with 1000 or more reported phishing attacks.

- 4 hosting networks with 5000 or more reported phishing attacks.

We measure phishing attacks to show where phishing sites are hosted and to identify the hosting service that has been allocated the IPv4 address space wherein the IP address of the phishing site lies.

A phisher may use one, several, or large numbers of URLs in a single phishing campaign. We apply rules to our phishing reports to de-duplicate URLs and to analyze hostname, URL path composition, target, and abuse report dates for similarities to obtain sets of URLs that we consider to be involved in one phishing attack. We also apply additional rules to group URLs into attacks based on observed cases.

In the table below, we show the twenty hosting networks with the highest numbers of reported phishing attacks.

Ranking of Hosting Networks (ASNs) by Phishing Attacks
(February to April 2021)

Rank AS Name AS number # Routed
IPv4 Addresses
Phishing Attacks ▼ Phishing Attack Score
1 NAMECHEAP-NET 22612 79,872 19,018 2381.06
2 CLOUDFLARENET 13335 2,334,464 17,392 74.50
3 UNIFIEDLAYER-AS-1 46606 1,391,360 8,915 64.07
4 DIGITALOCEAN-ASN 14061 2,466,560 5,367 21.76
5 GOOGLE 15169 23,094,784 4,713 2.04
6 AMAZON-02 16509 38,892,032 3,687 0.95
7 AWEX - Hostinger International Limited 204915 768 3,402 44296.88
8 DDOS-GUARD CORP. 262254 17,152 3,073 1791.63
9 OVH - OVH SAS 16276 3,814,656 2,969 7.78
10 ASN-QUADRANET-GLOBAL 8100 686,592 2,766 40.29
11 IDNIC-JALANET-AS-ID PT. Jupiter Jala Arta 131775 2,560 2,632 10281.25
12 MICROSOFT-CORP-MSN-AS-BLOCK 8075 38,045,440 2,544 0.67
13 WEEBLY 27647 2,048 2,343 11440.43
14 HETZNER-AS - Hetzner Online GmbH 24940 2,042,368 2,334 11.43
15 CONTABO - Contabo GmbH 51167 226,048 2,165 95.78
16 AMAZON-AES 14618 16,318,464 1,731 1.06
17 AS-CHOOPA 20473 1,004,032 1,709 17.02
18 GD-EMEA-DC-SXB1 - Host Europe GmbH 8972 406,016 1,512 37.24
19 AS-COLOCROSSING 36352 789,760 1,509 19.11
20 LAYER-HOST 46573 407,808 1,412 34.62

To allow comparison of large and small Hosting Networks (ASNs), we also rank Hosting Networks based on a metric, phishing attack score, which is calculated by dividing the number phishing attacks reported against an ASN by the number of routable IPv4 addresses allocated to that ASN.

Hosting (ASN) Phishing Attack Score = (number of phishing attacks/IP Addresses in ASN) * 10,000

In the table below, we show the top 20 hosting operators based on phishing attack score.

Ranking of Hosting Networks (ASNs) by Phishing Attack Score
(February to April 2021)

Hosting Networks (ASNs) with a minimum of 50,000 IPv4 addresses and 25 phishing attacks

Rank AS Name AS number # Routed IPv4
Addresses
Phishing attacks Phishing Attack Score ▼
1 NAMECHEAP-NET 22612 79,872 19,018 2381.06
2 AS-REGRU - "Domain names registrar REG.RU", Ltd 197695 93,440 1,285 137.52
3 IMH-WEST 22611 62,720 726 115.75
4 INMOTI-1 54641 54,784 580 105.87
5 CONTABO - Contabo GmbH 51167 226,048 2,165 95.78
6 AS-HOSTINGER - Hostinger International Limited 47583 89,856 687 76.46
7 CLOUDFLARENET 13335 2,334,464 17,392 74.50
8 UNIFIEDLAYER-AS-1 46606 1,391,360 8,915 64.07
9 SUNHK-DATA-AS-AP Sun Network (Hong Kong) Limited - HongKong Backbone 38197 91,392 575 62.92
10 VELIANET-AS - Host Europe GmbH 29066 81,408 449 55.15
11 XSERVER Xserver Inc. 131965 60,928 335 54.98
12 PONYNET 53667 60,416 273 45.19
13 AS-30083-GO-DADDY-COM-LLC 30083 66,816 294 44.00
14 RACKRAY - UAB Rakrejus 62282 58,880 254 43.14
15 ASN-QUADRANET-GLOBAL 8100 686,592 2,766 40.29
16 NFORCE - NForce Entertainment B.V. 43350 88,576 336 37.93
17 GD-EMEA-DC-SXB1 - Host Europe GmbH 8972 406,016 1,512 37.24
18 ALCHEMYNET 7296 73,216 264 36.06
19 A2HOSTING 55293 140,800 496 35.23
20 LAYER-HOST 46573 407,808 1,412 34.62