Skip to content

Autonomous System

AS24940

Last fetched

AS24940 is operated by HETZNER-AS - Hetzner Online GmbH, registered in DE, and announces 96 prefixes to 112 BGP neighbours. AS24940 has a reputation score of 13.8 (NEUTRAL); 23,575 of its 3,237,120 announced IPv4 addresses appear on threat feeds.

Nutrition Label

WHISPER CANON · AS24940Routing diversity9.9/10Peering density8.2/10MOAS conflict✓ noneThreat-feed listings—WHOIS transparency—Resolver footprint—canon.whisper.security/asn/24940

Routing footprint

Announced prefixes
96
BGP neighbours
112
RPKI ROAs
85
MOAS conflicts
0
CAIDA AS-rank
623
Customer-cone ASNs
71
Facilities
474
Internet exchanges
49
Customer degree
31
Peer degree
189
Provider degree
8

Signals

  • ddos-mitigationProvides DDoS scrubbing or absorption for its customers.
  • critical-infrastructureServes infrastructure the internet depends on operationally.

Infrastructure presence

Internet exchanges (49 total)

  • Speed-IX
  • LINX LON1
  • 1-NL FREE
  • 1-DE FREE
  • AMS-IX
  • France-IX Paris
  • GNM-IX
  • DE-CIX Frankfurt
  • NL-ix
  • VIX

Facilities (474 total)

  • Equinix CH1/CH2/CH4 - Chicago
  • Equinix SV1/SV5/SV10 - Silicon Valley, San Jose
  • Equinix SV8 - Silicon Valley, Palo Alto
  • Equinix DA1 - Dallas
  • Digital Realty NYC (60 Hudson)
  • Equinix NY1 - New York, Newark
  • Equinix LA1 - Los Angeles
  • Equinix DC1-DC15,DC21-DC22 - Ashburn
  • Equinix MI1 - Miami, NOTA
  • Equinix TR1 - Toronto

Route origin authorizations

A sample of 10 of this network’s 85 ROAs.

Upstreams

The networks that most often share an observed BGP path with AS24940.

Blast radius

Announced IPv4 addresses
3,237,120
Threat-listed addresses
23,575
Threat density
0.7283 %
Routed prefixes
91

How much of the internet this network is responsible for, and how much of that address space currently appears on a threat feed. Coverage: computed.

Peering ecosystem

A sample of 25 of this network’s 112 BGP neighbours.

Reputation

13.8reputation score (NEUTRAL)

AS24940 (HETZNER-AS - Hetzner Online GmbH, DE) has a reputation score of 62.5 (NEUTRAL).

Threat density
52.1/100
Graph metrics
90.0/100
Historical behaviour
75.0/100
Prefix age
20.0/100

These are reputation signals about the network as a whole, not a threat-feed verdict about a specific address.

Registration

Registered to
Hetzner Online GmbH
RIR
RIPE
Registered
Mon, 03 Jun 2002 08:29:26 GMT
Abuse contact
abuse@hetzner.com

Published by the registry, not curated by Canon.

Threat-feed evidence

Related pages

Pivot from AS24940 into the prefixes, peers and country it routes for.

Queries

This ASN's full card — routing footprint, peers, conflicts and RIR facts.


MATCH (a:ASN {name: $asn})
OPTIONAL MATCH (a)-[:HAS_NAME]->(an:ASN_NAME)
OPTIONAL MATCH (a)-[:HAS_COUNTRY]->(co:COUNTRY)
OPTIONAL MATCH (a)-[:REGISTERED_BY]->(org:ORGANIZATION)
WITH a,
     collect(an.name) AS operatorNames,
     collect(co.name) AS countries,
     collect(org.name) AS organizations
OPTIONAL MATCH (a)-[:ROUTES]->(prefix:ANNOUNCED_PREFIX)
WITH a, operatorNames, countries, organizations,
     collect(prefix.name)[0..25] AS samplePrefixes
OPTIONAL MATCH (a)-[:BGP_NEIGHBOR]-(peer:ASN)
OPTIONAL MATCH (peer)-[:HAS_NAME]->(peern:ASN_NAME)
WITH a, operatorNames, countries, organizations, samplePrefixes,
     collect({asn: peer.name, operator: peern.name})[0..25] AS samplePeers
OPTIONAL MATCH (a)<-[:CONFLICTS_WITH]-(conflict:ANNOUNCED_PREFIX)
WITH a, operatorNames, countries, organizations, samplePrefixes, samplePeers,
     collect(conflict.name)[0..25] AS sampleConflicts
OPTIONAL MATCH (a)-[:HAS_SIGNAL]->(sig:THREAT_SIGNAL_TYPE)
WITH a, operatorNames, countries, organizations, samplePrefixes, samplePeers, sampleConflicts,
     collect(DISTINCT sig.name) AS signals
OPTIONAL MATCH (a)-[:IX_MEMBER]->(ix:INTERNET_EXCHANGE)
WITH a, operatorNames, countries, organizations, samplePrefixes, samplePeers, sampleConflicts, signals,
     collect(ix.name)[0..10] AS sampleExchanges
OPTIONAL MATCH (a)-[:AS_PRESENT_AT]->(fac:FACILITY)
WITH a, operatorNames, countries, organizations, samplePrefixes, samplePeers, sampleConflicts, signals, sampleExchanges,
     collect(fac.name)[0..10] AS sampleFacilities
OPTIONAL MATCH (roa:ROA)-[:ROA_AUTHORIZES_ORIGIN]->(a)
WITH a, operatorNames, countries, organizations, samplePrefixes, samplePeers, sampleConflicts, signals, sampleExchanges, sampleFacilities,
     collect({prefix: roa.prefix, maxLength: roa.maxLength})[0..10] AS sampleRoas
CALL { WITH a MATCH (a)-[:ROUTES]->(p:ANNOUNCED_PREFIX) RETURN count(p) AS prefixCount }
CALL { WITH a MATCH (a)-[:BGP_NEIGHBOR]-(n:ASN) RETURN count(n) AS peerCount }
CALL { WITH a MATCH (a)<-[:CONFLICTS_WITH]-(c:ANNOUNCED_PREFIX) RETURN count(c) AS conflictCount }
CALL { WITH a MATCH (a)-[:ROA_AUTHORIZES_ORIGIN]-(r:ROA) RETURN count(r) AS roaCount }
CALL { WITH a MATCH (a)-[:AS_PRESENT_AT]->(f:FACILITY) RETURN count(f) AS facilityCount }
CALL { WITH a MATCH (a)-[:IX_MEMBER]->(x:INTERNET_EXCHANGE) RETURN count(x) AS ixpCount }
RETURN a.name AS name,
       a.rir AS rir,
       a.orgName AS orgName,
       a.asRank AS asRank,
       a.coneAsns AS coneAsns,
       a.conePrefixes AS conePrefixes,
       a.coneAddresses AS coneAddresses,
       a.registrationDate AS registrationDate,
       a.reputationScore AS reputationScore,
       a.reputationCategory AS reputationCategory,
       a.overallThreatLevel AS overallThreatLevel,
       a.abuseEmail AS abuseEmail,
       a.hijackPostureScore AS hijackPostureScore,
       a.hijackOriginMismatchCount AS hijackOriginMismatchCount,
       a.routeLeakCount AS routeLeakCount,
       a.routeLeakTypes AS routeLeakTypes,
       a.degreeCustomer AS degreeCustomer,
       a.degreePeer AS degreePeer,
       a.degreeProvider AS degreeProvider,
       operatorNames, countries, organizations,
       samplePrefixes, samplePeers, sampleConflicts,
       signals, sampleExchanges, sampleFacilities, sampleRoas,
       prefixCount, peerCount, conflictCount, roaCount, facilityCount, ixpCount
Run yourself →

The five networks that most often share this ASN's observed BGP paths.


MATCH (a:ASN {name: $asn})<-[:BGP_PATH]-(b:BGP_PATH_OBSERVATION)
WITH b LIMIT 200
MATCH (b)-[:BGP_PATH]->(up:ASN)
WHERE up.name <> $asn
WITH up.name AS asn, count(*) AS observations
ORDER BY observations DESC
LIMIT 5
RETURN asn, observations
Run yourself →

Or query Whisper from your own LLM workflow via the Whisper MCP server.