Skip to content

IPv6 address

2a06:2ec0:1:e::152

Last fetched

2a06:2ec0:1:e::152 is announced in 2a06:2ec0::/32 by AS-ZXCS - Stichting DIGI NL and geolocates to NL. 2a06:2ec0:1:e::152 is not listed on any threat feed indexed by WhisperGraph; reconciled level NONE.

Threat posture

0threat score (procedure-native scale)

NONE

No threats observed.

Threat feeds listing this
0
Verdict coverage
no-data

Nutrition Label

WHISPER CANON · 2a06:2ec0:1:e::152Routing diversity5.7/10Peering density4.9/10MOAS conflict✓ noneThreat-feed listings10.0/10WHOIS transparency—Resolver footprint—canon.whisper.security/ip6/2a06-2ec0-1-e--152

Attribution

Announced prefix
2a06:2ec0::/32
Announcing network
AS-ZXCS - Stichting DIGI NL
RIR-registered prefix
2a06:2ec0::/29
RPKI
valid

Abuse contact

Report abuse from 2a06:2ec0:1:e::152 to the address block's holder first and copy the announcing network. These are the abuse contacts WhisperGraph holds for the block and the network.

Address block and network (as206281)
abuse@diginl.nl

Anycast detection

This does not appear to be an anycast address on the three signals Canon evaluates: reverse DNS, announced-prefix width and the announcing network's peer count. The prefix-width threshold is IPv4-tuned, so treat a negative here as weaker evidence than the same verdict on an IPv4 address.

Reverse DNS

Geographic detail

Country
NL

Threat-feed evidence

History

Related pages

Pivot from 2a06:2ec0:1:e::152 into the network and country that carry it.

Queries

This address's full card — routing attribution, reverse DNS and listed feeds. $forms unwinds the graph's stored spellings (compressed, expanded, full-padded) of this address.


UNWIND $forms AS form
MATCH (ip:IPV6 {name: form})
WITH ip
LIMIT 1
OPTIONAL MATCH (ip)-[:BELONGS_TO]->(rp:REGISTERED_PREFIX)
OPTIONAL MATCH (ip)-[:ANNOUNCED_BY]->(ap:ANNOUNCED_PREFIX)
OPTIONAL MATCH (a:ASN)-[:ROUTES]->(ap)
OPTIONAL MATCH (a)-[:HAS_NAME]->(an:ASN_NAME)
OPTIONAL MATCH (ip)-[:LOCATED_IN]->(city:CITY)
OPTIONAL MATCH (ip)-[:HAS_COUNTRY]->(ipc:COUNTRY)
WITH ip, rp, ap, a, an, city, ipc
LIMIT 10
WITH ip,
     collect(rp.name) AS registeredPrefixes,
     collect(rp.abuseEmail) AS registeredAbuseEmails,
     collect({prefix: ap.name, asn: a.name, network: an.name, isMoas: ap.isMoas, rpkiStatus: ap.rpkiStatus, isAnycast: ap.isAnycast, dominantCity: ap.dominantCity, abuseEmail: ap.abuseEmail, networkAbuseEmail: a.abuseEmail}) AS announcements,
     collect(city.name) AS cities,
     collect(ipc.name) AS countries,
     collect(a.name) AS announcerNames,
     head(collect(a)) AS primaryAsn,
     head(collect(ap)) AS primaryPrefix
OPTIONAL MATCH (primaryPrefix)-[:CONFLICTS_WITH]->(conflict:ASN)
WITH ip, registeredPrefixes, registeredAbuseEmails, announcements, cities, countries, announcerNames, primaryAsn,
     collect(conflict.name) AS conflictAsns
CALL { WITH primaryAsn MATCH (primaryAsn)-[:ROUTES]->(p:ANNOUNCED_PREFIX) RETURN count(p) AS asnPrefixCount }
CALL { WITH primaryAsn MATCH (primaryAsn)-[:BGP_NEIGHBOR]-(peer:ASN) RETURN count(peer) AS asnPeerCount }
RETURN ip.name AS name,
       ip.verdictLevel AS verdictLevel,
       ip.verdictScore AS verdictScore,
       ip.verdictBlocking AS verdictBlocking,
       ip.verdictCoverage AS verdictCoverage,
       ip.verdictAdvisory AS verdictAdvisory,
       ip.threatSources AS threatSources,
       ip.threatFirstSeen AS threatFirstSeen,
       ip.threatLastSeen AS threatLastSeen,
       ip.isTor AS isTor,
       ip.isVpn AS isVpn,
       ip.isProxy AS isProxy,
       ip.isC2 AS isC2,
       ip.isPhishing AS isPhishing,
       registeredPrefixes, registeredAbuseEmails, announcements, cities, countries, announcerNames, conflictAsns,
       asnPrefixCount, asnPeerCount
Run yourself →

Network context — Tor exit relays, attributed actors, and the covering blocks' signals, cloud region and vendor.


UNWIND $forms AS form
MATCH (ip:IPV6 {name: form})
WITH ip
LIMIT 1
OPTIONAL MATCH (ip)-[:OPERATES_EXIT_NODE]->(tor:TOR_RELAY)
WITH ip, count(tor) AS torRelays
OPTIONAL MATCH (ip)-[:ATTRIBUTED_TO]->(actor:ACTOR)
WITH ip, torRelays, collect(actor.name)[0..5] AS actors
OPTIONAL MATCH (ip)-[:BELONGS_TO]->(p:PREFIX)
WITH torRelays, actors, collect(p.name) AS coveringPrefixes
UNWIND (CASE WHEN size(coveringPrefixes) = 0 THEN [null] ELSE coveringPrefixes END) AS pn
OPTIONAL MATCH (cp:PREFIX {name: pn})
OPTIONAL MATCH (cp)-[:HAS_SIGNAL]->(sig:THREAT_SIGNAL_TYPE)
OPTIONAL MATCH (cp)-[:PREFIX_IN_REGION]->(reg:CLOUD_REGION)
OPTIONAL MATCH (cp)-[:DELEGATED_TO]->(v:VENDOR)
RETURN torRelays, actors,
       collect(sig.name) AS signals,
       collect(reg.name) AS regions,
       collect(v.name) AS vendors
Run yourself →

Or query Whisper from your own LLM workflow via the Whisper MCP server.