#AS30823
The only prefix that appeared to suffer an outage was 45.137.118.0/24 originated by Aurologic GmbH (AS30823).

It was withdrawn at 02:05 UTC and returned via Elisa Oyj (AS6667) at 02:22 UTC.
November 21, 2024 at 10:03 PM
A significant amount of #CastleLoader C2 infrastructure identified by @julianferdinand.bsky.social was tied to #ThreatActivityEnabler 🇬🇧 FEMO IT SOLUTIONS #AS214351 utilising 🇩🇪 aurologic GmbH #AS30823 as their sole upstream provider. One to watch out for!
2/ TAG-150 is Insikt Group’s designation for the actor likely behind the malware families #CastleLoader, #CastleBot, and most recently #CastleRAT, a RAT documented here for the first time.
September 4, 2025 at 3:17 PM
I know which ASN I'm blocking at work today. ipinfo.io/AS30823
November 6, 2025 at 12:16 PM
THE (AS209847) lost 94% of its fleet (255→16 hosts), following an 83% loss the week before. QWINS-LTD lost 94% in a single interval (7,615→421). AUROLOGIC (AS30823) appeared in fleet data for the first time with a 74-minute RDP sweep from a single node that listens on nothing — 45.11.18.33 […]
Original post on mastodon.social
mastodon.social
September 21, 2026 at 9:16 AM
ASN: AS30823
Location: Frankfurt am Main, DE
Added: 2026-08-11T00:17

#shodansafari #infosec
August 16, 2026 at 2:00 PM
ASN: AS30823
Location: Frankfurt am Main, DE
Added: 2026-07-28T17:12

#shodansafari #infosec
August 1, 2026 at 2:00 AM
ASN: AS30823
Location: Frankfurt am Main, DE
Added: 2026-05-03T12:29

#shodansafari #infosec
May 6, 2026 at 4:00 PM