Autonomous system
AS11878 TZULO
Hosting ARIN
Summary
tzulo, inc.
hosting legacy
TZULO is tzulo, inc., a Chicago-based dedicated-server, colocation and cloud
hosting provider that has been trading since the early 2000s and runs its own
network out of Chicago and Los Angeles facilities. This is a hosting network, and
the routing evidence says so plainly.
What it's used for
Server hosting. RIS sees 195 IPv4 prefixes totalling about 114,688 addresses plus
33 IPv6 prefixes, against only 9 observed neighbours. That ratio is the tell:
a wholesale carrier of this address size would peer with hundreds of ASes. Nine
upstreams and a large, heavily fragmented address pool is a content-and-servers
network buying transit, not selling it. Every reverse-DNS name sampled follows the
same first-party template, static-<ip>.cust.tzulo.com, which is a hosting
provider's default naming for customer static assignments.
Notable
- The prefix registrations look scattered at first glance: alongside blocks registered to tzulo itself, RDAP returns small LLCs and individual people as the registered orgs of
/24s that tzulo announces. Read against the rest of the evidence this is the IPv4 leasing market, not brokered proxy space. tzulo is a real, findable business with public facilities and pricing, and the leased-in blocks wear tzulo's owncust.tzulo.comreverse DNS rather than a stranger's. - The fragmentation is worth understanding for anyone geolocating an address here: the space was assembled from many small acquisitions and transfers over time, so neighbouring
/24s can have very different registration histories.
This description is AI-generated, best-effort context — not authoritative, and provided without any guarantee of accuracy. Source, and how to suggest an edit.
Address space
Summary
| Country | Name | Prefixes |
|---|---|---|
| US | United States of America | 65 |
Registry
Allocation record
- Registry
- ARIN
- Handle
AS11878- Registry name
- TZULO
- Registrant
- tzulo, inc.
- Abuse contact
- abuse@tzulo.com
- Registered
- 2007-04-02
- Last changed
- 2012-02-24
- Status
- active
Reputation
Classification and threat
Hosting Datacenter or cloud provider. Addresses are servers, not people.
11 IC3 indicators addresses in this network appear in FBI IC3 cybersecurity advisories.
| Prefix | Advisory | Published |
|---|---|---|
198.44.129.56 | Cyber Criminal Groups UNC6040 and UNC6395 Compromising Salesforce Instances for Data Theft and Extortion | 2025-09-12 |
198.44.129.88 | Cyber Criminal Groups UNC6040 and UNC6395 Compromising Salesforce Instances for Data Theft and Extortion | 2025-09-12 |
198.54.130.100 | Cyber Criminal Groups UNC6040 and UNC6395 Compromising Salesforce Instances for Data Theft and Extortion | 2025-09-12 |
198.54.130.108 | Cyber Criminal Groups UNC6040 and UNC6395 Compromising Salesforce Instances for Data Theft and Extortion | 2025-09-12 |
198.54.133.123 | Cyber Criminal Groups UNC6040 and UNC6395 Compromising Salesforce Instances for Data Theft and Extortion | 2025-09-12 |
23.234.69.167 | Cyber Criminal Groups UNC6040 and UNC6395 Compromising Salesforce Instances for Data Theft and Extortion | 2025-09-12 |
68.235.43.202 | Cyber Criminal Groups UNC6040 and UNC6395 Compromising Salesforce Instances for Data Theft and Extortion | 2025-09-12 |
68.235.46.151 | Cyber Criminal Groups UNC6040 and UNC6395 Compromising Salesforce Instances for Data Theft and Extortion | 2025-09-12 |
68.235.46.202 | Cyber Criminal Groups UNC6040 and UNC6395 Compromising Salesforce Instances for Data Theft and Extortion | 2025-09-12 |
68.235.46.208 | Cyber Criminal Groups UNC6040 and UNC6395 Compromising Salesforce Instances for Data Theft and Extortion | 2025-09-12 |
Showing the first 10 of 11.
Threat data is alpha. Absence of an indicator is not evidence of good behaviour, only of absence from this one feed.
Elsewhere