asn.dev

Autonomous system

AS39351 ESAB-AS

Hosting RIPE

IPv4 addresses 14.59K 35 prefixes
IPv6 prefixes 15 counted as prefixes, not addresses
Countries 1 mostly SE
Flagged prefixes 0 none

Summary

31173 Services

Sweden · AI-generated

colo datacenter hosting

A Swedish data-center and network operator, 31173 Services AB, announcing as ESAB-AS. It owns and operates data centers in Malmö and Lund and runs an IP/MPLS network across northern and central Europe.

What it's used for

  • Colocation, hosting, and network/transit services with Swedish/EU data residency, plus VPS/game-server hosting delivered by customers on its network.

Notable

  • An IP here identifies 31173 as the host, not the operator of the hosted service.
  • The network spans many PoPs from Stockholm toward Central Europe (Copenhagen, Amsterdam, Frankfurt, Zurich), which is why it shows up as an upstream for other regional hosts.

Interesting

  • The name "31173" reads as "ELITE" in leetspeak, reflecting its roots serving low-latency gaming and enthusiast hosting in the Nordic region.

This description is AI-generated, best-effort context — not authoritative, and provided without any guarantee of accuracy. Source, and how to suggest an edit.

Address space

Summary

Full explorer
CountryNamePrefixes
SESweden50

Registry

Allocation record

via RIPE RDAP
Registry
RIPE
Handle
AS39351
Registry name
ESAB-AS
Registrant
ESAB-MNT
Abuse contact
abuse@31173.se
Registered
2006-02-06
Last changed
2026-04-08
Status
active

Reputation

Classification and threat

Hosting Datacenter or cloud provider. Addresses are servers, not people.

3 IC3 indicators addresses in this network appear in FBI IC3 cybersecurity advisories.

PrefixAdvisoryPublished
141.98.252.189Cyber Criminal Groups UNC6040 and UNC6395 Compromising Salesforce Instances for Data Theft and Extortion2025-09-12
185.209.199.56Cyber Criminal Groups UNC6040 and UNC6395 Compromising Salesforce Instances for Data Theft and Extortion2025-09-12
45.83.220.206Cyber Criminal Groups UNC6040 and UNC6395 Compromising Salesforce Instances for Data Theft and Extortion2025-09-12

Threat data is alpha. Absence of an indicator is not evidence of good behaviour, only of absence from this one feed.

Elsewhere

Cross-check