asn.dev

Autonomous system

AS51396 PFCLOUD

Hosting RIPE

IPv4 addresses 7.42K 24 prefixes
IPv6 prefixes 25 counted as prefixes, not addresses
Countries 1 mostly DE
Flagged prefixes 0 none

Summary

Pfcloud UG

Germany · AI-generated

hosting lir transit-reseller

PFCLOUD is Pfcloud UG (haftungsbeschränkt), a German LIR that leases address

space and resells transit to a sizeable set of small hosting networks, while

originating a substantial block of space itself.

What it's used for

Hosting and connectivity resale. RIS observes 33 IPv4 prefixes totalling 8,448

addresses plus 39 IPv6 prefixes — the widest IPv6 footprint of any network in

this size class — reached through 33 upstreams.

The distinctive feature is the customer cone: 22 downstream ASNs, including

[AS197170](https://asn.ipinfo.app/AS197170) (TechTies),

[AS203027](https://asn.ipinfo.app/AS203027),

[AS212094](https://asn.ipinfo.app/AS212094),

[AS214940](https://asn.ipinfo.app/AS214940) and

[AS58232](https://asn.ipinfo.app/AS58232). PeeringDB self-labels the network

"Network Services", Europe, 100-200Gbps, which fits an LIR selling space and

transit rather than a pure server host.

Notable

  • A classification on this ASN does not reach its customers. Pfcloud's 22 downstream ASNs originate their own prefixes; labelling AS51396 only labels space AS51396 itself announces. Each downstream is judged on its own evidence — AS197170 was, separately.
  • It sits behind 33 upstreams of its own, so despite the customer cone this is a reseller rather than a backbone. Tier-1 it is not.
  • Pfcloud recurs as the upstream of newly-registered hosting shells. When one of its customers turns up in a report, Pfcloud is usually one of the two or three transit providers listed.

Interesting

  • Reputation is substantial: listed in Spamhaus ASN-DROP under pfcloud.io, 176.65.148.0/22 in Spamhaus DROP as SBL679272, and an FBI IC3 indicator in the space at 176.65.149.100 — advisory [250912](https://www.ipinfo.app/out/?url=https%3A%2F%2Fwww.ic3.gov%2FCSA%2F2025%2F250912.pdf), UNC6040 and UNC6395 compromising Salesforce instances for data theft and extortion (2025-09-12).
  • The AS number was registered on 2023-12-08, which is recent for a network with a 22-ASN customer cone. Growth of that shape in under two years is characteristic of IPv4 leasing rather than organic hosting growth.
  • pfcloud.io sits behind a Cloudflare interstitial that does not render for automated fetches, so the product catalog cannot be read directly the way most hosts' can. Registry data, PeeringDB and the customer cone are what describe this network.

This description is AI-generated, best-effort context — not authoritative, and provided without any guarantee of accuracy. Source, and how to suggest an edit.

Address space

Summary

Full explorer
CountryNamePrefixes
DEGermany49

Registry

Allocation record

via RIPE RDAP
Registry
RIPE
Handle
AS51396
Registry name
PFCLOUD
Registrant
lir-de-pfcloud-2-MNT
Abuse contact
abuse@pfcloud.io
Registered
2023-12-08
Last changed
2025-12-18
Status
active

Reputation

Classification and threat

Hosting Datacenter or cloud provider. Addresses are servers, not people.

1 IC3 indicators addresses in this network appear in FBI IC3 cybersecurity advisories.

PrefixAdvisoryPublished
176.65.149.100Cyber Criminal Groups UNC6040 and UNC6395 Compromising Salesforce Instances for Data Theft and Extortion2025-09-12

Threat data is alpha. Absence of an indicator is not evidence of good behaviour, only of absence from this one feed.

Elsewhere

Cross-check