asn.dev

Autonomous system

AS60729 TORSERVERS-NET

VPN RIPE

IPv4 addresses 768 3 prefixes
IPv6 prefixes 3 counted as prefixes, not addresses
Countries 1 mostly DE
Flagged prefixes 0 none

Summary

Zwiebelfreunde e.V. (Tor exits)

Germany · AI-generated

tor

The network of Zwiebelfreunde e.V. (ZWIEBELFREUNDE), a German non-profit

association tied to the Torservers.net community that runs a large number of Tor

exit relays. RIPE records also show the renamed handle Stiftung Erneuerbare

Freiheit.

What it's used for

  • Hosting dedicated Tor exit nodes. Traffic leaving these IPs is anonymized Tor traffic, not a directly identifiable user or hosting tenant.

Notable

  • An IP here is a Tor exit, not an end user's real address. The originating user is anywhere on the internet, hidden behind the Tor circuit, so these ranges (e.g. the well-known 185.220.101.0/24 exits) appear on virtually every Tor/anonymizer detection list.

Interesting

  • Zwiebelfreunde is a privacy non-profit that supports the Tor project and related anonymity efforts, so this is a volunteer/charity network rather than a commercial VPN.

This description is AI-generated, best-effort context — not authoritative, and provided without any guarantee of accuracy. Source, and how to suggest an edit.

Address space

Summary

Full explorer
CountryNamePrefixes
DEGermany6

Registry

Allocation record

via RIPE RDAP
Registry
RIPE
Handle
AS60729
Registry name
TORSERVERS-NET
Registrant
lir-de-renewablefreedom-1-MNT
Abuse contact
abuse@renewablefreedom.org
Registered
2013-05-22
Last changed
2024-02-12
Status
active

Reputation

Classification and threat

VPN Commercial VPN operator. Traffic is proxied on behalf of subscribers.

8 IC3 indicators addresses in this network appear in FBI IC3 cybersecurity advisories.

PrefixAdvisoryPublished
185.220.101.133Cyber Criminal Groups UNC6040 and UNC6395 Compromising Salesforce Instances for Data Theft and Extortion2025-09-12
185.220.101.143Cyber Criminal Groups UNC6040 and UNC6395 Compromising Salesforce Instances for Data Theft and Extortion2025-09-12
185.220.101.164Cyber Criminal Groups UNC6040 and UNC6395 Compromising Salesforce Instances for Data Theft and Extortion2025-09-12
185.220.101.167Cyber Criminal Groups UNC6040 and UNC6395 Compromising Salesforce Instances for Data Theft and Extortion2025-09-12
185.220.101.169Cyber Criminal Groups UNC6040 and UNC6395 Compromising Salesforce Instances for Data Theft and Extortion2025-09-12
185.220.101.180Cyber Criminal Groups UNC6040 and UNC6395 Compromising Salesforce Instances for Data Theft and Extortion2025-09-12
185.220.101.185Cyber Criminal Groups UNC6040 and UNC6395 Compromising Salesforce Instances for Data Theft and Extortion2025-09-12
185.220.101.33Cyber Criminal Groups UNC6040 and UNC6395 Compromising Salesforce Instances for Data Theft and Extortion2025-09-12

Threat data is alpha. Absence of an indicator is not evidence of good behaviour, only of absence from this one feed.

Elsewhere

Cross-check