Skip to main content

Infrawatch — verifying a scanner with no forward DNS via authoritative reverse DNS

by shop owners for shop owners.

How the PARC feed for Infrawatch came about: a threat-intel scanner leasing scattered single IPs across the Hydra Communications network. No FCrDNS possible — identified via authoritative reverse DNS *.infrawat.ch. 581 IPs, derived from the CINS blacklist and confirmed stable.

Infrawatch (infrawatch.com) is an internet-wide threat-intel scanner — “Real Time Internet Intelligence”, tracking proxies, VPNs and hostile networks. Not an SEO tool. Infrawatch leases scattered single IPs across the network of Hydra Communications (AS25369, an ISP) — no dedicated range, no official list. A classic FCrDNS proof is impossible (no forward records). Instead it is identified via authoritative reverse DNS *.infrawat.ch. 1,177 IPs: derived from the CINS blacklist (581) and completed via a reverse scan of the neighbouring ranges. Part of our PARC Security feed.

infrawatch.json — view feed   infrawatch.com →

Why no FCrDNS here — and why reverse DNS is still enough

We verify our other scanner feeds bidirectionally (FCrDNS): the PTR must forward-resolve back to the same IP. With Infrawatch that is impossible — the reverse names 185-216-145-162.infrawat.ch have no forward record. But that is not a gap here:

A reverse-DNS record can only be set by whoever controls the IP (the lessee, via the host). Nobody can name a foreign IP infrawat.ch. So if an IP’s PTR points to *.infrawat.ch, that IP belongs to Infrawatch — not spoofable. FCrDNS otherwise guards against forward identity spoofing (anyone can claim “I am Googlebot”); that risk does not exist in authoritative reverse DNS. So reverse-only is a valid ownership proof here.

AS25369 belongs to the ISP, not Infrawatch

The 581 IPs are scattered across ~21 entirely different prefixes (69.5.169.0/24, 194.88.98.0/23, 185.216.144.0/22, 217.146.80.0/20, 5.226.136.0/21 …), all on AS25369 — Hydra Communications Ltd. Hydra is a hosting/IP-transit provider, not Infrawatch. The blocks are shared: neighbouring IPs belong to other Hydra customers —

185.216.145.5   → moschatelineage.com
185.216.145.10  → baremetal.zare.com
185.216.145.162 → 185-216-145-162.infrawat.ch   ← Infrawatch
185.216.145.200 → discoverproassistance.com

So neither ASN nor prefix works as an identifier — only the per-IP reverse DNS. The feed is therefore per-IP, not range-based.

From 581 to 1,177 — neighbours from the derived ranges

CINS gave us 581 scattered single IPs. From those we know the /24 clusters Infrawatch sits in. Because the reverse PTR marks each Infrawatch IP unambiguously, the neighbours can be uncovered: we fully reverse-scanned the BGP prefixes around the known IPs (22,784 addresses across 21 /24s) — spread over a pool of 16 DNS resolvers — and kept every IP whose PTR is *.infrawat.ch.

Result: 1,177 IPs (581 from CINS + 596 newly discovered neighbours). Tellingly, all hits sit in the same 21 /24s — the rest of the larger Hydra prefixes belong to other customers. Infrawatch’s active footprint in these blocks is therefore exhausted.

Reverse-DNS pattern & stability

<dashed-ip>.infrawat.ch      (e.g. 185-216-145-162.infrawat.ch)

We freshly reverse-resolved all 1,177 IPs: 1,177 of 1,177 point to *.infrawat.ch — none rotated away. Unlike cloud scanners (Stretchoid on Azure), Infrawatch sits on fixed hosting, so the set is stable. The PARC feed is kept current by regular reverse re-verification.

Sources

← Back to PARC Security   Get in touch