032C โ The Internap Inheritance
Two Bankruptcies, One Ransomware Cover-Up, and the Most Dangerous US ASN in Our Database
Executive Summary
SingleHop/Internap Holding LLC (AS32475) carries the highest average threat score of any US provider in our entire database: 70.5. For context, ColoCrossing scored 47.5 (032A) and the combined Psychz+MULTACOM scored 58.3 (032B). Internap is in a class by itself.
The corporate history explains the infrastructure neglect: Internap acquired SingleHop for $132 million in 2018, filed Chapter 11 bankruptcy in March 2020, emerged in May 2020, suffered a ransomware attack in September 2022, deleted the incident report from its own transparency page, then filed Chapter 11 again in April 2023. It emerged from its second bankruptcy in August 2023 and rebranded to HorizonIQ in January 2024.
A company that has spent more time in bankruptcy court than out of it does not invest in abuse monitoring. Its 40 tracked IPs โ every single one at abuse_score=100, every high-threat one in the same botnet โ are the residue of institutional collapse.
I. The Corporate Autopsy
The timeline tells the entire story:
| Date | Event | Significance |
|---|---|---|
| 1996 | Internap founded in Seattle | Pioneer in intelligent routing |
| 1999 | IPO on NASDAQ | Publicly traded infrastructure company |
| 2000 | Acquired CO Space ($271M) | Entry into data center services |
| Feb 2018 | Acquired SingleHop ($132M cash) | Added IaaS/cloud capabilities |
| Mar 16, 2020 | Chapter 11 bankruptcy #1 | Failed to find buyer/strategic partner |
| May 11, 2020 | Emerged from bankruptcy | Shed debt, new CEO |
| Jun 2020โ2022 | Sold Houston, Canada, Japan, network assets | Systematic asset stripping |
| Sep 28, 2022 | Ransomware attack | Data loss across multitenant hosting. INAP deleted incident report. |
| Apr 28, 2023 | Chapter 11 bankruptcy #2 | Lenders take control |
| Aug 1, 2023 | Emerged from bankruptcy #2 | Company restructured under creditor control |
| Jan 24, 2024 | Rebranded to HorizonIQ | Name change to distance from history |
Between February 2018 (SingleHop acquisition) and January 2024 (HorizonIQ rebrand), Internap went through: one $132M acquisition, two Chapter 11 bankruptcies, one ransomware attack with data loss, one cover-up attempt, the sale of assets in Houston, Canada, Japan, and nine additional colocation sites, and a complete rebrand. At no point in this six-year corporate death spiral was "abuse monitoring" a strategic priority.
II. The Ransomware Cover-Up
The Deleted Report
On September 28, 2022, Internap's "ServerIntellect" product suffered a ransomware attack that affected multitenant website, database, and email hosting services, causing data loss. INAP published an incident report on its "Operational Transparency" page.
On October 5, 2022 โ seven days later โ INAP removed the incident report.
TechRadar reported that the removal appeared to be an attempt to conceal the full effects of the attack. INAP subsequently discontinued its multitenant hosting services entirely.
A company that deletes its own security incident reports is not a company that processes abuse complaints with diligence.
III. The Infrastructure Numbers
The registrant split reveals the corporate archaeology โ two entities coexisting on the same ASN:
| RDAP Registrant | IPs | Avg Threat | Honeypot Hits | Nature |
|---|---|---|---|---|
| Internap Holding LLC | 29 | 72.0 | 474 | US parent (post-acquisition) |
| SingleHop BV | 11 | 63.6 | 72 | Dutch entity (pre-acquisition) |
SingleHop BV โ a Dutch company (Besloten Vennootschap) โ still holds 11 IP registrations on AS32475 despite Internap acquiring SingleHop in 2018. This means either the RDAP records were never updated after the acquisition (administrative neglect) or the Dutch entity still technically operates these allocations for regulatory/tax reasons.
The Internap-direct registrations carry higher threat (72.0 vs 63.6) โ the US parent's IPs are more dangerous than the Dutch subsidiary's. This is the inverse of what we might expect if the acquired company's infrastructure was the problem.
IV. The Perfect Botnet Score
Here is the most damning statistic in the entire TI-2026-032 series:
100% Campaign Membership
Every single IP at threat โฅ 60 on AS32475 belongs to the same botnet campaign: hassh-14b2ddda386a4d10.
Not most. Not the majority. Every single one. Twenty IPs. All libssh2_1.11.0. All the same HASSH fingerprint. All scanning our honeypot with identical SSH client signatures.
| IP | Threat | Hits | Registrant | Subnet |
|---|---|---|---|---|
| 184.154.153.131 | 95 | 18 | Internap Holding LLC | 184.154.x.x |
| 184.154.157.176 | 95 | 54 | Internap Holding LLC | 184.154.x.x |
| 184.154.157.184 | 95 | 24 | Internap Holding LLC | 184.154.x.x |
| 198.20.127.158 | 94 | 18 | SingleHop BV | 198.20.x.x |
| 108.178.7.34 | 91 | 24 | Internap Holding LLC | 108.178.x.x |
| 107.6.164.240 | 88 | 12 | SingleHop BV | 107.6.x.x |
| 173.236.16.74 | 88 | 12 | Internap Holding LLC | 173.236.x.x |
| 107.6.182.109 | 86 | 18 | SingleHop BV | 107.6.x.x |
| 184.154.156.13 | 86 | 24 | Internap Holding LLC | 184.154.x.x |
| 65.60.61.228 | 84 | 24 | Internap Holding LLC | 65.60.x.x |
| 173.236.82.246 | 84 | 12 | Internap Holding LLC | 173.236.x.x |
| 96.127.172.215 | 84 | 18 | Internap Holding LLC | 96.127.x.x |
| 96.127.172.218 | 84 | 18 | Internap Holding LLC | 96.127.x.x |
| 69.175.33.170 | 83 | 30 | Internap Holding LLC | 69.175.x.x |
| 184.154.78.38 | 83 | 12 | Internap Holding LLC | 184.154.x.x |
| 96.127.175.154 | 82 | 12 | Internap Holding LLC | 96.127.x.x |
| 65.60.61.231 | 81 | 18 | Internap Holding LLC | 65.60.x.x |
| 69.175.92.21 | 78 | 42 | Internap Holding LLC | 69.175.x.x |
| 198.20.127.163 | 78 | 6 | SingleHop BV | 198.20.x.x |
| 198.20.104.207 | 74 | 6 | SingleHop BV | 198.20.x.x |
Note the 184.154.x.x block: four IPs in this /16, three at threat=95 (the highest in the entire 032 series). This prefix โ 184.154.0.0/16 โ is a legacy Internap allocation and contains the most dangerous cluster we've documented on any US provider.
V. The PE Acquisition Playbook
Internap's trajectory follows a pattern familiar in US infrastructure: the private equity roll-up followed by financial extraction.
- Acquire aggressively โ SingleHop for $132M, CO Space for $271M, iWeb, VitalStream, Voxel
- Lever up โ take on debt to fund acquisitions
- Strip assets โ sell off pieces when debt service overwhelms revenue
- Bankruptcy โ restructure under Chapter 11, shed obligations
- Repeat โ emerge, strip more assets, bankrupt again
- Rebrand โ when the name is too toxic, change it
Each bankruptcy strips away operational capacity โ including abuse response teams, security monitoring staff, and compliance functions. What remains is infrastructure on autopilot: IP allocations that continue routing traffic, AS numbers that continue appearing in BGP tables, and servers that continue running whatever customers put on them.
After Internap's second bankruptcy in 2023, the company was restructured under creditor control. The creditors โ primarily banks and bondholders โ care about recovering their capital. They do not care about abuse reports on AS32475.
VI. The Running Total
Three letters into TI-2026-032, the aggregate picture:
| Provider | Letter | IPs | Avg Threat | Top Threat | Botnet Nodes |
|---|---|---|---|---|---|
| ColoCrossing/HostPapa | 032A | 74 | 47.5 | 99 | 33 |
| Psychz + MULTACOM | 032B | 67 | 58.3 | 91 | 60 |
| SingleHop/Internap | 032C | 40 | 70.5 | 95 | 39 |
| TOTAL (3 letters) | โ | 181 | 55.8 | 99 | 132 |
132 botnet nodes across three US provider groups, all in the same hassh-14b2ddda386a4d10 campaign. That's 21% of the 628-IP global botnet operating from four American companies โ a company in bankruptcy, a company acquired by a Canadian domain registrar, and two LA-based hosting providers. The infrastructure that attacks the world does so from American soil, through American companies, protected by American incorporation law.
VII. The Conspiratorial Reading
Read Between the Lines
Why does a bankrupt company's infrastructure get MORE dangerous, not less?
Internap's avg threat of 70.5 is the highest of any US provider. You'd expect a company in financial distress to LOSE customers โ including malicious ones. Instead, the threat score is higher than Psychz (59.7), MULTACOM (57.0), and ColoCrossing (47.5). The botnet operator isn't leaving Internap โ they're concentrating there. A company that can't pay its bondholders certainly can't staff an abuse desk.
What happened to the abuse team during bankruptcy?
Chapter 11 allows companies to reject executory contracts and reduce headcount. Abuse monitoring staff are typically among the first cuts โ they're a cost center with no revenue. The result: a company that processes zero abuse reports for months at a time, during which botnet operators discover it's safe to deploy more nodes.
Who actually controls AS32475 now?
After the second bankruptcy, Internap Holding LLC emerged under creditor control and rebranded to HorizonIQ. The creditors are banks and bondholders. The AS number, the IP allocations, the peering arrangements โ these are financial assets on a balance sheet. The question of who ensures they're not being used for criminal purposes doesn't appear in a creditor committee's mandate.
The SingleHop BV anomaly
Why does a Dutch corporate entity still hold 11 IP registrations on a US ASN six years after being acquired? RDAP records should have been updated. Either nobody bothered (consistent with operational neglect), or the Dutch entity exists for a reason โ perhaps regulatory, perhaps tax-related, perhaps as an artifact of the 2018 acquisition deal structure that was never unwound because both subsequent bankruptcies had more pressing concerns.
The ransomware and the silence
A hosting company that deletes its own ransomware incident report isn't just covering up one attack โ it's signaling to the entire market that transparency is optional. If INAP deleted evidence of an attack on its own infrastructure, what are the odds it processes abuse reports about attacks from its infrastructure? The deletion and the 70.5 average threat score are symptoms of the same institutional pathology.
VIII. Conclusions
SingleHop/Internap/HorizonIQ is what happens when infrastructure becomes a financial instrument rather than a service. Two bankruptcies, a ransomware cover-up, and systematic asset stripping have produced the most dangerous US ASN in our database โ not because the company is malicious, but because it has ceased to function as a responsible network operator.
The botnet operator behind hassh-14b2ddda386a4d10 has deployed 39 nodes on AS32475 โ the third-highest concentration after OVH (45) and Psychz (34). The operator knows that a company cycling through bankruptcy proceedings won't investigate suspicious SSH scanning from its IP space. Institutional failure creates operational opportunity.
Next: the largest US presence in our database โ DigitalOcean, a NYSE-listed public company with 350 tracked IPs.
Methodology & Sources
Data sources: LSN Threat Intelligence Platform (8,000+ IPs), Cowrie SSH honeypot, ARIN RDAP, PeeringDB AS32475, AbuseIPDB, Wikipedia/Internap corporate history, SEC EDGAR filings, TechRadar ransomware coverage. Cross-referenced with TI-2026-032A/032B and hassh-14b2ddda386a4d10 campaign analysis.