Summary

  • Three independent third-party mirrors of RIPE data now show AS210328's aut-num object last modified 2026-08-21T04:38:32Z, with an import policy "from AS48693 accept ANY" and an export policy "to AS48693 announce AS210328" — replacing the 2021-era policy that named AS12695.
  • The counterpart, AS48693 (Rices Privately owned enterprise, Ukraine), was itself updated by IPinfo on 15 September 2026 and lists AS210328 among its peers and downstreams.
  • The routing footprint remains small: three IPv4 prefixes originated, two announced, two RPKI-valid, one (185.218.138.0/24) still without a covering ROA in the retrieved views — and the site's claims of direct physical peering to Yandex, Sberbank and ROSTELECOM remain uncorroborated by any observed routing in the snapshots examined.

What the August edit establishes

A registry edit is a dated, checkable event. Three mirrors that embed RIPE output — whois.ipip.net, Hurricane Electric's BGP toolkit and IPGeolocation.io — agree that the AS210328 aut-num was last modified at 04:38:32 UTC on 21 August 2026, and that its import/export policy now references AS48693 rather than AS12695. The object keeps status ASSIGNED, maintainers RIPE-NCC-END-MNT and ALMAZ-MNT, and sponsoring organisation ORG-DNJ1-RIPE. This is consistent with a deliberate maintenance action this August, not a database accident.

The counterpart is itself observable. IPinfo describes AS48693 as Rices Privately owned enterprise, a Ukrainian hosting network on ntup.net with 2,560 IPv4 addresses, last updated 15 September 2026, and places AS210328 in both its peer and downstream tables. So the August edit names a real, currently maintained network.

What the routing observations show

Hurricane Electric reports three IPv4 prefixes originated by AS210328 but only two announced: 77.91.65.0/24, 185.136.15.0/24 and 185.218.138.0/24, with 512 originated addresses and zero IPv6. ping.pe's per-prefix RPKI view marks the first two VALID and 185.218.138.0/24 NOT-FOUND — no covering ROA for AS210328.

Notably, the ping.pe page for 185.218.138.0/24 shows AS209630 (LLC VASH KREDIT BANK) as the origin in its view, while other sources describe a multi-origin state including AS205997 and AS210328; origin sets are collector- and time-dependent, and BTW's prior reporting documents a ROA over that prefix issued to AS205997 being revoked on 24 August 2026.

What no retrieved view shows is peering. ping.pe records zero peers and zero downstreams for AS210328; every observed relationship is upstream transit through AS202425, AS201814 or AS48693. That is the measured contradiction with the operator's own site, almazcloud.network, which sells DIAMOND-branded Cloud Connect from $499 per month per 10G port, BGP announcements from $99 per month per prefix, GRE tunnels and corporate cloud VPN, and claims direct physical peering to Yandex, Sberbank and ROSTELECOM. Marketing text is not evidence of routing; the collector views examined do not corroborate it.

Disclosure of retrieval limits

The RIPE database web UI itself was not retrievable during this research pass — only the page shell was returned, with no object attributes. Every "live registry" statement in this briefing therefore rests on third-party mirrors embedding RIPE output, not on a first-party inspection of the authoritative record. Mirrors also disagree among themselves on contact handles: whois.ipip.net and IPGeolocation.io show admin-c/tech-c ZAN42-RIPE (a role object with an abuse mailbox and a remark that replies are given only to Russian-language emails), while Hurricane Electric shows DUMY-RIPE for the same fields.

The full public dossier on this target is consolidated in BTW's directory entry for almazcloud.network.

Sources