Co-Tenants on the Edge
What ~1,900 .academy domains beside a Squarespace brand teach about shared hosting, reputation, and hunting your own infrastructure
A reverse-IP dump pulled during an internal audit of a small Squarespace site produced about two thousand neighbor hostnames. Nearly nineteen hundred of them ended in .academy. At 2 a.m. in a SOC that looks like a cluster: a brand, a suspicious TLD, a shared address. It is not a cluster in the incident sense. It is what multi-tenant anycast looks like when you finally count it.
Core numbers :
2,020 neighbor names compiled; 1,898 ended in .academy
1,767 / 1,898 (93.1%) still resolve Squarespace-only to the official connect quartet
54 unique A-record IPs across the whole set
27 unique outlier apexes fully re-resolved
83 compile-time resolve failures (82 still dead; 1 revived onto a connect IP)
QuantC ~874k lines; ~548k string hits on SQSP ranges
QuantumGuard top talkers after the LAN: the four connect IPs at ~42k–44k mentions each
Why reverse-IP graphs show up in internal audits
Internal audit, done honestly, uses the same opening moves as an external hunter. You ask DNS who answers for your name. You ask the registry who sold it. You ask the address who else lives there. The last question is reverse-IP: given 198.49.23.144, which hostnames have been seen pointing at it?
You ask because attackers ask. Passive DNS and “hosts on this IP” APIs are cheap reconnaissance. They populate phishing-kit reports, bulletproof-hosting writeups, and the mental model that collocation implies relationship. On a dedicated VPS that model is often fair. On a SaaS connect IP it is almost always wrong.
In this engagement the subject was quantitativesecurity.org: Tucows registrar, NS1 p07 plus squarespacedns.com, apex on Squarespace’s published connect set 198.49.23.144/145 and 198.185.159.144/145 (AS53831). The first article closed the origin: not hijacked, not a Go phishing kit, residual risk in SPF/DMARC, expiry, and clone surface. Then the local reverse-IP dumps were compiled. 2,020 names. 1,898 ended in .academy.
That is the moment an audit either becomes a witch hunt or a platform lesson.
The graph is not optional. Misreading it is.
The owned property (what “adjacent” is adjacent to)
Squarespace connect quartet
Official Squarespace connect quartet (AS53831) — these four IPs are Quantitative Security’s published web edge and the neighborhood 1,767 academies still share:
Not used by any academy in this file: 198.49.23.176/177/180/181, 198.185.159.176/177.
Name gate (confirmed):
HTTPS to IP, no SNI/Host → 403 + X-Sqsp-Edge: true; TLS CN=*.squarespace.com (DigiCert)
HTTPS to IP + Host/SNI = www → 200 site
HTTPS to IP + foreign Host → 404
Apex Host → 301 → www
Fingerprint pair: nmap says Golang net/http; HTTP says Server: Squarespace + crumb cookie + HTML <!-- This is Squarespace. --> + site id 650b298815aab365957d7171. Both true. Do not allowlist “Go + Squarespace” globally; do not denylist the VIP from a school dump.
Origin verdict: not compromised, not a Go phishing kit, not hijacked. Residual is mail-auth, expiry, clone surface, dual-label SOC confusion, and this shared-IP neighborhood.
Multi-tenant SaaS: false incidents and real reputation risk
Two stories compete for the same packets.
False incident narrative. “Our site shares an IP with 1,500 unknown academies. Scanners flag the IP. Therefore we are clustered with malicious infrastructure, or we have been parked on a bad neighborhood, or the Go listener nmap sees is a second server.” Each clause appeared, in some form, in the parent case. Each failed a test. The academies are other customers. The Go fingerprint is Squarespace’s implementation. The neighborhood is the product.
Real reputation risk. A mail or web reputation system that keys on IP, not hostname, will treat the connect quartet as one organism. If a co-tenant spams, hosts a cloned shop, or trips a malware crawler, the address can heat up. Industry chatter already notes Squarespace shared-IP false positives. That is not theoretical camouflage for an attacker either: a kit that spoofs Server: Squarespace on a Go process can hide in the same label space defenders use to allowlist the brand.
Public abuse data confirms the residual is live. AbuseIPDB shows repeated reports against the connect addresses (dozens of reports per IP, confidence scores commonly in the teens to low-forties). Categories include phishing, email spam, and brand-infringement attributions that resolve to other hostnames on the same VIP. URLhaus has historically listed offline malware URLs (including Cobalt Strike and Mozi-related paths) associated with 198.49.23.145; those entries are offline and reflect tenant activity on the shared edge, not ownership of the brand.
Name-gating is the nuance. Talking to the IP with no Host/SNI yields 403 and X-Sqsp-Edge. A foreign Host yields 404. The correct name yields the site. Content is not a free-for-all on the VIP. Reputation systems that never send SNI still see one IP. Hunters who never re-resolve still see one dump.
The operational rule: co-tenancy explains the graph; it does not erase blast radius. You document the first so you do not page people. You accept or mitigate the second as a platform choice.
Stratification: a monoculture with a thin, honest tail
Every name was classified by live (then compiled) A records.
Resolved: 1,815. Fail: 83. Live re-dig: 82 still dead; 1 revived (www.shop.level-up.academy→ 198.185.159.144).
Next-busiest non-SQSP IPs are tiny: AWS GA pair 76.223.67.189 / 13.248.213.45 (5 hosts each), 52.223.13.41 (4). Everything else is 1–2 names. That is monoculture with a measurement error bar.
The majority, sampled. Forty random bucket-A names, headers and a title grab. Forty of forty returned Server: Squarespace and a crumb cookie — the same pair www.quantitativesecurity.org returns. About half were 301/302 to www or to an off-TLD brand (including a Thinkific classroom). Of the 200s, a large fraction were Squarespace’s own Coming Soon placeholder (~3 KB, noindex). Two were platform sad-paths: “Domain Not Claimed,” “Website Expired.” A handful were real brochure sites with static1.squarespace CDN and 300 KB–1.3 MB HTML. Fingerprint consistency is not a vibe. It is 40/40.
The tail, worked first. Twenty-seven unique apex outliers, fully re-resolved. They are boring in the way that matters.
Complete IP catalog — 54 A-record addresses
The neighborhood QS actually lives in
Mixed leftovers
Cloudflare anycast (AS13335)
Open on every scanned CF dest: 80, 443, 8080, 8443. Path: AT&T → 172.68.188.{20,72,74,76,78,83} → VIP, ~9–18 ms.
Selected IPs and hosts:
104.18.35.90 — www.cyberquest.academy, www.nursepreneur.academy
104.21.24.163 / 172.67.219.154 — baytree.academy
104.21.65.86 / 172.67.160.104 — onegreen.academy
104.21.68.177 / 172.67.197.137 — augmere.academy
104.21.83.161 / 172.67.178.103 — legalgeek.academy
162.159.140.166 / 172.64.152.166 — cyberquest / nursepreneur pairs
162.159.140.98 / 172.66.0.96 — muktajeevanswamibapa.academy
Additional VIPs for qace.academy pairs
GitHub Pages / Fastly (185.199.108.0/22, AS54113)
Open 80/443. Path ~10–20 ms.
185.199.108.153 … 185.199.111.153 — beautymafia.academy set (Server: GitHub.com; www CNAME maksimmaverick.github.io)
Wix (185.230.63.0/24, AS58182)
Open 80/443. Path via Telia ~39–58 ms.
185.230.63.107 / .171 / .186 — aivana.academy (unattached Wix, Pepyaka 404). www also on GCLB 34.149.87.45.
Vercel (AS16509)
Open 80/443. Path ~9–31 ms.
76.76.21.21 / .98 / .142, 66.33.60.66 / .67 — foundationbasketball.academy, cognet.academy (Server: Vercel)
Broader .academy
Public sources do show active abuse on other .academy names (examples: polymarket.academy, tradebnb.academy, various “cyberlearn” / trading-academy downloaders, wallet-connect phishing). This is TLD-fashion noise, not evidence that the 1,898 names sharing the Squarespace VIP are a coordinated set.
AWS Global Accelerator / Netlify landers (AS16509)
the Author
Public urlscan activity on 52.223.13.41 shows heavy generic /lander usage across many unrelated domains — consistent with parking infrastructure, not a unique campaign tied to the academy names.
Google / GCE / ghs
Hostinger, Namecheap/Worldstream, Infomaniak/Odoo
Hostinger (77.37.76.*, 147.79.120.*, 92.112.198.42) — cuttingedge.academy (hcdn); live A drifted vs compile.
Namecheap 104.219.250.37 + Worldstream 2.59.170.20 — learnpianomtl.academy
(park page; HTTPS broken on Worldstream).
Infomaniak VIP 84.16.66.164 (HAProxy) + Odoo/OVH 91.134.82.31 — matrimoney.academy.
Host dossiers — every live outlier (27 apexes)
Registrar ≠ NS ≠ A (the three-layer finding).Supported: 12 / 27 outlier apexes are registered at Squarespace Domains (11 × “II LLC”, 1 × legacy “Domains LLC”) and do not host on the connect quartet. They point at Wix, GitHub, Vercel, Netlify, Google Sites, Hostinger, or Cloudflare.
Exhibits:
cyberquest.academy — Tucows (same registrar family as QS) + Squarespace/NS1 nameservers + Cloudflare A.
ilearn.academy — Squarespace Domains + nsb*.squarespacedns.com + Google Sites.
baytree.academy — Cloudflare fronting Squarespace (still sets crumb on CF IP).
Per-host facts (context only; not QS assets):
agilitycoach.academy/lernegerne.academy — A 52.223.13.41. 114-byte /lander stub. Parking.
contentbliss.academy/inni.academy/montgomeryandmiller.academy — same GA pair, identical 114-byte stub. Shared lander product, n=5.
aivana.academy — Wix unattached (Pepyaka 404). Registrar SQSP Domains II.
algomio.academy (P0) — 35.188.140.129. OpenSSH 10.0p2 Debian + nginx “Coming Soon”. TLS LE. No auth attempted. Path ~150 ms.
augmere.academy — CF. Live product (“Plan it. Prove it. Build it.”). Catch-all 200 on /admin = homepage size.
baytree.academy — CF + crumb; www “Website Expired”. CF fronting SQSP.
beautymafia.academy — GitHub Pages. Telegram/Instagram links.
blnd.academy (P0) — 35.207.173.107. Path ~231 ms via 62.67.38.114 (NetCologne). nginx + WordPress/Elementor + Pure-FTPd + Dovecot + MySQL 8.4.6-6 on 3306. Public WP REST exposed users + posts (dev hostname leak blnd-academy.local). Class finding: shared-hosting control-panel stack on the public Internet. Not a QS asset.
cognet.academy/foundationbasketball.academy — Vercel shop/product pages.
cuttingedge.academy — Hostinger CRA shell; SPA catch-all.
cyberquest.academy — SQSP NS + Cloudflare A. Confirmed: SQSP nameservers ≠ SQSP web anycast.
ilearn.academy — Google Sites / Frontend; Anthropic domain-verification TXT; catch-all 1587 B.
legalgeek.academy — CF 404 “Domain Not Claimed”.
lionheartcoaching.academy — SQSP DNS + Netlify dest → ivyroadmaps.com. Third-party coaching brand.
learnpianomtl.academy — Namecheap + Worldstream park; TLS broken.
matrimoney.academy — Infomaniak HAProxy + Odoo /web/login.
muktajeevanswamibapa.academy — CF + DigitalOcean app; /register real size.
onegreen.academy — CF golf-academy brochure.
qace.academy — CF 301 → qaceinstitute.com.
www.nursepreneur.academy — CF, large live body.
Mixed still-SQSP names (boldmoves, ina, partneringleadership) retain Squarespace on the name while carrying unused European extra As.
No high-confidence public campaign IOCs were found tying these specific 27 apex names to known active phishing or malware operations. Broader .academy TLD abuse exists (other names, other registrars), but it does not map onto this audit set.
Services — what is actually listening
Sensors (QuantC / QuantumGuard) — self-recon, not a botnet
QG main-log top IPs overlapping the academy unique set: 15. The four connect IPs sit at ~42k–44k mentions each. QuantC ~874k lines with ~548k hits on SQSP ranges. Stream dominated by lab host ↔ SQSP :443. Confirmed: volume is self-recon of one edge. Do not promote outlier IPs or co-tenant names to a QS blocklist.
Abuse / IOC cross-reference
Connect quartet:
AbuseIPDB: repeated reports on 198.49.23.144 and 198.49.23.145 (dozens of reports, confidence commonly 17–41%). Categories are phishing, email spam, brand infringement, and scanner noise. Reports routinely attribute activity to other hostnames on the same VIP.
URLhaus: historical offline malware URLs associated with 198.49.23.145 (Cobalt Strike .exe, Mozi-related paths). Offline; shared-edge attribution.
No evidence that the reports originate from or target quantitativesecurity.org itself.
Outlier apexes / IPs from the 27:
No high-confidence public campaign IOCs found for blnd.academy, algomio.academy, cyberquest.academy, baytree.academy, or the other named outliers in the package.
AWS GA lander IPs show heavy generic /lander parking use; neighboring GA addresses appear in some phishing reports, consistent with shared parking infrastructure rather than a unique academy botnet.
Broader .academy TLD contains unrelated phishing (e.g. other names not in this set). That is TLD-fashion noise, not evidence that the 1,898 names on the Squarespace VIP are coordinated.
The public abuse data strengthens residual R-1 / S-3 (shared-IP reputation). It does not change the origin verdict or the property line. The noise is platform-level.
What do you do with the strangers on the same address?
1,767 names (93%) still resolve Squarespace-only to the same four anycast addresses. Forty-eight live elsewhere. Eighty-three are dead DNS. Three are mixed. Public abuse databases show ongoing noise on those same four addresses — phishing, spam, and historical offline malware URLs attributed to other tenants. That is the shared-edge residual made visible, not evidence of a crime gang co-located with the brand.
Reverse-IP graphs appear because SaaS edges are multi-tenant by design and because dumps go stale. They do not appear because the brand was clustered with a threat set. What stays in scope is small: document the official VIPs; teach the SOC not to ticket co-tenants as owned servers; keep SPF/DMARC and registrar lock; watch class IOCs (anycast + crumb + empty PTR), not school names.
Hunting your own infrastructure means drawing the property line on a shared street — in writing, with counts, with the public abuse data that already sits on the same VIPs — before someone else’s reverse-IP CSV becomes tomorrow’s false incident channel.