Executive Summary
Six months before 1337 Services GmbH registered its first autonomous system number, six months before the SHA1 hash appeared in BGP databases, six months before any of the German corporate infrastructure existed in the RIPE ecosystem โ someone in Battice, Belgium created a RIPE maintainer object called SERVPERSO-MNT.
The date was April 16, 2021. The address: Place du marchรฉ 31, 2A, 4651 Battice โ a small town in the French-speaking Wallonian province of Liรจge. The entity: "Servperso Systems NOC," a name that contracts serveur personnel โ personal server.
Our initial hypothesis was that SERVPERSO was a shell entity pre-positioned by 1337 Services' directors. That hypothesis is wrong.
SERVPERSO is operated by Sarah Rossius, a Belgian individual running a legitimate micro-ISP from an apartment above a market square since 2017. She has real clients, real peering, real IXP membership. 1337 Services GmbH is one of approximately ten clients โ and the only one on the Spamhaus DROP list.
The question is no longer whether SERVPERSO is a front. It is why Sarah Rossius continues to provide IP space to a bulletproof hosting network whose abuse reports number in the hundreds, whose directors run cybercrime forums, and whose /24 block hosts mass phishing, Tor exit relays, gaming fraud, and crypto scams โ while her own abuse page explicitly acknowledges receiving complaints about "bulletproof hosting."
At some point, inaction becomes indistinguishable from facilitation.
Chapter 1: The Timeline โ Revised
Our first analysis in Part A noted that SERVPERSO-MNT was created six months before 1337 Services' RIPE organization, and framed this as suspicious pre-positioning. The deep investigation tells a different story.
| Date | Event | Entity |
|---|---|---|
| 2017-08-10 | PeeringDB organization created | Servperso Systems |
| 2018-05-15 | Netname BE-SERVPERSO-SYSTEMS-20180515 in IP block | SERVPERSO |
| 2019-05-27 | AS34872 peering at LocIX Netherlands | SERVPERSO |
| 2019-09-13 | AS208210 created in RIPE | SERVPERSO |
| 2020-07-02 | First sub-allocation: 45.154.97.0/24 to SERVEUR_TECH | SERVPERSO โ Client |
| 2021-04-16 | SERVPERSO-MNT maintainer created | SERVPERSO |
| 2021-10-27 | ORG-SG394-RIPE created (1337 Services RIPE org) | 1337 Services GmbH |
| 2021-11-08 | ORG-CR158-RIPE created (SERVPERSO formal LIR status) | Sarah Rossius |
| 2022-03-08 | 45.154.98.0/24 sub-allocated to 1337 Services | SERVPERSO โ 1337 |
| 2025-01-29 | Operation Talent seizure | FBI / BKA |
| 2026-04-01 | SERVPERSO-MNT last modified | SERVPERSO |
| 2026-06-10 | ORG-CR158-RIPE and abuse role last modified | SERVPERSO |
SERVPERSO existed as a functional network operation for four years before 1337 Services became a customer. The April 2021 SERVPERSO-MNT creation was a maintainer reorganization within an already-running operation, not the founding of a front company. Two weeks after 1337 Services registered its RIPE org, Sarah Rossius formalized her own LIR status โ possibly motivated by needing formal LIR credentials to properly serve 1337 as a customer, or simply coincidental timing.
Hypothesis Tested and Revised
Initial hypothesis: SERVPERSO was a shell entity pre-positioned by Marzahl/Grimpe to fragment jurisdiction before launching 1337 Services.
Evidence against: Different RIPE NCC accounts (SSO authentication). Different named individuals (Rossius vs. Marzahl/Grimpe). Different countries (BE vs. DE). Different phone numbers. No shared authentication credentials. Legitimate independent operations since 2017. Multiple non-1337 clients.
Revised conclusion: SERVPERSO is an independent Belgian micro-ISP that accepted 1337 Services as a paying customer. The "Belgian precursor" is not a front โ it is an enabling infrastructure provider that knowingly maintains IP space for a bulletproof hosting network.
Chapter 2: Sarah Rossius โ The "Silly Smol Meow Meow ASN Maker"
RIPE LIR organization ORG-CR158-RIPE is registered to:
org-name: Sarah Rossius trading as Servperso Systems
org-type: LIR
country: BE
reg-nr: Not Applicable
address: Place du marchรฉ 31 B22, 4651 Herve, BELGIUM
phone: +3212860037
remarks: "--- Silly smol Meow Meow ASN maker since 2019 ---"
remarks: "ASN SPONSOR / IPv4 & IPv6 / IP Transit (VM/Tunnel/)"
remarks: website: WWW.SERVPERSO.NET
The registration number is "Not Applicable" โ Sarah Rossius operates as an unregistered sole proprietor, common for Belgian individuals below the โฌ25,000 VAT registration threshold or under the activitรฉ complรฉmentaire (complementary activity) regime. No Belgian Crossroads Bank for Enterprises (BCE/KBO) registration was found.
The self-description โ "Silly smol Meow Meow ASN maker" โ places SERVPERSO squarely in the European hobbyist networking community. These are individuals who obtain ASNs for educational purposes, run BGP tunnels, peer at internet exchange points, and provide sponsorship services for others wanting their own ASN. It's a legitimate subculture. And in this case, one of its members provides the IP allocation layer for a bulletproof hosting network.
The phone number (+3212860037) uses Belgian area code 012, corresponding to the Sint-Truiden/Tongeren area in Flemish Limburg โ not the Liรจge province where Battice is located. This suggests a VoIP number, standard practice among technical operators.
Chapter 3: Place du Marchรฉ 31, Battice
Battice is a village in the commune of Herve, in the province of Liรจge, in the French-speaking region of Wallonia. The commune population is approximately 17,000; the village of Battice itself houses roughly 5,000 people. It sits on the N3 national road between Liรจge and Aachen, about 25 kilometers east of Liรจge.
Place du Marchรฉ โ the market square โ is the village center. OpenStreetMap confirms building 31 (OSM way ID 633901704, 50.6473ยฐN, 5.8205ยฐE) as a generic building with no commercial classification. The RIPE records use two different unit numbers: "2A" (NOC role SSN105-RIPE) and "B22" (LIR org ORG-CR158-RIPE) โ both consistent with an apartment building above ground-floor shops.
This is not a datacenter address. This is not a virtual office. Based on all available evidence, this is Sarah Rossius's home.
The Name Confirmed
Servperso = serveur personnel โ French for "personal server." The Terms of Service PDF on servperso.net is tagged lang(fr-BE) (Belgian French). The operator is French-speaking, consistent with the Wallonian location. The name is consistent with a Belgian home-server enthusiast who grew their hobby into a micro-ISP โ exactly the profile the evidence supports.
Chapter 4: What SERVPERSO Maintains โ The Full Picture
SERVPERSO controls two RIPE-allocated /22 blocks (2,048 IPv4 addresses total). Here is how they're divided:
Block 1: 45.154.96.0/22
| /24 Block | Client | ASN | Status |
|---|---|---|---|
| 45.154.96.0/24 | DYJIX (France) | AS212815 | โ Legitimate French ISP |
| 45.154.97.0/24 | SERVEUR_TECH (France) | AS207300 | โ Hobbyist BGP tunnel service |
| 45.154.98.0/24 | 1337 Services GmbH (Germany) | AS210558 | ๐ด Spamhaus DROP, 100% abuse |
| 45.154.99.0/24 | SERVPERSO own use | AS34872 | โ Internal infrastructure |
Block 2: 194.28.96.0/22
| /24 Block | Client | Country | Status |
|---|---|---|---|
| 194.28.96.0/24 | CEHD SAS | France | โ Legitimate ISP |
| 194.28.97.0/24 | WAN4YOU / El Bouddunti | Belgium | โ Belgian MPLS backbone |
| Remaining /24s: allocation not publicly detailed | |||
Of approximately ten identified clients, 1337 Services GmbH is the only one with abuse indicators. Every other client is a legitimate small ISP, hobbyist network, or infrastructure project. The contamination is precise: one quarter of one /22, one client out of ten.
Chapter 5: The Toxic Quarter
45.154.98.0/24 is the single most concentrated block of criminal infrastructure on AS210558. Our intelligence platform tracks five IPs; reverse DNS reveals 211 PTR records across the full /24.
What the PTR Records Show
| PTR Pattern | Count | Purpose |
|---|---|---|
*.powered.by.rdp.sh | 30+ | rdp.sh bulletproof hosting customers |
ns1.rdp.sh | 1 | Primary nameserver for rdp.sh |
tor-exit-1.allium.top | 1 | 2cb.li/Satanist Tor exit relay |
| Turkish phishing domains (.cfd/.sbs) | 30+ | Mass phishing operation |
support-edgerwallet.com | 1 | Cryptocurrency wallet phishing |
acesso-imediato.com | 1 | Brazilian scam/fraud |
d0wnrite.com | 1 | Gaming fraud platform |
powered.by.cdn.amazon.com | 4+ | Fake CDN / reverse proxy |
| Offensive racial slur | 1 | Characteristic of criminal hosting clientele |
This is not speculative abuse. This is verifiable in public DNS. The PTR records themselves document the criminal character of this block: phishing, fraud, anonymization, brand impersonation, hate speech.
The entire /24 is on Spamhaus DROP (SBL687510). DROP is the nuclear option โ it tells ISPs worldwide to silently discard all traffic from this prefix at their border routers. Spamhaus applies it when a block is "directly operated by or leased to criminal spam/attack groups."
The Two Notable Tenants
45.154.98.153 โ hostname 45.154.98.153.powered.by.rdp.sh. AbuseIPDB: confidence 100%, 289 reports from 155 distinct reporters. Shodan reveals ports 80, 82, 83, 84 (web services), 9100 (Prometheus node_exporter), 9600 (Logstash monitoring). The monitoring stack indicates professionally managed infrastructure โ someone is collecting metrics and aggregating logs. 50 OTX pulses list this IP as part of anonymization networks.
45.154.98.33 โ hostname tor-exit-1.allium.top. AbuseIPDB: confidence 100%, 150 reports from 79 reporters, flagged as Tor exit. This is a relay operated by the entity investigated in TI-2026-033: the 2cb.li network, run by an anonymous operator using death-themed nicknames across 49+ Tor relays on 17+ ASNs.
A professional DevOps monitoring stack and a death-themed Tor exit relay. Same /24. Same Belgian maintainer.
Chapter 6: The Complicity Question
SERVPERSO's own abuse reporting page at servperso.net/abuse explicitly lists "bulletproof hosting" as a category of abuse complaint they receive. This is not a provider unaware of the problem. This is a provider who has categorized the complaints and continues to maintain the allocation.
The Evidence of Knowledge
- 289 AbuseIPDB reports on 45.154.98.153 from 155 distinct reporters โ each sent to abuse@servperso.net
- 150 AbuseIPDB reports on 45.154.98.33 from 79 reporters
- Spamhaus DROP listing โ the most severe IP blacklist classification โ on the entire /24
- Self-acknowledged "bulletproof hosting" abuse category on the SERVPERSO website
- Active maintenance: ORG-CR158-RIPE last modified June 10, 2026 โ ten days before this report
Sarah Rossius knows. She maintains the records. She receives the abuse reports. She has the administrative authority to revoke the sub-allocation. She has not.
There are three ways to interpret this:
- Economic dependency: 1337 Services is a paying customer whose revenue Sarah Rossius cannot afford to lose. A micro-ISP operating from an apartment in Battice may not have the financial cushion to terminate a client paying for a /24 sub-allocation.
- Contractual constraint: RIPE NCC policies on sub-allocation revocation may create friction. Once a sub-allocation is made, revoking it requires process โ and 1337 Services would likely challenge any revocation.
- Willful tolerance: The financial benefit outweighs the reputational cost. Bulletproof hosting pays well, and the reputational damage is limited to technical communities that most people never see.
All three may be simultaneously true. None of them constitute a defense.
Chapter 7: The Route Object โ Four Parties, Three Countries
The BGP route object for 45.154.98.0/24 via AS210558 has three maintainers:
route: 45.154.98.0/24
origin: AS210558
mnt-by: SERVPERSO-MNT โ Belgium (LIR, IP allocation)
mnt-by: lir-de-1337services-1-MNT โ Germany (client, route management)
mnt-by: HYBULA-MNT โ Netherlands (hosting/transit)
created: 2022-03-08T22:45:21Z
Hybula B.V. is a Dutch cloud hosting company founded in 2017 that accepts cryptocurrency payments. Their presence as the third maintainer on this route object suggests they provide physical hosting or upstream transit for 1337 Services' infrastructure on this prefix.
The full chain from traffic to accountability:
Any law enforcement investigation of activity on this /24 must coordinate between the anonymous relay operator, the German company, the Belgian sole proprietor, and the Dutch hosting provider. This is not a bug. For the operator, this is the feature.
Chapter 8: The Geo Discrepancy
Our intelligence platform detects a consistent geographic disagreement across all five SERVPERSO-maintained IPs:
| Source | What It Measures | Country |
|---|---|---|
| Team Cymru (BGP) | Where traffic actually routes | ๐ง๐ช Belgium |
| RDAP (Registration) | Where IP space is registered | ๐ณ๐ฑ Netherlands |
| AbuseIPDB (Geolocation) | Where IP appears geographically | ๐ณ๐ฑ Netherlands (3 IPs) / ๐ง๐ช Belgium (2 IPs) |
BGP says Belgium. Registration says Netherlands. For the two IPs where BGP routes through Belgium (45.154.98.19, 45.154.98.160), traffic may actually transit Belgian infrastructure โ possibly through the WIIT Dรผsseldorf datacenter where SERVPERSO has a presence, or through Belgian peering. The rdp.sh geofeed URL in the RIPE inetnum object attempts to override geolocation databases with custom data โ a technique used to manipulate where services like MaxMind place IP addresses.
Chapter 9: What We Now Know, What We Don't
Established Facts
- SERVPERSO is operated by Sarah Rossius, a Belgian individual in Battice/Herve, not a shell company
- SERVPERSO has been active since 2017 with genuine operations, IXP membership, and multiple legitimate clients
- 1337 Services became a customer in late 2021, within an already-established Belgian micro-ISP
- 45.154.98.0/24 was sub-allocated in March 2022 and has been consistently toxic since
- SERVPERSO knows about the abuse โ their website categorizes "bulletproof hosting" complaints
- The sub-allocation has survived Operation Talent, hundreds of abuse reports, and Spamhaus DROP listing
- SERVPERSO remains actively maintained as of June 2026
Open Questions
- What is Sarah Rossius's online identity? No social media profiles confirmed beyond @servperso (Twitter, inaccessible). She may operate under a pseudonym in relevant communities.
- What does the client contract say? SERVPERSO's Terms of Service exist as a Belgian French PDF. Do they include an acceptable use policy? Is there a termination clause for abuse?
- What revenue does 1337 Services represent? A /24 sub-allocation's market value is significant โ potentially โฌ500-2,000/month. For a sole proprietor operating from a Belgian apartment, this could be substantial income.
- Has RIPE NCC intervened? RIPE's policies allow for mediation in disputes over IP space used for abuse. No RIPE NCC action against SERVPERSO or 1337 Services is publicly documented.
- What role does Hybula B.V. play? The Dutch hosting company's presence on the route object suggests physical infrastructure involvement. The exact nature โ transit, colocation, hosting โ is unclear.
Methodology
This investigation uses RIPE NCC REST API queries (organisation, mntner, inetnum, route, role objects), PeeringDB organisation records, bgp.he.net reverse DNS and routing data, OpenStreetMap/Nominatim geolocation, AbuseIPDB abuse reports, Shodan service discovery, AlienVault OTX threat intelligence feeds, Spamhaus DROP/SBL data, Wayback Machine web archives, and our honeypot intelligence platform's entity graph (271,000+ edges).
All RIPE data was verified from live queries on June 20, 2026. Per-source attribution is maintained throughout โ where sources disagree, the disagreement is documented.
No active scanning was performed against SERVPERSO infrastructure. No contact was made with Sarah Rossius.