Executive Summary

When our threat intelligence platform queries Team Cymru's BGP database for AS210558 โ€” a German autonomous system routing traffic for 50 IPv4 prefixes โ€” the org field returns not a company name, but a cryptographic hash: 028f45e8dd4f225cb46a7d8003745a3a7f55d3a0.

Behind this hash sits 1337 Services GmbH, registered at Hamburg's Handelsregister under HRB 164175. Its commercial brand, rdp.sh, advertises "Private, anonymous hosting with DDoS protection" and accepts 20+ cryptocurrencies including Monero. Its IP space is mediated through three maintainer layers spanning Germany, Belgium, and the Netherlands. Its geographic claims are systematically false โ€” 32 IPs simultaneously claim to be in Poland, the United States, the Netherlands, Belgium, and Germany depending on which source you query.

In January 2025, Operation Talent seized starkrdp.io โ€” a reseller on this platform. The backend survived.

This is the foundation of the Anonymity Factory. Everything else is built on it.

Chapter 1: The Hash That Replaced a Name

Every autonomous system on the internet has an org field in the major IP-to-ASN databases. It's how threat intelligence tools identify who operates which IP block. When you query AS16276, you get "OVH SAS." When you query AS14061, you get "DigitalOcean, LLC." When you query AS210558, you get this:

028f45e8dd4f225cb46a7d8003745a3a7f55d3a0, DE

That's a 40-character hexadecimal string โ€” the exact length of a SHA1 hash. Not a company name. Not an abbreviation. A hash.

The effect is precise: any automated threat intelligence system that correlates abuse reports by org name will fail to link AS210558's activity to "1337 Services GmbH." The hash is unique enough that no other entity will match it, but opaque enough that the entity behind it is invisible to automated queries. It's not an alias. It's not a typo. It's a mask.

The Two Possibilities

If deliberate: This represents a novel evasion technique โ€” exploiting the BGP metadata layer itself to frustrate threat intelligence correlation. The operator submits a hash instead of a name to the Regional Internet Registry's operational feed, knowing that automated tools parse this field literally.

If accidental: It's a data processing artifact in Team Cymru's pipeline โ€” perhaps an internal identifier that wasn't dereferenced. But even if accidental, the company has no incentive to fix it. An opaque identifier provides the same protection as a deliberate one.

Either way, the name disappears from the single most widely-used IP-to-org mapping service on the internet.

RIPE NCC's own database, queried directly, returns the real name: 1337 Services GmbH, ORG-SG394-RIPE, with a registered address at Ludwig-Erhard-Str. 18, Hamburg. But RIPE's whois is not what automated threat intel tools typically query in bulk. Team Cymru is. And in Team Cymru, 1337 Services GmbH doesn't exist.

Chapter 2: The Company Behind the Hash

Hamburg's Handelsregister (commercial register) entry HRB 164175 reveals a standard German GmbH (limited liability company):

FieldValue
Company1337 Services GmbH
CourtAmtsgericht Hamburg
RegistrationHRB 164175
AddressLudwig-Erhard-Str. 18, Hamburg
DirectorsFlorian Marzahl, Finn Alexander Grimpe
RIPE OrgORG-SG394-RIPE
ASN Allocated2021-10-28

The name itself โ€” 1337 โ€” is leetspeak for "elite," a term from hacking subculture. This is not a name chosen by a conventional hosting company. It's a signal to a specific audience: people who understand the reference are the intended customers.

The address is verifiable. The directors are real people with German tax IDs. The company pays its RIPE NCC membership fees. On paper, everything is legitimate. The question is never whether the company exists โ€” it clearly does. The question is what the company enables.

โš ๏ธ Critical Attribution: The Forum Operators

Krebs on Security and Intel 471 have confirmed what the corporate filings don't say: Florian Marzahl is "FlorainN" and "StarkRDP" โ€” the administrator of Cracked, a cybercrime forum with 4 million users and $4 million in revenue. Finn Alexander Grimpe is "Finndev" โ€” the founder and owner of Nulled, a forum with 5 million users generating $1 million per year.

Both forums were seized in Operation Talent (January 2025). The hosting company they built to serve those forums was not.

Grimpe's digital footprint extends further: email f.grimpe@gmail.com was registered at Raidforums (FBI-seized 2022), vDOS (DDoS-for-hire, shut down 2016), and used to register nulled.lol and nulled.it. His personal site finn.lu (archived 2015) hosted cracked software and game cheating tools. He is also alleged to own Shoppy.gg (Shoppy Ecommerce Ltd, registered in Israel) โ€” an e-commerce platform catering to cybercrime forum users.

This is not a hosting company that happens to have criminal customers. The hosting company was built by cybercriminals to serve cybercriminals.

The Virtual Office

The company's registered address โ€” Ludwig-Erhard-Str. 18, 20459 Hamburg โ€” is BZ Business Center, a company that explicitly offers "Virtuelles Bรผro in Hamburg am Michel" (virtual office). For a monthly fee, they provide a legally serviceable business address (Ladungsfรคhige Geschรคftsadresse), mail forwarding, and phone service. 1337 Services GmbH has no real office, no employees, and no physical presence in Germany.

A RIPE NOC phone number (+4941218302498) uses area code 04121 โ€” Elmshorn, a town 25km northwest of Hamburg. This may indicate the real location of the operators, but it could equally be a VoIP number.

The 2019 Anomaly

IP block 2.58.56.0/24 carries the netname DE-1337SERVICES-20190321. That embedded date โ€” March 21, 2019 โ€” predates the company's incorporation by approximately 2.5 years. The individuals were acquiring or controlling IP space before the formal company existed. The GmbH was not created to start a hosting business. It was created to formalize one that was already running.

Chapter 3: rdp.sh โ€” The Commercial Brand

The public-facing brand is rdp.sh. The website's JSON-LD structured data confirms the connection:

{
  "@context": "https://schema.org",
  "@type": "Organization",
  "legalName": "1337 Services GmbH",
  "address": {
    "streetAddress": "Ludwig-Erhard-Str. 18",
    "addressLocality": "Hamburg",
    "addressCountry": "DE"
  }
}

The product lineup tells you what market rdp.sh serves:

ProductDescriptionStarting Price
Windows RDPRemote Desktop servers, pre-installed Windowsโ‚ฌ4.99/mo
Linux KVM VPSFull root access, custom ISO supportโ‚ฌ2.99/mo
Dedicated ServersBare metal, DDoS protection includedโ‚ฌ49/mo

Three features define the service:

  1. Anonymous registration โ€” no identity verification required
  2. 20+ cryptocurrencies accepted โ€” including Monero (XMR), which is specifically designed to prevent transaction tracing
  3. DDoS protection included โ€” customers won't lose their servers when targets fight back

This is not "hosting that happens to accept crypto." This is infrastructure specifically designed for users who need anonymity. The DDoS protection is the tell โ€” legitimate hosting customers rarely need it. People whose activities provoke retaliatory DDoS attacks do.

Chapter 4: The Three Maintainer Layers

RIPE NCC organizes IP space through "maintainer" objects โ€” administrative entities responsible for specific address blocks. AS210558's 32 tracked IPs are distributed across three maintainers, each in a different country:

MaintainerCountryIPsAvg ThreatAvg AbuseRole
PREFIXBROKER-MNT๐Ÿ‡ณ๐Ÿ‡ฑ Netherlands233881IP brokerage intermediary
SERVPERSO-MNT๐Ÿ‡ง๐Ÿ‡ช Belgium53299Belgian entity, predates 1337 Services
RIPE-NCC-HM-MNT๐Ÿ‡ฉ๐Ÿ‡ช Germany425100RIPE direct allocation

This structure creates a specific effect: abuse reports route to intermediaries, not to the operator.

If you receive an attack from 45.154.98.153 (SERVPERSO-maintained), your abuse report goes to a Belgian entity in Battice. If you're attacked from 192.159.99.79 (PREFIXBROKER-maintained), your report goes to a Dutch IP broker. Neither of these entities operates the server โ€” they just maintain the RIPE records for the address space. The actual server operator, 1337 Services in Hamburg, is two administrative hops removed from the abuse complaint.

The Abuse Report Chain

Victim โ†’ sends abuse report โ†’ RIPE whois says PREFIXBROKER-MNT โ†’ abuse@ goes to Prefix Broker BV (NL) โ†’ who must forward to 1337 Services GmbH (DE) โ†’ who may or may not act on it.

Each hop introduces delay, jurisdictional friction, and plausible deniability. A report that would reach a normal hosting company in hours may take weeks through this chain โ€” if it arrives at all.

The Abuse Handler: Prefix Broker BV

RIPE records reveal an additional layer: Prefix Broker BV, operated by Wessel Sandkuijl from Heiloo, Netherlands (RIPE handle WS4858-RIPE). Sandkuijl's PREFIXBROKER-MNT is not just the maintainer of 23 IP blocks โ€” it also controls SGAH10-RIPE, the official "1337 Services GmbH abuse handling" role object.

This means a Dutch IP broker directly controls where abuse reports for a German bulletproof host are routed. Reports about traffic from servers possibly in Poland, the United States, or Belgium go first to Heiloo, Netherlands, then (perhaps) to Hamburg, Germany, to a virtual office that forwards mail. Maximum jurisdictional fragmentation, minimum accountability.

The SERVPERSO connection is particularly interesting. SERVPERSO Systems was created on 2021-04-16 โ€” six months before AS210558 was allocated to 1337 Services (2021-10-28). The Belgian entity was established first. The German ASN came after. This timeline suggests planning: the intermediary layer was set up before the core infrastructure existed.

Chapter 5: The Geography That Lies

Geolocation databases disagree on where AS210558's IPs are located. This is not normal. For most hosting companies, all sources agree within one country. For 1337 Services, we found 11 distinct country-combination patterns across just 32 IPs:

PatternAbuseIPDBCymru (BGP)RDAP (Reg)Count
A๐Ÿ‡ต๐Ÿ‡ฑ PL๐Ÿ‡ณ๐Ÿ‡ฑ NL๐Ÿ‡ต๐Ÿ‡ฑ PL6 IPs
B๐Ÿ‡ต๐Ÿ‡ฑ PL๐Ÿ‡ณ๐Ÿ‡ฑ NL๐Ÿ‡ฉ๐Ÿ‡ช DE5 IPs
C๐Ÿ‡บ๐Ÿ‡ธ US๐Ÿ‡ณ๐Ÿ‡ฑ NL๐Ÿ‡บ๐Ÿ‡ธ US4 IPs
D๐Ÿ‡ณ๐Ÿ‡ฑ NL๐Ÿ‡ณ๐Ÿ‡ฑ NL๐Ÿ‡ฉ๐Ÿ‡ช DE3 IPs
E๐Ÿ‡ฉ๐Ÿ‡ช DE๐Ÿ‡ง๐Ÿ‡ช BE๐Ÿ‡ฉ๐Ÿ‡ช DE3 IPs
Fโ€“KVariousNL/BE/DEVarious11 IPs

The key pattern: Cymru (BGP routing) consistently shows NL, BE, or DE โ€” the actual physical path the packets take. But RDAP (registration records) and AbuseIPDB (community reporting) show PL, US, and other countries โ€” where the IPs claim to be.

This divergence is not accidental. BGP routing cannot lie โ€” packets physically traverse specific networks and the path is observable. But registration records and geolocation databases can be manipulated through:

  • Registering IP blocks with misleading country codes in RIPE objects
  • Publishing geofeed files that claim non-European locations for European-routed IPs
  • Using intermediary maintainers in different countries to fragment the paper trail

The effect: a Polish CERT investigating abuse from "Polish" IPs finds they're actually routed through the Netherlands. A US victim tracing an "American" IP discovers the registration is German. Jurisdiction fragments. Nobody's responsible.

Chapter 6: Operation Talent โ€” What They Seized and What They Didn't

On January 29, 2025, a joint operation by the FBI, DOJ, Europol, BKA, and Dutch National Police seized several cybercrime platforms. The DOJ press release lists the seized domains:

Seized Domains:
- cracked.io (cybercrime forum, 4M users)
- nulled.to (cybercrime forum, 5M users)
- starkrdp.io (RDP hosting reseller)
- mysellix.io (digital goods marketplace)
- sellix.io (digital goods marketplace)

StarkRDP was a reseller on rdp.sh's infrastructure. It sold pre-configured Windows RDP access to customers โ€” the classic tool for anonymized network access, credential testing, and fraud operations. StarkRDP didn't own the servers. It resold 1337 Services GmbH's infrastructure under its own brand.

The seizure took down the reseller. The backend โ€” rdp.sh, AS210558, 1337 Services GmbH, and all 50 IPv4 prefixes โ€” continued operating without interruption. The geofeed, updated after the seizure, still reads:

# 1337 Services GmbH - www.rdp.sh - Geofeed
# Generated: [post-seizure date]
45.94.31.0/24,DE,DE-HH,Hamburg,
45.138.16.0/24,PL,PL-MZ,Mazowieckie,
45.141.215.0/24,PL,PL-MZ,Mazowieckie,
...

The Backend Survived

Two possible explanations:

1. Jurisdictional gap: The operation was led by US and Dutch authorities. 1337 Services is a German GmbH. Seizing the German backend may have required a separate BKA warrant that was not part of Operation Talent's scope.

2. Strategic choice: Investigators may have deliberately left the backend operational to monitor other resellers and customers using the same infrastructure. Taking down the reseller but leaving the hosting platform intact is a known law enforcement technique for mapping criminal networks.

Either way, the infrastructure that enabled StarkRDP continues to enable others.

Post-Seizure: Business as Usual

In the 18 months since Operation Talent, the operators have not slowed down:

  • RIPE org record modified: June 2, 2026 (18 days ago)
  • PeeringDB entry updated: February 19, 2025 (3 weeks after seizure)
  • Geofeed refreshed: April 15, 2025
  • RIPE aut-num v6: January 22, 2026 (likely when the SHA1 hash was added)

Marzahl posted on Telegram that StarkRDP "has always been operating by the law" and announced they would restart under a new name with existing customer accounts transferred. The backend infrastructure was never interrupted.

Chapter 7: The Ghost IPs

Our threat intelligence platform tracks 32 IPs on AS210558. Every single one has zero honeypot hits โ€” they never attacked our infrastructure directly. Yet their average AbuseIPDB score is 88 out of 100, with 11 IPs scoring a perfect 100%.

These are ghost IPs โ€” infrastructure that appears in third-party abuse reports, entity links, and enrichment databases but never touches our sensors. This pattern is characteristic of hosting infrastructure rather than attack infrastructure. The IPs don't attack; they host the machines that attack.

Spamhaus DROP: Half the Network Blocklisted

Of 22 currently announced IPv4 /24 prefixes, 11 are on the Spamhaus DROP list โ€” the most authoritative blocklist on the internet, reserved for networks with "no legitimate use." SBL reference numbers range from 682998 to 697646, showing progressive listing over time:

2.58.56.0/24   โ†’ SBL696366    45.80.158.0/24  โ†’ SBL696368
45.83.28.0/24  โ†’ SBL696369    45.83.31.0/24   โ†’ SBL697646
45.88.186.0/24 โ†’ SBL682998    45.92.1.0/24    โ†’ SBL696370
45.94.31.0/24  โ†’ SBL696372    45.138.16.0/24  โ†’ SBL687508
45.141.215.0/24โ†’ SBL682999    45.152.149.0/24 โ†’ SBL687509
45.154.98.0/24 โ†’ SBL687510

When half your routing table is on Spamhaus DROP, the network is the abuse. Not customers misusing a platform โ€” the platform itself is the abuse vector.

32
IPs tracked on AS210558
0
Direct honeypot hits
88
Average abuse score (/100)
50
IPv4 prefixes (PeeringDB)
11
BGP upstream peers
3
Maintainer layers

The SERVPERSO-MNT block (45.154.98.0/24) is the most abused: all 5 tracked IPs score 99-100% on AbuseIPDB. These are the IPs most frequently reported for abuse โ€” and they route to a Belgian intermediary who has no obligation to act on abuse reports directed at a German company's customers.

Chapter 8: The Upstream Network

AS210558 doesn't exist in isolation. Its BGP sessions connect it to the global internet through 11 upstream providers:

ASNNameTypeSignificance
AS16276OVH SASTier-2 cloudMajor transit provider, legitimacy signal
AS3257GTT CommunicationsTier-1 carrierGlobal backbone, premium transit
AS7922ComcastTier-1 ISPUS eyeball network, unusual for EU hosting
AS41745โ€”TransitEuropean transit
AS215224โ€”TransitSmall transit provider
AS200730โ€”TransitEuropean peer
AS203144โ€”TransitEuropean peer
AS211484โ€”TransitSmall provider
AS34224NeterraTransitBulgarian carrier
AS210644โ€”TransitSmall provider
AS61125โ€”TransitSmall provider

ERA-IX: The Boutique Exchange

Rather than peering at AMS-IX or DE-CIX โ€” the two largest internet exchange points in Europe โ€” 1337 Services peers exclusively at ERA-IX Amsterdam, a small privately-owned IXP launched mid-2022. Their port: 200 Gbps. Connected 2023-10-29. Choosing a boutique exchange over the majors reduces operational visibility and the likelihood of proactive abuse monitoring that larger IXPs increasingly perform.

The presence of GTT (Tier-1) and OVH (Tier-2) as upstream providers means 1337 Services has legitimate peering agreements with major carriers. This is not a fly-by-night operation that will disappear when upstream providers get abuse complaints. It has contractual relationships with some of the largest networks on the planet.

The Comcast peering is unusual โ€” US eyeball networks rarely peer with small European hosting companies. This may relate to the US-geolocated IPs in the AS210558 range (124.198.x.x and 192.159.99.x blocks).

Chapter 9: The Tor Layer

Shodan data reveals port 9001 โ€” the standard Tor relay ORPort โ€” running on multiple AS210558 IPs. Port 9100 (Prometheus node_exporter) appears alongside, indicating centralized monitoring of the Tor relay infrastructure.

This isn't surprising. As we'll explore in later installments of this series, AS210558 hosts Tor exit nodes operated by multiple independent relay operators โ€” including the 2cb.li network (49+ relays), which routes an estimated 1-3% of all Tor exit traffic through 1337 Services infrastructure.

The Tor relays are not run by 1337 Services itself. They're run by customers who rent VPS instances on rdp.sh and deploy Tor relay software. But the choice of hosting provider is not random โ€” operators running Tor exit nodes need hosting that won't shut them down when abuse reports arrive. rdp.sh's architecture (anonymous registration, crypto payment, three-layer abuse report routing) is purpose-built for exactly this type of customer.

What Comes Next

The SHA1 mask is the first layer. Beneath it sits a structure designed from the ground up for one purpose: making it as difficult as possible to connect abusive internet activity to the infrastructure that enables it.

In Part B โ€” The Belgian Precursor, we follow the SERVPERSO-MNT thread: a Belgian entity created six months before 1337 Services' ASN was even allocated. Was it infrastructure preparation? An earlier attempt? Or something else entirely?

Next: Part B โ€” The Belgian Precursor: The SERVPERSO trail leads to Battice, Belgium โ€” and a timeline that suggests the abuse report routing was designed before the hosting platform existed.

Methodology & Sources

This investigation combines first-party threat intelligence platform data (32 IPs on AS210558, enriched via 10+ OSINT sources) with RIPE NCC registry data, PeeringDB, Team Cymru's IP-to-ASN service, Shodan, AbuseIPDB, and DOJ press releases. Geographic discrepancy analysis uses multi-source comparison (AbuseIPDB geolocation vs. Cymru BGP routing vs. RDAP registration). Corporate records from Hamburg Handelsregister (HRB 164175).

Confidence: HIGH โ€” All factual claims are multi-source verified. The SHA1 hash interpretation (deliberate vs. artifact) is explicitly flagged as uncertain.

Cross-references: TI-2026-026C (German gray zone hosting), TI-2026-024A (Offshore bulletproof), TI-2026-021C (Architecture of impunity).

Series: This is Part A of "The Anonymity Factory" โ€” a 10-part investigation into how a small German-Belgian operation became backbone infrastructure for ~3% of Tor exit traffic and an unknown share of bulletproof hosting services. Parts B through J trace the intermediaries, the relay operators, the Saint Kitts shells, and the questions that Operation Talent left unanswered.

โš  Personal capacity. Research published independently โ€” not reflecting employer views. Derived from passive observation of attacks against personal infrastructure. Full disclaimer โ†’
โ† Previous The Anonymity Factory โ€” 1 / 12 Next โ†’