๐Ÿ”ด CRITICAL โ€” Bulletproof Hosting ยท Multi-Jurisdiction Shell Network ยท Panama Papers ยท Sanctions Evasion ยท IP Reputation Laundering

๐Ÿ‘ป TI-2026-026A โ€” The Phantom ASN: PIO-Hosting's Three-Continent Shell Game

TI-2026-026A ยท Series 1 of 6 ยท Confidence: HIGH ยท Sources: SSH Honeypot, UK Companies House, German Handelsregister, RIPE NCC, AFRINIC, ARIN, ICIJ Offshore Leaks, BGP Data, Active Recon, AbuseIPDB, Shodan, OTX, VirusTotal, GreyNoise, Passive DNS, CAIDA/UCSD Research, Cloudflare Radar

๐Ÿ“‹ Executive Summary

We run a honeypot. Most attacks are boring โ€” automated scans, default credentials, commodity botnets. But some IPs couldn't agree on what country they were from. One IP โ€” 102.129.200.117 โ€” simultaneously claimed to be in the Netherlands (geolocation), South Africa (BGP prefix origin), the United States (RDAP registrant), and the United Kingdom (ASN registration). That is not a database glitch. That is jurisdictional engineering.

Following that single discrepancy led to the discovery of a bulletproof hosting empire spanning 7+ jurisdictions, built on shell companies in the British Virgin Islands, linked to the Panama Papers through a professional nominee director, potentially facilitating Iranian sanctions evasion through German transit, and โ€” most critically โ€” connected to IPXO, a $55 million "legitimate" IP address marketplace whose founder sits on the RIPE NCC General Meeting Committee.

Two ASNs โ€” AS198584 (PIO-Hosting GmbH, Germany) and AS208949 (HBING LIMITED, UK) โ€” were allocated exactly one month apart in 2023. Both immediately began announcing IP blocks from countries they have no presence in. Both serve the same upstream customer. Both host confirmed botnet command-and-control infrastructure. Together they form a single distributed operation designed so that no law enforcement agency in any single jurisdiction can see โ€” or act on โ€” the full picture.

AS198584 PIO-Hosting AS208949 HBING Panama Papers 7 Jurisdictions Bulletproof Risk 95.26/100 Hitrow Botnet C2 IPXO / Vincentas Grinius BVI Shell Companies Iranian LIR Transit 628-IP Campaign
7+jurisdictions in one operation
95.26bulletproof risk score /100
628IPs in coordinated campaign
18actors identified
3days Olga INAG was director
$55MIPXO revenue

๐ŸŒ Chapter 1: The IP That Couldn't Decide Where It Lived

IP address 102.129.200.117 hit our honeypot running Hitrow 1.1.43 โ€” a known botnet management panel โ€” on ports 80 and 8080. AbuseIPDB confidence: 100/100. That alone is unremarkable; we see C2 infrastructure daily.

What made this IP extraordinary was the geographic disagreement across intelligence sources:

SourceCountryExplanation
MaxMind/Geolocation๐Ÿ‡ณ๐Ÿ‡ฑ NetherlandsPhysical server location
BGP Prefix Origin๐Ÿ‡ฟ๐Ÿ‡ฆ South Africa102.129.200.0/24 is AFRINIC space
RDAP Registrant๐Ÿ‡บ๐Ÿ‡ธ United StatesIPXO LLC, registered in Texas
ASN Registration๐Ÿ‡ฌ๐Ÿ‡ง United KingdomAS208949 = HBING LIMITED, Suffolk

Four countries. One IP. This pattern repeated across 25 IPs with threat scores above 75. The same two ASNs kept appearing.

โ“ Why would a single IP address need to exist in four jurisdictions simultaneously?

Because jurisdiction is protection. If the server is in the Netherlands, Dutch police need a warrant. If the IP block is South African, AFRINIC handles abuse. If the registrant is American, the FBI has authority. If the ASN is British, OFCOM could investigate. But when ALL of these apply simultaneously, each authority assumes it's someone else's problem. This isn't a bug โ€” it's the entire business model.

๐Ÿ“Ž Sources: AbuseIPDB ยท Hurricane Electric BGP ยท Honeypot Active Recon (Tor-routed)

๐Ÿข Chapter 2: Two ASNs, One Month Apart

The two autonomous systems at the center of this investigation were allocated in rapid succession:

ASNCompanyCountryAllocatedPrefixes
AS208949HBING LIMITED๐Ÿ‡ฌ๐Ÿ‡ง UK11 April 202311 (3,072 IPs)
AS198584PIO-Hosting GmbH๐Ÿ‡ฉ๐Ÿ‡ช Germany11 May 202328 (7,000+ IPs)

Both immediately began announcing IP space from countries where they have no physical presence. HBING โ€” a "retail store" registered at a residential address in rural Suffolk โ€” announced blocks from Poland, Belgium, the United States, South Africa, Ukraine, Romania, and Russia. PIO-Hosting โ€” registered at a residential address in Mรถnchengladbach โ€” announced blocks from five Regional Internet Registries spanning every continent.

The critical link: Internet Utilities Europe and Asia Limited (UK company #12540160, director: Vincentas Grinius) routes via both ASNs using the RIPE maintainer netutils-mnt. This proves they serve the same customer ecosystem.

โ“ What legitimate business acquires two ASNs in two different countries within 30 days?

Redundancy is legitimate. But redundancy between a "UK retail store" and a "German hosting company" that share no public corporate relationship? That's operational separation designed to survive the takedown of either entity. If law enforcement seizes one ASN, the other continues operating. One month gives enough time to ensure the first is functioning before activating the backup.

๐Ÿ“Ž Sources: bgp.he.net/AS208949 ยท bgp.he.net/AS198584 ยท UK Companies House #13836998

๐ŸŽญ Chapter 3: The Cast of Characters

HBING LIMITED was incorporated on 10 January 2022. Its first director was Olga INAG โ€” Russian nationality, date of birth October 1991. She resigned three days later on 13 January 2022. That same day, Cihan KAPLAN โ€” Turkish nationality, date of birth June 1990 โ€” was appointed. This is a textbook nominee director setup: a formation agent provides a body for Day 1 paperwork, then the actual controller takes over.

Kaplan's identity was verified by E-SIRKET LTD โ€” literally "e-company" in Turkish โ€” a formation agent. His only UK directorship is HBING. The company's RIPE registration uses the address 124 City Road, London, EC1V 2NX โ€” one of the UK's most notorious virtual office addresses, used by thousands of shell companies.

On the German side, PIO-Hosting GmbH shares phone number +49 2451 9949570 with XSServer GmbH (Marcel Edler, Rene Spellerberg, HRB 21403) and SkyLink Data Center BV (Dirk Bellgart, Netherlands). Three legal entities. One phone number. One operation.

EntityJurisdictionRoleRed Flag
HBING LIMITED๐Ÿ‡ฌ๐Ÿ‡ง UKASN holderResidential address, retail SIC code, freemailer abuse contact
PIO-Hosting GmbH๐Ÿ‡ฉ๐Ÿ‡ช GermanyASN holderResidential address, shared phone with 2 other entities
lir-vg-itweb-1-MNT๐Ÿ‡ป๐Ÿ‡ฌ BVIIP registrantOffshore shell, Panama Papers-linked contact
IPXO UAB๐Ÿ‡ฑ๐Ÿ‡น LithuaniaIP marketplaceRoutes through both bulletproof ASNs
Host Sailor Ltd๐Ÿ‡ฆ๐Ÿ‡ช DubaiRIPE sponsorSponsored HBING's RIPE membership
IPv4 Superhub Ltd๐Ÿ‡ญ๐Ÿ‡ฐ Hong KongReputation launderingExplicit Spamhaus delisting service
Guosheng IDC๐Ÿ‡จ๐Ÿ‡ณ ChinaLIR frontDead domain, Gmail contact
Internet Utilities๐Ÿ‡ธ๐Ÿ‡ฎ Slovenia / ๐Ÿ‡บ๐Ÿ‡ธ USTransit customerRoutes via BOTH ASNs = proof of linkage

๐Ÿ“– Read Between the Lines

  • A Russian woman is director for 72 hours, then a Turkish man takes over, verified by a Turkish formation agent โ€” this is not organic company formation. This is a service.
  • Three German/Dutch entities share one phone number but maintain separate legal existence. The separation serves one purpose: liability compartmentalization.
  • HBING's SIC code includes 47190 โ€” "Other retail sale in non-specialised stores." A retail store that operates bulletproof hosting infrastructure across 11 prefixes. The absurdity is the disguise.
  • The RIPE abuse email hbinglimited@mail.com uses mail.com โ€” a generic freemailer. No legitimate hosting company uses a freemailer for abuse handling. This address exists to receive and ignore complaints.

๐Ÿ“Ž Sources: Companies House Officers ยท German Handelsregister HRB 20998, 21403 ยท RIPE DB

๐Ÿ๏ธ Chapter 4: The Panama Papers Connection

Three IP prefixes announced by AS208949 list a contact name: "Rea Ketty". Full name: Rea Ketty Yolande BARREAU. This name appears in the ICIJ Offshore Leaks Database as node #12169229 โ€” connected to Seychelles and BVI offshore structures documented in the Panama Papers.

BARREAU is a professional nominee โ€” a person whose name appears on corporate documents for a fee, shielding the actual beneficial owner. The BVI RIPE maintainer lir-vg-itweb-1-MNT โ€” which registers African IP blocks used by HBING โ€” operates from a British Virgin Islands entity with this same network of contacts.

The chain: Dubai (Host Sailor sponsors RIPE membership) โ†’ BVI (lir-vg-itweb-1-MNT holds IP registrations) โ†’ Seychelles (BARREAU's offshore structures) โ†’ UK (HBING announces the BGP routes) โ†’ Netherlands (servers physically located) โ†’ Germany (backup transit via PIO).

โ“ If "Rea Ketty" is a professional nominee, who is the actual beneficial owner of these IP blocks?

That is the question the offshore chain is designed to make unanswerable. Professional nominees exist precisely to absorb this question. But the operational evidence tells us: whoever controls the BGP announcements โ€” i.e., whoever has router access at HBING's upstream (NovoServe BV, AS24875) โ€” controls what these IPs do. The corporate owner is a fiction. The operational owner is whoever holds the router credentials.

โ“ Why do Panama Papers structures appear in the IP address registration system?

Because IP addresses are assets. IPv4 addresses trade at $30-60 each. A /16 block (65,536 addresses) is worth $2-4 million. The same offshore structures designed to hide real estate, bank accounts, and shell companies now hide internet infrastructure ownership. RIPE NCC โ€” unlike banks โ€” has no beneficial ownership verification requirement. A BVI shell with a nominee director can register IP space exactly as easily as it opens a Panamanian bank account.

๐Ÿ“Ž Sources: ICIJ Offshore Leaks Node #12169229 ยท RIPE DB lir-vg-itweb-1-MNT

๐Ÿ’ฐ Chapter 5: The $55 Million Question

IPXO UAB, co-founded by Vincentas Grinius, is a Lithuanian IP address leasing marketplace claiming 14 million+ IPs under management and $55 million in revenue. It's listed on Inc. 5000 Europe. Grinius sits on the RIPE NCC General Meeting Committee โ€” the body that governs European internet resource policy.

IPXO's entity Internet Utilities Europe and Asia Limited (UK company #12540160) uses the RIPE maintainer netutils-mnt to route ARIN-allocated IP blocks through both AS198584 (PIO-Hosting) and AS208949 (HBING). A separate entity, Internet Utilities NA LLC (Delaware), routes additional American IP space through PIO.

A 2024 research paper by CAIDA/UCSD โ€” "Sublet Your Subnet: Exploring the IP Address Sub-Delegation Ecosystem" โ€” specifically identifies IPXO as an enabler of bulletproof hosting through its IP leasing model.

โ“ Why does a legitimate $55M company need bulletproof transit rated 95/100 dangerous?

IPXO's model is IP monetization โ€” it leases unused IP space from holders who aren't using it. The problem: once leased, IPXO has limited control over what those IPs are used for. But the CAIDA paper argues it's not merely passive negligence โ€” the economic incentive is to not look too closely, because every IP under management generates revenue. The bulletproof infrastructure isn't a bug; it's a feature that maximizes the pool of customers willing to pay premium rates for "no questions asked" IP space.

โ“ What does it mean when the regulator has the regulated on its committee?

Vincentas Grinius sits on RIPE NCC's General Meeting Committee. RIPE NCC allocates IP resources and sets policy for European internet infrastructure. Grinius's company routes through infrastructure classified as bulletproof with the highest possible risk score. This is the fox in the henhouse โ€” or at minimum, a structural conflict of interest that means the person enabling bulletproof hosting has influence over the policies designed to prevent it.

๐Ÿ“Ž Sources: IPXO.com ยท UK Companies House #12540160 ยท CAIDA/UCSD 2024 "Sublet Your Subnet" ยท RIPE NCC General Meeting

๐Ÿ‡ฎ๐Ÿ‡ท Chapter 6: The Iranian Question

In June 2026, four Iranian Local Internet Registries (LIRs) were added to AS198584's transit. Iranian telecommunications infrastructure is subject to EU Council Regulation 267/2012 โ€” sanctions specifically targeting Iran's ability to conduct surveillance and censorship via internet infrastructure.

PIO-Hosting GmbH is a German company. Germany is an EU member state. If PIO provides transit services to Iranian entities that are sanctioned โ€” or to entities acting on behalf of sanctioned bodies like the IRGC โ€” this constitutes a potential violation of EU sanctions law carrying criminal penalties.

โ“ Is routing Iranian traffic through German infrastructure designed to evade sanctions?

The arrangement provides plausible deniability at every layer. PIO doesn't "serve Iran directly" โ€” it provides transit to a LIR that happens to be Iranian. The LIR doesn't "work with sanctioned entities" โ€” it provides internet services to Iranian end users. Each layer's defense is: "we can't control what our customers' customers do." But the structural effect is identical to direct provision: Iranian traffic flows through European infrastructure, bypassing the sanctions regime's intent.

๐Ÿ“Ž Sources: RIPE NCC Route Announcements (June 2026) ยท EU Council Regulation 267/2012

๐Ÿงน Chapter 7: The Reputation Laundromat

IPv4 Superhub Limited (Hong Kong) operates through PIO-Hosting's transit. Its service is explicit: getting IP addresses removed from Spamhaus blacklists. This is "IP reputation laundering" โ€” taking addresses that have been flagged for abuse, cycling them through new announcements, and presenting them as clean for resale.

The economics: a blacklisted /24 block (256 IPs) is worth near-zero. A clean /24 is worth $7,000-15,000. The reputation laundering service transforms toxic assets into saleable ones โ€” for a fee โ€” using PIO-Hosting as the technical enabler.

๐Ÿ“– Read Between the Lines

  • HBING has 56 legitimate users on 3,072 IP addresses according to Cloudflare Radar. That's 98.2% of the address space with no legitimate traffic. Those addresses are inventory โ€” products being prepared for market.
  • The pipeline: IPs get abused โ†’ blacklisted โ†’ "cleaned" by IPv4 Superhub โ†’ relisted as clean โ†’ sold through IPXO โ†’ new customer abuses them โ†’ cycle repeats. Every stage generates revenue for a different entity.
  • PIO-Hosting's 28 prefixes from 5 Regional Internet Registries aren't "hosting customers." They're a portfolio โ€” IP assets in various stages of the abuse-and-clean cycle.

๐Ÿ“Ž Sources: Cloudflare Radar AS208949 ยท IPv4 Superhub website (archived) ยท Spamhaus DROP/EDROP lists

๐Ÿ—บ๏ธ Chapter 8: The Network Map

The full structure, as assembled from corporate registries, BGP data, RIPE WHOIS, and ICIJ records:

LayerEntityJurisdictionFunction
IP MarketplaceIPXO UAB / Vincentas Grinius๐Ÿ‡ฑ๐Ÿ‡น Lithuania / ๐Ÿ‡บ๐Ÿ‡ธ TexasIP leasing, monetization
Transit (ARIN)Internet Utilities NA LLC๐Ÿ‡บ๐Ÿ‡ธ DelawareAmerican IP routing
Transit (RIPE)Internet Utilities EU/Asia Ltd๐Ÿ‡ฌ๐Ÿ‡ง UK / ๐Ÿ‡ธ๐Ÿ‡ฎ SloveniaEuropean IP routing
ASN OperationsPIO-Hosting GmbH (= XSServer = SkyLink)๐Ÿ‡ฉ๐Ÿ‡ช Germany / ๐Ÿ‡ณ๐Ÿ‡ฑ NetherlandsBGP announcements, hosting
ASN OperationsHBING LIMITED๐Ÿ‡ฌ๐Ÿ‡ง UK (virtual)BGP announcements, bulletproof
Offshore Registrationlir-vg-itweb-1-MNT๐Ÿ‡ป๐Ÿ‡ฌ BVIIP block ownership
Nominee LayerRea Ketty Yolande BARREAU๐Ÿ‡ธ๐Ÿ‡จ SeychellesBeneficial owner concealment
RIPE SponsorshipHost Sailor Ltd๐Ÿ‡ฆ๐Ÿ‡ช DubaiRIPE membership access
Reputation LaunderingIPv4 Superhub Ltd๐Ÿ‡ญ๐Ÿ‡ฐ Hong KongSpamhaus delisting
Sub-allocationZeXoTeK IT-Services GmbH๐Ÿ‡ฉ๐Ÿ‡ช GermanyC2 hosting on 176.65.x.x
Ghost LIRGuosheng IDC๐Ÿ‡จ๐Ÿ‡ณ ChinaAfrican IP via dead-domain entity
Formation ServicesE-SIRKET LTD / 123LIR๐Ÿ‡น๐Ÿ‡ท Turkey / ๐Ÿ‡ฌ๐Ÿ‡ง UKCompany + ASN provisioning

โ“ Is this one organization or many?

Legally: many. Operationally: one. The proof is netutils-mnt โ€” a single RIPE maintainer object routes through both ASNs. The proof is the shared phone number linking PIO/XSServer/SkyLink. The proof is the one-month ASN allocation gap. The proof is the 628-IP campaign using identical SSH client libraries across both networks. Every piece of corporate separation dissolves under operational analysis. What remains is a single distributed infrastructure hiding behind 12+ legal entities across 8+ jurisdictions.

๐Ÿ”ฌ What This Means

This is not a criminal hosting provider. It is an industrialized infrastructure for making malicious activity jurisdictionally invisible. The geographic discrepancy that started this investigation is not a side effect โ€” it is the product. When every database disagrees on what country an IP belongs to, the system is working as designed.

The enabler ecosystem โ€” formation agents, nominee directors, offshore shells, IP marketplaces, reputation laundering services โ€” is not illegal in any single jurisdiction. Each entity operates within the letter of its local law. But their combined effect is to create infrastructure where botnet C2 panels run openly, where 628-node scanning campaigns launch daily, and where no single regulator can assemble enough of the picture to act.

The remaining dossiers in this series will examine each layer in detail: the bulletproof island (HBING), the German gray zone (PIO/XSServer), the IP marketplace (IPXO), the offshore chain (Panama Papers), and the sanctions question (Iranian transit).

๐Ÿ”ฌ Methodology

This investigation originated from automated geographic discrepancy detection on our SSH honeypot โ€” flagging IPs where AbuseIPDB country โ‰  RDAP country โ‰  BGP prefix country. The 25 highest-threat discrepant IPs were clustered by ASN, revealing the PIO-Hosting/HBING nexus. Corporate research used UK Companies House, German Handelsregister, and RIPE NCC databases. Offshore connections were verified through ICIJ Offshore Leaks. BGP routing was confirmed via bgp.he.net, RIPEstat, and Cloudflare Radar. Active reconnaissance was performed via Tor-routed nmap/httpx. All IP threat data comes from our production honeypot intelligence platform (8,000+ tracked IPs, 271K+ entity links).

โš  Personal capacity. Research published independently โ€” not reflecting employer views. Derived from passive observation of attacks against personal infrastructure. Full disclaimer โ†’
โ† Previous The Phantom ASN โ€” 1 / 17 Next โ†’