๐ป TI-2026-026A โ The Phantom ASN: PIO-Hosting's Three-Continent Shell Game
๐ Executive Summary
We run a honeypot. Most attacks are boring โ automated scans, default credentials, commodity botnets. But some IPs couldn't agree on what country they were from. One IP โ 102.129.200.117 โ simultaneously claimed to be in the Netherlands (geolocation), South Africa (BGP prefix origin), the United States (RDAP registrant), and the United Kingdom (ASN registration). That is not a database glitch. That is jurisdictional engineering.
Following that single discrepancy led to the discovery of a bulletproof hosting empire spanning 7+ jurisdictions, built on shell companies in the British Virgin Islands, linked to the Panama Papers through a professional nominee director, potentially facilitating Iranian sanctions evasion through German transit, and โ most critically โ connected to IPXO, a $55 million "legitimate" IP address marketplace whose founder sits on the RIPE NCC General Meeting Committee.
Two ASNs โ AS198584 (PIO-Hosting GmbH, Germany) and AS208949 (HBING LIMITED, UK) โ were allocated exactly one month apart in 2023. Both immediately began announcing IP blocks from countries they have no presence in. Both serve the same upstream customer. Both host confirmed botnet command-and-control infrastructure. Together they form a single distributed operation designed so that no law enforcement agency in any single jurisdiction can see โ or act on โ the full picture.
๐ Chapter 1: The IP That Couldn't Decide Where It Lived
IP address 102.129.200.117 hit our honeypot running Hitrow 1.1.43 โ a known botnet management panel โ on ports 80 and 8080. AbuseIPDB confidence: 100/100. That alone is unremarkable; we see C2 infrastructure daily.
What made this IP extraordinary was the geographic disagreement across intelligence sources:
| Source | Country | Explanation |
|---|---|---|
| MaxMind/Geolocation | ๐ณ๐ฑ Netherlands | Physical server location |
| BGP Prefix Origin | ๐ฟ๐ฆ South Africa | 102.129.200.0/24 is AFRINIC space |
| RDAP Registrant | ๐บ๐ธ United States | IPXO LLC, registered in Texas |
| ASN Registration | ๐ฌ๐ง United Kingdom | AS208949 = HBING LIMITED, Suffolk |
Four countries. One IP. This pattern repeated across 25 IPs with threat scores above 75. The same two ASNs kept appearing.
โ Why would a single IP address need to exist in four jurisdictions simultaneously?
Because jurisdiction is protection. If the server is in the Netherlands, Dutch police need a warrant. If the IP block is South African, AFRINIC handles abuse. If the registrant is American, the FBI has authority. If the ASN is British, OFCOM could investigate. But when ALL of these apply simultaneously, each authority assumes it's someone else's problem. This isn't a bug โ it's the entire business model.
๐ Sources: AbuseIPDB ยท Hurricane Electric BGP ยท Honeypot Active Recon (Tor-routed)
๐ข Chapter 2: Two ASNs, One Month Apart
The two autonomous systems at the center of this investigation were allocated in rapid succession:
| ASN | Company | Country | Allocated | Prefixes |
|---|---|---|---|---|
| AS208949 | HBING LIMITED | ๐ฌ๐ง UK | 11 April 2023 | 11 (3,072 IPs) |
| AS198584 | PIO-Hosting GmbH | ๐ฉ๐ช Germany | 11 May 2023 | 28 (7,000+ IPs) |
Both immediately began announcing IP space from countries where they have no physical presence. HBING โ a "retail store" registered at a residential address in rural Suffolk โ announced blocks from Poland, Belgium, the United States, South Africa, Ukraine, Romania, and Russia. PIO-Hosting โ registered at a residential address in Mรถnchengladbach โ announced blocks from five Regional Internet Registries spanning every continent.
The critical link: Internet Utilities Europe and Asia Limited (UK company #12540160, director: Vincentas Grinius) routes via both ASNs using the RIPE maintainer netutils-mnt. This proves they serve the same customer ecosystem.
โ What legitimate business acquires two ASNs in two different countries within 30 days?
Redundancy is legitimate. But redundancy between a "UK retail store" and a "German hosting company" that share no public corporate relationship? That's operational separation designed to survive the takedown of either entity. If law enforcement seizes one ASN, the other continues operating. One month gives enough time to ensure the first is functioning before activating the backup.
๐ Sources: bgp.he.net/AS208949 ยท bgp.he.net/AS198584 ยท UK Companies House #13836998
๐ญ Chapter 3: The Cast of Characters
HBING LIMITED was incorporated on 10 January 2022. Its first director was Olga INAG โ Russian nationality, date of birth October 1991. She resigned three days later on 13 January 2022. That same day, Cihan KAPLAN โ Turkish nationality, date of birth June 1990 โ was appointed. This is a textbook nominee director setup: a formation agent provides a body for Day 1 paperwork, then the actual controller takes over.
Kaplan's identity was verified by E-SIRKET LTD โ literally "e-company" in Turkish โ a formation agent. His only UK directorship is HBING. The company's RIPE registration uses the address 124 City Road, London, EC1V 2NX โ one of the UK's most notorious virtual office addresses, used by thousands of shell companies.
On the German side, PIO-Hosting GmbH shares phone number +49 2451 9949570 with XSServer GmbH (Marcel Edler, Rene Spellerberg, HRB 21403) and SkyLink Data Center BV (Dirk Bellgart, Netherlands). Three legal entities. One phone number. One operation.
| Entity | Jurisdiction | Role | Red Flag |
|---|---|---|---|
| HBING LIMITED | ๐ฌ๐ง UK | ASN holder | Residential address, retail SIC code, freemailer abuse contact |
| PIO-Hosting GmbH | ๐ฉ๐ช Germany | ASN holder | Residential address, shared phone with 2 other entities |
| lir-vg-itweb-1-MNT | ๐ป๐ฌ BVI | IP registrant | Offshore shell, Panama Papers-linked contact |
| IPXO UAB | ๐ฑ๐น Lithuania | IP marketplace | Routes through both bulletproof ASNs |
| Host Sailor Ltd | ๐ฆ๐ช Dubai | RIPE sponsor | Sponsored HBING's RIPE membership |
| IPv4 Superhub Ltd | ๐ญ๐ฐ Hong Kong | Reputation laundering | Explicit Spamhaus delisting service |
| Guosheng IDC | ๐จ๐ณ China | LIR front | Dead domain, Gmail contact |
| Internet Utilities | ๐ธ๐ฎ Slovenia / ๐บ๐ธ US | Transit customer | Routes via BOTH ASNs = proof of linkage |
๐ Read Between the Lines
- A Russian woman is director for 72 hours, then a Turkish man takes over, verified by a Turkish formation agent โ this is not organic company formation. This is a service.
- Three German/Dutch entities share one phone number but maintain separate legal existence. The separation serves one purpose: liability compartmentalization.
- HBING's SIC code includes 47190 โ "Other retail sale in non-specialised stores." A retail store that operates bulletproof hosting infrastructure across 11 prefixes. The absurdity is the disguise.
- The RIPE abuse email
hbinglimited@mail.comuses mail.com โ a generic freemailer. No legitimate hosting company uses a freemailer for abuse handling. This address exists to receive and ignore complaints.
๐ Sources: Companies House Officers ยท German Handelsregister HRB 20998, 21403 ยท RIPE DB
๐๏ธ Chapter 4: The Panama Papers Connection
Three IP prefixes announced by AS208949 list a contact name: "Rea Ketty". Full name: Rea Ketty Yolande BARREAU. This name appears in the ICIJ Offshore Leaks Database as node #12169229 โ connected to Seychelles and BVI offshore structures documented in the Panama Papers.
BARREAU is a professional nominee โ a person whose name appears on corporate documents for a fee, shielding the actual beneficial owner. The BVI RIPE maintainer lir-vg-itweb-1-MNT โ which registers African IP blocks used by HBING โ operates from a British Virgin Islands entity with this same network of contacts.
The chain: Dubai (Host Sailor sponsors RIPE membership) โ BVI (lir-vg-itweb-1-MNT holds IP registrations) โ Seychelles (BARREAU's offshore structures) โ UK (HBING announces the BGP routes) โ Netherlands (servers physically located) โ Germany (backup transit via PIO).
โ If "Rea Ketty" is a professional nominee, who is the actual beneficial owner of these IP blocks?
That is the question the offshore chain is designed to make unanswerable. Professional nominees exist precisely to absorb this question. But the operational evidence tells us: whoever controls the BGP announcements โ i.e., whoever has router access at HBING's upstream (NovoServe BV, AS24875) โ controls what these IPs do. The corporate owner is a fiction. The operational owner is whoever holds the router credentials.
โ Why do Panama Papers structures appear in the IP address registration system?
Because IP addresses are assets. IPv4 addresses trade at $30-60 each. A /16 block (65,536 addresses) is worth $2-4 million. The same offshore structures designed to hide real estate, bank accounts, and shell companies now hide internet infrastructure ownership. RIPE NCC โ unlike banks โ has no beneficial ownership verification requirement. A BVI shell with a nominee director can register IP space exactly as easily as it opens a Panamanian bank account.
๐ Sources: ICIJ Offshore Leaks Node #12169229 ยท RIPE DB lir-vg-itweb-1-MNT
๐ฐ Chapter 5: The $55 Million Question
IPXO UAB, co-founded by Vincentas Grinius, is a Lithuanian IP address leasing marketplace claiming 14 million+ IPs under management and $55 million in revenue. It's listed on Inc. 5000 Europe. Grinius sits on the RIPE NCC General Meeting Committee โ the body that governs European internet resource policy.
IPXO's entity Internet Utilities Europe and Asia Limited (UK company #12540160) uses the RIPE maintainer netutils-mnt to route ARIN-allocated IP blocks through both AS198584 (PIO-Hosting) and AS208949 (HBING). A separate entity, Internet Utilities NA LLC (Delaware), routes additional American IP space through PIO.
A 2024 research paper by CAIDA/UCSD โ "Sublet Your Subnet: Exploring the IP Address Sub-Delegation Ecosystem" โ specifically identifies IPXO as an enabler of bulletproof hosting through its IP leasing model.
โ Why does a legitimate $55M company need bulletproof transit rated 95/100 dangerous?
IPXO's model is IP monetization โ it leases unused IP space from holders who aren't using it. The problem: once leased, IPXO has limited control over what those IPs are used for. But the CAIDA paper argues it's not merely passive negligence โ the economic incentive is to not look too closely, because every IP under management generates revenue. The bulletproof infrastructure isn't a bug; it's a feature that maximizes the pool of customers willing to pay premium rates for "no questions asked" IP space.
โ What does it mean when the regulator has the regulated on its committee?
Vincentas Grinius sits on RIPE NCC's General Meeting Committee. RIPE NCC allocates IP resources and sets policy for European internet infrastructure. Grinius's company routes through infrastructure classified as bulletproof with the highest possible risk score. This is the fox in the henhouse โ or at minimum, a structural conflict of interest that means the person enabling bulletproof hosting has influence over the policies designed to prevent it.
๐ Sources: IPXO.com ยท UK Companies House #12540160 ยท CAIDA/UCSD 2024 "Sublet Your Subnet" ยท RIPE NCC General Meeting
๐ฎ๐ท Chapter 6: The Iranian Question
In June 2026, four Iranian Local Internet Registries (LIRs) were added to AS198584's transit. Iranian telecommunications infrastructure is subject to EU Council Regulation 267/2012 โ sanctions specifically targeting Iran's ability to conduct surveillance and censorship via internet infrastructure.
PIO-Hosting GmbH is a German company. Germany is an EU member state. If PIO provides transit services to Iranian entities that are sanctioned โ or to entities acting on behalf of sanctioned bodies like the IRGC โ this constitutes a potential violation of EU sanctions law carrying criminal penalties.
โ Is routing Iranian traffic through German infrastructure designed to evade sanctions?
The arrangement provides plausible deniability at every layer. PIO doesn't "serve Iran directly" โ it provides transit to a LIR that happens to be Iranian. The LIR doesn't "work with sanctioned entities" โ it provides internet services to Iranian end users. Each layer's defense is: "we can't control what our customers' customers do." But the structural effect is identical to direct provision: Iranian traffic flows through European infrastructure, bypassing the sanctions regime's intent.
๐ Sources: RIPE NCC Route Announcements (June 2026) ยท EU Council Regulation 267/2012
๐งน Chapter 7: The Reputation Laundromat
IPv4 Superhub Limited (Hong Kong) operates through PIO-Hosting's transit. Its service is explicit: getting IP addresses removed from Spamhaus blacklists. This is "IP reputation laundering" โ taking addresses that have been flagged for abuse, cycling them through new announcements, and presenting them as clean for resale.
The economics: a blacklisted /24 block (256 IPs) is worth near-zero. A clean /24 is worth $7,000-15,000. The reputation laundering service transforms toxic assets into saleable ones โ for a fee โ using PIO-Hosting as the technical enabler.
๐ Read Between the Lines
- HBING has 56 legitimate users on 3,072 IP addresses according to Cloudflare Radar. That's 98.2% of the address space with no legitimate traffic. Those addresses are inventory โ products being prepared for market.
- The pipeline: IPs get abused โ blacklisted โ "cleaned" by IPv4 Superhub โ relisted as clean โ sold through IPXO โ new customer abuses them โ cycle repeats. Every stage generates revenue for a different entity.
- PIO-Hosting's 28 prefixes from 5 Regional Internet Registries aren't "hosting customers." They're a portfolio โ IP assets in various stages of the abuse-and-clean cycle.
๐ Sources: Cloudflare Radar AS208949 ยท IPv4 Superhub website (archived) ยท Spamhaus DROP/EDROP lists
๐บ๏ธ Chapter 8: The Network Map
The full structure, as assembled from corporate registries, BGP data, RIPE WHOIS, and ICIJ records:
| Layer | Entity | Jurisdiction | Function |
|---|---|---|---|
| IP Marketplace | IPXO UAB / Vincentas Grinius | ๐ฑ๐น Lithuania / ๐บ๐ธ Texas | IP leasing, monetization |
| Transit (ARIN) | Internet Utilities NA LLC | ๐บ๐ธ Delaware | American IP routing |
| Transit (RIPE) | Internet Utilities EU/Asia Ltd | ๐ฌ๐ง UK / ๐ธ๐ฎ Slovenia | European IP routing |
| ASN Operations | PIO-Hosting GmbH (= XSServer = SkyLink) | ๐ฉ๐ช Germany / ๐ณ๐ฑ Netherlands | BGP announcements, hosting |
| ASN Operations | HBING LIMITED | ๐ฌ๐ง UK (virtual) | BGP announcements, bulletproof |
| Offshore Registration | lir-vg-itweb-1-MNT | ๐ป๐ฌ BVI | IP block ownership |
| Nominee Layer | Rea Ketty Yolande BARREAU | ๐ธ๐จ Seychelles | Beneficial owner concealment |
| RIPE Sponsorship | Host Sailor Ltd | ๐ฆ๐ช Dubai | RIPE membership access |
| Reputation Laundering | IPv4 Superhub Ltd | ๐ญ๐ฐ Hong Kong | Spamhaus delisting |
| Sub-allocation | ZeXoTeK IT-Services GmbH | ๐ฉ๐ช Germany | C2 hosting on 176.65.x.x |
| Ghost LIR | Guosheng IDC | ๐จ๐ณ China | African IP via dead-domain entity |
| Formation Services | E-SIRKET LTD / 123LIR | ๐น๐ท Turkey / ๐ฌ๐ง UK | Company + ASN provisioning |
โ Is this one organization or many?
Legally: many. Operationally: one. The proof is netutils-mnt โ a single RIPE maintainer object routes through both ASNs. The proof is the shared phone number linking PIO/XSServer/SkyLink. The proof is the one-month ASN allocation gap. The proof is the 628-IP campaign using identical SSH client libraries across both networks. Every piece of corporate separation dissolves under operational analysis. What remains is a single distributed infrastructure hiding behind 12+ legal entities across 8+ jurisdictions.
๐ฌ What This Means
This is not a criminal hosting provider. It is an industrialized infrastructure for making malicious activity jurisdictionally invisible. The geographic discrepancy that started this investigation is not a side effect โ it is the product. When every database disagrees on what country an IP belongs to, the system is working as designed.
The enabler ecosystem โ formation agents, nominee directors, offshore shells, IP marketplaces, reputation laundering services โ is not illegal in any single jurisdiction. Each entity operates within the letter of its local law. But their combined effect is to create infrastructure where botnet C2 panels run openly, where 628-node scanning campaigns launch daily, and where no single regulator can assemble enough of the picture to act.
The remaining dossiers in this series will examine each layer in detail: the bulletproof island (HBING), the German gray zone (PIO/XSServer), the IP marketplace (IPXO), the offshore chain (Panama Papers), and the sanctions question (Iranian transit).
๐ฌ Methodology
This investigation originated from automated geographic discrepancy detection on our SSH honeypot โ flagging IPs where AbuseIPDB country โ RDAP country โ BGP prefix country. The 25 highest-threat discrepant IPs were clustered by ASN, revealing the PIO-Hosting/HBING nexus. Corporate research used UK Companies House, German Handelsregister, and RIPE NCC databases. Offshore connections were verified through ICIJ Offshore Leaks. BGP routing was confirmed via bgp.he.net, RIPEstat, and Cloudflare Radar. Active reconnaissance was performed via Tor-routed nmap/httpx. All IP threat data comes from our production honeypot intelligence platform (8,000+ tracked IPs, 271K+ entity links).