๐๏ธ TI-2026-026B โ The Bulletproof Archipelago: HBING LIMITED's Island-Hopping Infrastructure
๐ Executive Summary
HBING LIMITED (UK Company #13836998) is registered as a retail store at a residential address in rural Suffolk. It operates AS208949 โ an autonomous system classified as bulletproof with a risk score of 95.26 out of 100. Its abuse contact is a Gmail address. Its RIPE registration is at one of London's most notorious virtual office addresses. It has 56 legitimate users across 3,072 IP addresses.
This dossier disassembles HBING piece by piece: the three-day Russian director, the Turkish controller verified by a formation agent, the BVI shell maintainer with a Panama Papers-linked contact, the Dubai sponsorship, the African IP space laundered through European transit, the Hitrow botnet C2 panel running on its infrastructure, and the seven countries whose IP space flows through a single UK company that has never operated a server in the United Kingdom.
๐ The Company: A Retail Store in Rural Suffolk
HBING LIMITED was incorporated on 10 January 2022. According to UK Companies House, it is classified under SIC codes 47190 ("Other retail sale in non-specialised stores") and 63110 ("Data processing, hosting and related activities"). Its registered address is 82a James Carter Road, Mildenhall, Suffolk, IP28 7DE โ a residential address in a small town primarily known for its nearby RAF base.
Its RIPE NCC registration tells a different story. The RIPE address is 124 City Road, London, EC1V 2NX โ a virtual office used by thousands of shell companies. The abuse contact is hbinglimited@mail.com โ a freemailer, not a corporate domain.
| Field | Companies House | RIPE NCC |
|---|---|---|
| Address | 82a James Carter Rd, Mildenhall, Suffolk | 124 City Road, London EC1V 2NX |
| Nature | Residential | Virtual office (1000s of companies) |
| SIC Code | 47190 โ Retail store | โ |
| Not filed | hbinglimited@mail.com | |
| PeeringDB | โ | Not listed |
โ What kind of "retail store" operates bulletproof hosting infrastructure spanning seven countries?
The kind that isn't a retail store. The SIC code 47190 was likely chosen because it creates no regulatory obligations. A hosting company (63110) might attract scrutiny from Ofcom or the ICO. A "retail store" that also happens to announce BGP routes for botnet C2 infrastructure flies under every regulatory radar because no UK regulator monitors retail stores for internet infrastructure abuse.
๐ Sources: Companies House #13836998 ยท RIPE ORG-HA1037-RIPE
๐ญ The Directors: 72 Hours of Olga
HBING's incorporation timeline reveals a textbook nominee-director pattern:
| Date | Event | Person | Nationality |
|---|---|---|---|
| 10 Jan 2022 | Company incorporated | Olga INAG (Director) | ๐ท๐บ Russian |
| 13 Jan 2022 | Olga INAG resigns | โ | โ |
| 13 Jan 2022 | Cihan KAPLAN appointed | Cihan KAPLAN | ๐น๐ท Turkish |
| 11 Mar 2026 | Identity verification | Verified by E-SIRKET LTD | โ |
Olga INAG โ Russian, born October 1991 โ served as director for exactly three days. Her address was "Suite A" at the same Mildenhall premises. She was a nominee: a warm body to satisfy Companies House incorporation requirements, immediately replaced by the actual controller.
Cihan KAPLAN โ Turkish, born June 1990 โ has exactly one UK directorship: HBING. He resides in Turkey. His identity was verified by E-SIRKET LTD ("e-company" in Turkish) โ a formation agent, not a legal firm. KAPLAN holds no other visible UK corporate presence.
โ Who hired Olga INAG for three days, and who is she really?
Nominee directors are a service. Formation agents maintain pools of individuals willing to be named on Day 1. They resign on Day 2 or 3 once the actual controller's paperwork clears. Olga INAG likely appears on dozens or hundreds of UK company formations โ a Russian national whose role is to exist briefly on paper. The question isn't who she is. The question is who paid the formation agent, and whether that person is Cihan Kaplan or someone Kaplan also works for.
โ If KAPLAN is the actual beneficial owner, why use a Turkish formation agent for identity verification four years after incorporation?
The identity verification happened on 11 March 2026 โ four years after incorporation. This timing coincides with the UK's new Register of Overseas Entities and enhanced ID verification requirements introduced under the Economic Crime and Corporate Transparency Act 2023. KAPLAN verified because he was required to, not voluntarily. The choice of E-SIRKET (a Turkish ACSP) means the verification was handled within Turkey's commercial system, not the UK's โ minimizing British regulatory contact.
๐ Sources: Companies House Officers ยท Kaplan Appointments
๐๏ธ The BVI Layer: lir-vg-itweb-1-MNT
Three of HBING's 10 announced prefixes are maintained by lir-vg-itweb-1-MNT โ a RIPE maintainer whose "lir-vg" prefix identifies it as a British Virgin Islands entity. Its admin contact is listed as "Rea Ketty" with a Seychelles address and a US (Atlanta) phone number:
| Field | Value |
|---|---|
| Maintainer | lir-vg-itweb-1-MNT |
| Description | "Startup maintainer" |
| Created | 20 April 2022 (3 months after HBING incorporation) |
| Admin Contact | RK11506-RIPE โ "Rea Ketty" |
| Address | House of Francis, Room 303, รle Du Port, Mahe, Seychelles |
| Phone | +1-470-809-9233 (Atlanta, GA area code) |
| Abuse Email | abuse.webltd@gmail.com |
The prefixes managed by this BVI shell:
| Prefix | Country | Netname | Created |
|---|---|---|---|
| 45.88.0.0/24 | ๐ต๐ฑ Poland | Layer_IT_services | 2023-09-25 |
| 45.148.145.0/24 | ๐ง๐ช Belgium | Lay | 2025-01-05 |
| 45.148.146.0/24 | ๐ต๐ฑ Poland | Lay | 2024-02-26 |
Polish and Belgian IP space. Registered by a BVI entity. With a Seychelles address. An Atlanta phone number. A Gmail abuse contact. Announced by a UK ASN. Hosted in the Netherlands. Six jurisdictions for three /24 blocks.
โ "Rea Ketty" appears in the ICIJ Panama Papers database as node #12169229. Is this the same person?
The full name in ICIJ records is Rea Ketty Yolande BARREAU. The Seychelles address (House of Francis, รle Du Port) is a known offshore registration building housing hundreds of corporate entities. BARREAU is almost certainly a professional nominee โ someone whose name appears on documents for a fee. The real question: the same nominee appears in both Panama Papers offshore structures AND internet infrastructure registration. This means the same offshore service industry that hides money also hides internet infrastructure ownership. The tools are identical; only the asset class changed.
๐ Sources: ICIJ Offshore Leaks #12169229 ยท RIPE lir-vg-itweb-1-MNT
๐ The Prefix Inventory: Seven Countries, One ASN
AS208949 currently announces 10 prefixes. At its peak in early 2024, it announced approximately 40 prefixes. The current inventory spans IP registrations in:
| Country | Prefix(es) | Registrant | Maintainer |
|---|---|---|---|
| ๐ต๐ฑ Poland | 45.88.0.0/24, 45.148.146.0/24 | Layer IT / "Lay" | lir-vg-itweb-1-MNT (BVI) |
| ๐ง๐ช Belgium | 45.148.145.0/24 | "Lay" | lir-vg-itweb-1-MNT (BVI) |
| ๐ฌ๐ง United Kingdom | 185.114.146.0/23 | IPXO / Internet Utilities | netutils-mnt |
| ๐ฟ๐ฆ South Africa | 102.165.51.0/24 | Netutils | netutils-mnt (IPXO) |
| ๐บ๐ธ United States | 102.129.200.0/24, 192.101.68.0/24 | HEFICED / DECRYPT | DAL1-MNT / MNT-DL-317 |
| ๐บ๐ฆ Ukraine | 195.211.191.0/24 | PITLINE-NET | hbing-mnt |
| ๐ท๐ด Romania | 93.113.203.0/24 | NET GATE COMUNICATII SRL | WORLD-NET-MNT |
| ๐ท๐บ Russia | 193.151.109.0/24 | SilverCom.RU Ltd | ru-silvercomru-1-mnt |
Eight countries. Three RIPE maintainers (BVI shell, IPXO, and self). Two Regional Internet Registries (RIPE and AFRINIC). One RPKI-invalid route. Zero PeeringDB listing. 56 legitimate users.
๐ Read Between the Lines
- 56 users on 3,072 IPs means one legitimate user per 55 IP addresses. Normal hosting density is 10-100+ customers per IP. This isn't a hosting company โ it's an IP address warehouse.
- Ukrainian and Russian IP space announced by the same ASN โ during an active war between the two countries. The infrastructure doesn't care about geopolitics; it cares about addressable inventory.
- The peak of 40 prefixes in early 2024 followed by decline to 10 suggests prefix rotation โ blocks are leased, used, potentially burned (blacklisted), then returned. The 30 "missing" prefixes didn't disappear; they moved to other ASNs in the same ecosystem.
- No PeeringDB listing means HBING does not participate in the normal internet exchange ecosystem. Legitimate hosting companies always list on PeeringDB for business development. HBING's absence is a statement: it does not want to be found by potential peers or customers through normal channels.
๐ Sources: bgp.he.net Prefixes ยท RIPEstat Announced Prefixes ยท Cloudflare Radar
๐ค The Payload: Hitrow 1.1.43
Our Tor-routed active reconnaissance of HBING infrastructure discovered Hitrow 1.1.43 running on 102.129.200.117 ports 80 and 8080. HTTP title: "Welcome to Hitrow". Hitrow is a botnet management panel โ a web-based command-and-control interface for coordinating brute-force SSH attacks.
This IP's threat profile:
| Source | Score/Classification |
|---|---|
| AbuseIPDB | 100/100 confidence |
| GreyNoise | Malicious |
| VirusTotal | 14 engines flagged malicious |
| OTX | Multiple threat pulses |
| Honeypot Classification | Botnet C2 (confidence 0.80) |
| DShield | 4,019 attacks reported |
All five HBING IPs observed by our honeypot have AbuseIPDB confidence 100/100. All use the same SSH client library (libssh2_1.11.0). They are part of a 628-IP scanning campaign using identical HASSH fingerprints โ automated brute-force infrastructure coordinated from these C2 panels.
โ HBING is a "hosting company." Is it possible they simply host a customer who runs Hitrow, without HBING's knowledge?
That argument fails on three counts. First, 100% of observed HBING IPs have maximum abuse scores โ this isn't one bad customer among many; it's the entire network. Second, the abuse contact is a Gmail address that demonstrably does not respond. Third, when every IP uses the identical SSH library and participates in the same campaign, this is not "a customer" โ this is the infrastructure operator themselves. HBING doesn't have a malware problem. HBING is the malware infrastructure.
๐ Sources: Active Recon (Tor-routed httpx) ยท AbuseIPDB ยท Honeypot HASSH Clustering ยท DShield
๐ฆ๐ช The Enabler Chain: Dubai โ BVI โ Seychelles โ UK
HBING's ASN (AS208949) is sponsored by Host Sailor Ltd โ a Dubai-based entity registered at 1605 Churchill Executive Tower, Burj Khalifa Area, Dubai with a US phone number (+1-646-518-9099). Host Sailor is a RIPE LIR since December 2014; its business model includes sponsoring ASN registrations for third parties.
The chain of enablement:
| Step | Entity | Jurisdiction | Service Provided |
|---|---|---|---|
| 1 | Host Sailor Ltd | ๐ฆ๐ช Dubai | RIPE LIR sponsorship (ASN access) |
| 2 | 123LIR / ANT BM Limited | ๐ฌ๐ง UK | ASN registration service |
| 3 | E-SIRKET LTD | ๐น๐ท Turkey | Company formation, ID verification |
| 4 | lir-vg-itweb-1-MNT | ๐ป๐ฌ BVI | IP block registration |
| 5 | "Rea Ketty" / BARREAU | ๐ธ๐จ Seychelles | Nominee contact |
| 6 | HBING LIMITED / KAPLAN | ๐ฌ๐ง UK | BGP announcements |
| 7 | NovoServe B.V. | ๐ณ๐ฑ Netherlands | Physical transit/colocation |
Seven entities across seven jurisdictions to accomplish one thing: announce IP addresses into the global routing table. Each entity operates within the legal boundaries of its own jurisdiction. No single regulator sees โ or is responsible for โ the complete picture.
โ Is NovoServe complicit, or just a transit provider?
NovoServe B.V. (AS24875, Netherlands) provides physical transit for HBING's announcements. As a Dutch entity, it is subject to Dutch law and EU regulations. The question is whether NovoServe performs due diligence on the traffic it carries. A network classified as 95% bulletproof with maximum abuse scores should trigger any reasonable "know your customer" check. If NovoServe knows and continues providing transit, it is an enabler. If it doesn't know, its compliance processes are inadequate for the risk it carries.
๐ The IPXO Connection: Whose IP Space Is This Really?
Three of HBING's prefixes are directly linked to IPXO through maintainer records:
| Prefix | Link to IPXO | Evidence |
|---|---|---|
| 185.114.146.0/23 | Direct: netname "IPXO", org ORG-IL687-RIPE | Internet Utilities EU/Asia Ltd |
| 102.129.200.0/24 | Direct: netname "HEFICED-CLOUD-SERVERS", abuse@ipxo.com | AFRINIC registration |
| 102.165.51.0/24 | Maintainer match: netutils-mnt | Same mnt as ORG-IL687-RIPE |
IPXO's own IP space โ including African blocks originally allocated by AFRINIC โ is announced through an ASN classified as bulletproof with risk 95.26/100. The AFRINIC block 102.129.200.0/24 is the one where Hitrow botnet C2 was confirmed running. IPXO's abuse email (abuse@ipxo.com) is listed as the contact for that block.
โ If IPXO owns the IP space and HBING announces it, who is responsible for the Hitrow C2 panel running on 102.129.200.117?
Both. IPXO as the IP holder/lessor has a responsibility under its own Terms of Service (Clause 18) to ensure leased space is not used for illegal activity. HBING as the routing entity has operational control. The structure creates a responsibility gap: IPXO says "we don't control routing," HBING says "we don't own the IPs." Meanwhile, a botnet C2 panel runs openly on port 80. This gap is not an accident โ it is the product being sold.
๐ Sources: RIPEstat WHOIS 102.129.200.0/24 ยท RIPEstat 185.114.146.0/23
โฑ๏ธ Timeline: From Incorporation to Bulletproof
| Date | Event |
|---|---|
| 10 Jan 2022 | HBING incorporated (Olga INAG director) |
| 13 Jan 2022 | INAG resigns; KAPLAN appointed |
| 20 Apr 2022 | lir-vg-itweb-1-MNT created (BVI shell) |
| 02 Apr 2023 | RIPE organization created |
| 11 Apr 2023 | AS208949 allocated |
| 29 Apr 2023 | First BGP announcement |
| Aug-Oct 2023 | Rapid expansion: 16โ40 prefixes |
| Feb 2024 | Peak: ~40 prefixes, ~10,000+ IPs |
| 2024-2025 | Gradual decline (blocks rotated out) |
| 11 Mar 2026 | KAPLAN identity re-verified (new UK law) |
| Jun 2026 | Current: 10 prefixes, 3,072 IPs, risk 95.26 |
๐ Read Between the Lines
- The BVI shell (lir-vg-itweb-1-MNT) was created 3 months after incorporation โ this is pre-planned offshore infrastructure, not an afterthought.
- The ASN was allocated 15 months after incorporation. Why the gap? Because the corporate structure (BVI shell, nominee contacts, Dubai sponsorship) needed to be assembled first. The ASN was the last piece, not the first.
- Peak operations (40 prefixes) lasted only months before declining. This pattern matches prefix rotation โ use blocks until they're blacklisted, then swap for fresh ones. The infrastructure stays; the IP addresses cycle through it.
- The 2026 identity verification was forced by law, not voluntary. If the Economic Crime Act hadn't required it, KAPLAN might never have formally verified his identity with UK authorities.
๐ฌ Methodology
HBING LIMITED was identified through automated geographic discrepancy detection on production SSH honeypot data. Corporate research used UK Companies House API and RIPE NCC REST API. BGP analysis used bgp.he.net, RIPEstat, and Cloudflare Radar. The BVI/offshore connection was verified through RIPE maintainer records and cross-referenced against ICIJ Offshore Leaks Database. Active reconnaissance of HBING IP infrastructure was performed via Tor-routed nmap and httpx, confirming Hitrow C2 panels. All threat scores derive from our multi-source enrichment pipeline (AbuseIPDB, Shodan, GreyNoise, OTX, VirusTotal, DShield, Pulsedive).