๐Ÿ”ด CRITICAL โ€” Bulletproof Hosting ยท BVI Shell Company ยท Panama Papers Nominee ยท Seven-Country Prefix Laundering ยท Botnet C2 Confirmed

๐Ÿ๏ธ TI-2026-026B โ€” The Bulletproof Archipelago: HBING LIMITED's Island-Hopping Infrastructure

TI-2026-026B ยท Series 2 of 6 ยท Confidence: HIGH ยท Sources: UK Companies House, RIPE NCC, AFRINIC, BGP Data, Cloudflare Radar, Honeypot Active Recon, AbuseIPDB, Shodan, ICIJ Offshore Leaks, PeeringDB

๐Ÿ“‹ Executive Summary

HBING LIMITED (UK Company #13836998) is registered as a retail store at a residential address in rural Suffolk. It operates AS208949 โ€” an autonomous system classified as bulletproof with a risk score of 95.26 out of 100. Its abuse contact is a Gmail address. Its RIPE registration is at one of London's most notorious virtual office addresses. It has 56 legitimate users across 3,072 IP addresses.

This dossier disassembles HBING piece by piece: the three-day Russian director, the Turkish controller verified by a formation agent, the BVI shell maintainer with a Panama Papers-linked contact, the Dubai sponsorship, the African IP space laundered through European transit, the Hitrow botnet C2 panel running on its infrastructure, and the seven countries whose IP space flows through a single UK company that has never operated a server in the United Kingdom.

AS208949 HBING LIMITED Company #13836998 Risk 95.26/100 Hitrow 1.1.43 C2 BVI Shell Panama Papers 3-Day Nominee Director 56 Users / 3,072 IPs 7 Countries
95.26bulletproof risk score
3days Olga INAG was director
7countries' IP space through one ASN
56legitimate users (Cloudflare)
3,072IP addresses controlled
100%AbuseIPDB on all observed IPs

๐Ÿ  The Company: A Retail Store in Rural Suffolk

HBING LIMITED was incorporated on 10 January 2022. According to UK Companies House, it is classified under SIC codes 47190 ("Other retail sale in non-specialised stores") and 63110 ("Data processing, hosting and related activities"). Its registered address is 82a James Carter Road, Mildenhall, Suffolk, IP28 7DE โ€” a residential address in a small town primarily known for its nearby RAF base.

Its RIPE NCC registration tells a different story. The RIPE address is 124 City Road, London, EC1V 2NX โ€” a virtual office used by thousands of shell companies. The abuse contact is hbinglimited@mail.com โ€” a freemailer, not a corporate domain.

FieldCompanies HouseRIPE NCC
Address82a James Carter Rd, Mildenhall, Suffolk124 City Road, London EC1V 2NX
NatureResidentialVirtual office (1000s of companies)
SIC Code47190 โ€” Retail storeโ€”
EmailNot filedhbinglimited@mail.com
PeeringDBโ€”Not listed

โ“ What kind of "retail store" operates bulletproof hosting infrastructure spanning seven countries?

The kind that isn't a retail store. The SIC code 47190 was likely chosen because it creates no regulatory obligations. A hosting company (63110) might attract scrutiny from Ofcom or the ICO. A "retail store" that also happens to announce BGP routes for botnet C2 infrastructure flies under every regulatory radar because no UK regulator monitors retail stores for internet infrastructure abuse.

๐Ÿ“Ž Sources: Companies House #13836998 ยท RIPE ORG-HA1037-RIPE

๐ŸŽญ The Directors: 72 Hours of Olga

HBING's incorporation timeline reveals a textbook nominee-director pattern:

DateEventPersonNationality
10 Jan 2022Company incorporatedOlga INAG (Director)๐Ÿ‡ท๐Ÿ‡บ Russian
13 Jan 2022Olga INAG resignsโ€”โ€”
13 Jan 2022Cihan KAPLAN appointedCihan KAPLAN๐Ÿ‡น๐Ÿ‡ท Turkish
11 Mar 2026Identity verificationVerified by E-SIRKET LTDโ€”

Olga INAG โ€” Russian, born October 1991 โ€” served as director for exactly three days. Her address was "Suite A" at the same Mildenhall premises. She was a nominee: a warm body to satisfy Companies House incorporation requirements, immediately replaced by the actual controller.

Cihan KAPLAN โ€” Turkish, born June 1990 โ€” has exactly one UK directorship: HBING. He resides in Turkey. His identity was verified by E-SIRKET LTD ("e-company" in Turkish) โ€” a formation agent, not a legal firm. KAPLAN holds no other visible UK corporate presence.

โ“ Who hired Olga INAG for three days, and who is she really?

Nominee directors are a service. Formation agents maintain pools of individuals willing to be named on Day 1. They resign on Day 2 or 3 once the actual controller's paperwork clears. Olga INAG likely appears on dozens or hundreds of UK company formations โ€” a Russian national whose role is to exist briefly on paper. The question isn't who she is. The question is who paid the formation agent, and whether that person is Cihan Kaplan or someone Kaplan also works for.

โ“ If KAPLAN is the actual beneficial owner, why use a Turkish formation agent for identity verification four years after incorporation?

The identity verification happened on 11 March 2026 โ€” four years after incorporation. This timing coincides with the UK's new Register of Overseas Entities and enhanced ID verification requirements introduced under the Economic Crime and Corporate Transparency Act 2023. KAPLAN verified because he was required to, not voluntarily. The choice of E-SIRKET (a Turkish ACSP) means the verification was handled within Turkey's commercial system, not the UK's โ€” minimizing British regulatory contact.

๐Ÿ“Ž Sources: Companies House Officers ยท Kaplan Appointments

๐Ÿ๏ธ The BVI Layer: lir-vg-itweb-1-MNT

Three of HBING's 10 announced prefixes are maintained by lir-vg-itweb-1-MNT โ€” a RIPE maintainer whose "lir-vg" prefix identifies it as a British Virgin Islands entity. Its admin contact is listed as "Rea Ketty" with a Seychelles address and a US (Atlanta) phone number:

FieldValue
Maintainerlir-vg-itweb-1-MNT
Description"Startup maintainer"
Created20 April 2022 (3 months after HBING incorporation)
Admin ContactRK11506-RIPE โ€” "Rea Ketty"
AddressHouse of Francis, Room 303, รŽle Du Port, Mahe, Seychelles
Phone+1-470-809-9233 (Atlanta, GA area code)
Abuse Emailabuse.webltd@gmail.com

The prefixes managed by this BVI shell:

PrefixCountryNetnameCreated
45.88.0.0/24๐Ÿ‡ต๐Ÿ‡ฑ PolandLayer_IT_services2023-09-25
45.148.145.0/24๐Ÿ‡ง๐Ÿ‡ช BelgiumLay2025-01-05
45.148.146.0/24๐Ÿ‡ต๐Ÿ‡ฑ PolandLay2024-02-26

Polish and Belgian IP space. Registered by a BVI entity. With a Seychelles address. An Atlanta phone number. A Gmail abuse contact. Announced by a UK ASN. Hosted in the Netherlands. Six jurisdictions for three /24 blocks.

โ“ "Rea Ketty" appears in the ICIJ Panama Papers database as node #12169229. Is this the same person?

The full name in ICIJ records is Rea Ketty Yolande BARREAU. The Seychelles address (House of Francis, รŽle Du Port) is a known offshore registration building housing hundreds of corporate entities. BARREAU is almost certainly a professional nominee โ€” someone whose name appears on documents for a fee. The real question: the same nominee appears in both Panama Papers offshore structures AND internet infrastructure registration. This means the same offshore service industry that hides money also hides internet infrastructure ownership. The tools are identical; only the asset class changed.

๐Ÿ“Ž Sources: ICIJ Offshore Leaks #12169229 ยท RIPE lir-vg-itweb-1-MNT

๐ŸŒ The Prefix Inventory: Seven Countries, One ASN

AS208949 currently announces 10 prefixes. At its peak in early 2024, it announced approximately 40 prefixes. The current inventory spans IP registrations in:

CountryPrefix(es)RegistrantMaintainer
๐Ÿ‡ต๐Ÿ‡ฑ Poland45.88.0.0/24, 45.148.146.0/24Layer IT / "Lay"lir-vg-itweb-1-MNT (BVI)
๐Ÿ‡ง๐Ÿ‡ช Belgium45.148.145.0/24"Lay"lir-vg-itweb-1-MNT (BVI)
๐Ÿ‡ฌ๐Ÿ‡ง United Kingdom185.114.146.0/23IPXO / Internet Utilitiesnetutils-mnt
๐Ÿ‡ฟ๐Ÿ‡ฆ South Africa102.165.51.0/24Netutilsnetutils-mnt (IPXO)
๐Ÿ‡บ๐Ÿ‡ธ United States102.129.200.0/24, 192.101.68.0/24HEFICED / DECRYPTDAL1-MNT / MNT-DL-317
๐Ÿ‡บ๐Ÿ‡ฆ Ukraine195.211.191.0/24PITLINE-NEThbing-mnt
๐Ÿ‡ท๐Ÿ‡ด Romania93.113.203.0/24NET GATE COMUNICATII SRLWORLD-NET-MNT
๐Ÿ‡ท๐Ÿ‡บ Russia193.151.109.0/24SilverCom.RU Ltdru-silvercomru-1-mnt

Eight countries. Three RIPE maintainers (BVI shell, IPXO, and self). Two Regional Internet Registries (RIPE and AFRINIC). One RPKI-invalid route. Zero PeeringDB listing. 56 legitimate users.

๐Ÿ“– Read Between the Lines

  • 56 users on 3,072 IPs means one legitimate user per 55 IP addresses. Normal hosting density is 10-100+ customers per IP. This isn't a hosting company โ€” it's an IP address warehouse.
  • Ukrainian and Russian IP space announced by the same ASN โ€” during an active war between the two countries. The infrastructure doesn't care about geopolitics; it cares about addressable inventory.
  • The peak of 40 prefixes in early 2024 followed by decline to 10 suggests prefix rotation โ€” blocks are leased, used, potentially burned (blacklisted), then returned. The 30 "missing" prefixes didn't disappear; they moved to other ASNs in the same ecosystem.
  • No PeeringDB listing means HBING does not participate in the normal internet exchange ecosystem. Legitimate hosting companies always list on PeeringDB for business development. HBING's absence is a statement: it does not want to be found by potential peers or customers through normal channels.

๐Ÿ“Ž Sources: bgp.he.net Prefixes ยท RIPEstat Announced Prefixes ยท Cloudflare Radar

๐Ÿค– The Payload: Hitrow 1.1.43

Our Tor-routed active reconnaissance of HBING infrastructure discovered Hitrow 1.1.43 running on 102.129.200.117 ports 80 and 8080. HTTP title: "Welcome to Hitrow". Hitrow is a botnet management panel โ€” a web-based command-and-control interface for coordinating brute-force SSH attacks.

This IP's threat profile:

SourceScore/Classification
AbuseIPDB100/100 confidence
GreyNoiseMalicious
VirusTotal14 engines flagged malicious
OTXMultiple threat pulses
Honeypot ClassificationBotnet C2 (confidence 0.80)
DShield4,019 attacks reported

All five HBING IPs observed by our honeypot have AbuseIPDB confidence 100/100. All use the same SSH client library (libssh2_1.11.0). They are part of a 628-IP scanning campaign using identical HASSH fingerprints โ€” automated brute-force infrastructure coordinated from these C2 panels.

โ“ HBING is a "hosting company." Is it possible they simply host a customer who runs Hitrow, without HBING's knowledge?

That argument fails on three counts. First, 100% of observed HBING IPs have maximum abuse scores โ€” this isn't one bad customer among many; it's the entire network. Second, the abuse contact is a Gmail address that demonstrably does not respond. Third, when every IP uses the identical SSH library and participates in the same campaign, this is not "a customer" โ€” this is the infrastructure operator themselves. HBING doesn't have a malware problem. HBING is the malware infrastructure.

๐Ÿ“Ž Sources: Active Recon (Tor-routed httpx) ยท AbuseIPDB ยท Honeypot HASSH Clustering ยท DShield

๐Ÿ‡ฆ๐Ÿ‡ช The Enabler Chain: Dubai โ†’ BVI โ†’ Seychelles โ†’ UK

HBING's ASN (AS208949) is sponsored by Host Sailor Ltd โ€” a Dubai-based entity registered at 1605 Churchill Executive Tower, Burj Khalifa Area, Dubai with a US phone number (+1-646-518-9099). Host Sailor is a RIPE LIR since December 2014; its business model includes sponsoring ASN registrations for third parties.

The chain of enablement:

StepEntityJurisdictionService Provided
1Host Sailor Ltd๐Ÿ‡ฆ๐Ÿ‡ช DubaiRIPE LIR sponsorship (ASN access)
2123LIR / ANT BM Limited๐Ÿ‡ฌ๐Ÿ‡ง UKASN registration service
3E-SIRKET LTD๐Ÿ‡น๐Ÿ‡ท TurkeyCompany formation, ID verification
4lir-vg-itweb-1-MNT๐Ÿ‡ป๐Ÿ‡ฌ BVIIP block registration
5"Rea Ketty" / BARREAU๐Ÿ‡ธ๐Ÿ‡จ SeychellesNominee contact
6HBING LIMITED / KAPLAN๐Ÿ‡ฌ๐Ÿ‡ง UKBGP announcements
7NovoServe B.V.๐Ÿ‡ณ๐Ÿ‡ฑ NetherlandsPhysical transit/colocation

Seven entities across seven jurisdictions to accomplish one thing: announce IP addresses into the global routing table. Each entity operates within the legal boundaries of its own jurisdiction. No single regulator sees โ€” or is responsible for โ€” the complete picture.

โ“ Is NovoServe complicit, or just a transit provider?

NovoServe B.V. (AS24875, Netherlands) provides physical transit for HBING's announcements. As a Dutch entity, it is subject to Dutch law and EU regulations. The question is whether NovoServe performs due diligence on the traffic it carries. A network classified as 95% bulletproof with maximum abuse scores should trigger any reasonable "know your customer" check. If NovoServe knows and continues providing transit, it is an enabler. If it doesn't know, its compliance processes are inadequate for the risk it carries.

๐Ÿ“Š The IPXO Connection: Whose IP Space Is This Really?

Three of HBING's prefixes are directly linked to IPXO through maintainer records:

PrefixLink to IPXOEvidence
185.114.146.0/23Direct: netname "IPXO", org ORG-IL687-RIPEInternet Utilities EU/Asia Ltd
102.129.200.0/24Direct: netname "HEFICED-CLOUD-SERVERS", abuse@ipxo.comAFRINIC registration
102.165.51.0/24Maintainer match: netutils-mntSame mnt as ORG-IL687-RIPE

IPXO's own IP space โ€” including African blocks originally allocated by AFRINIC โ€” is announced through an ASN classified as bulletproof with risk 95.26/100. The AFRINIC block 102.129.200.0/24 is the one where Hitrow botnet C2 was confirmed running. IPXO's abuse email (abuse@ipxo.com) is listed as the contact for that block.

โ“ If IPXO owns the IP space and HBING announces it, who is responsible for the Hitrow C2 panel running on 102.129.200.117?

Both. IPXO as the IP holder/lessor has a responsibility under its own Terms of Service (Clause 18) to ensure leased space is not used for illegal activity. HBING as the routing entity has operational control. The structure creates a responsibility gap: IPXO says "we don't control routing," HBING says "we don't own the IPs." Meanwhile, a botnet C2 panel runs openly on port 80. This gap is not an accident โ€” it is the product being sold.

๐Ÿ“Ž Sources: RIPEstat WHOIS 102.129.200.0/24 ยท RIPEstat 185.114.146.0/23

โฑ๏ธ Timeline: From Incorporation to Bulletproof

DateEvent
10 Jan 2022HBING incorporated (Olga INAG director)
13 Jan 2022INAG resigns; KAPLAN appointed
20 Apr 2022lir-vg-itweb-1-MNT created (BVI shell)
02 Apr 2023RIPE organization created
11 Apr 2023AS208949 allocated
29 Apr 2023First BGP announcement
Aug-Oct 2023Rapid expansion: 16โ†’40 prefixes
Feb 2024Peak: ~40 prefixes, ~10,000+ IPs
2024-2025Gradual decline (blocks rotated out)
11 Mar 2026KAPLAN identity re-verified (new UK law)
Jun 2026Current: 10 prefixes, 3,072 IPs, risk 95.26

๐Ÿ“– Read Between the Lines

  • The BVI shell (lir-vg-itweb-1-MNT) was created 3 months after incorporation โ€” this is pre-planned offshore infrastructure, not an afterthought.
  • The ASN was allocated 15 months after incorporation. Why the gap? Because the corporate structure (BVI shell, nominee contacts, Dubai sponsorship) needed to be assembled first. The ASN was the last piece, not the first.
  • Peak operations (40 prefixes) lasted only months before declining. This pattern matches prefix rotation โ€” use blocks until they're blacklisted, then swap for fresh ones. The infrastructure stays; the IP addresses cycle through it.
  • The 2026 identity verification was forced by law, not voluntary. If the Economic Crime Act hadn't required it, KAPLAN might never have formally verified his identity with UK authorities.

๐Ÿ”ฌ Methodology

HBING LIMITED was identified through automated geographic discrepancy detection on production SSH honeypot data. Corporate research used UK Companies House API and RIPE NCC REST API. BGP analysis used bgp.he.net, RIPEstat, and Cloudflare Radar. The BVI/offshore connection was verified through RIPE maintainer records and cross-referenced against ICIJ Offshore Leaks Database. Active reconnaissance of HBING IP infrastructure was performed via Tor-routed nmap and httpx, confirming Hitrow C2 panels. All threat scores derive from our multi-source enrichment pipeline (AbuseIPDB, Shodan, GreyNoise, OTX, VirusTotal, DShield, Pulsedive).

โš  Personal capacity. Research published independently โ€” not reflecting employer views. Derived from passive observation of attacks against personal infrastructure. Full disclaimer โ†’
โ† Previous The Phantom ASN โ€” 2 / 17 Next โ†’