CRITICAL โ€” MULTI-ENTITY OBFUSCATION

๐Ÿ‡ฉ๐Ÿ‡ช TI-2026-026C โ€” The German Gray Zone: How Three Companies Share One Phone Number and 42 Prefixes from Five Continents

Series: The Phantom ASN (Part 3 of 6) ยท Published: July 2025 ยท Classification: OSINT + Corporate Registry + Honeypot Forensics

Executive Summary: In the heart of Germany's Rhineland, three companies โ€” PIO-Hosting GmbH, XSServer GmbH, and SkyLink Data Center BV โ€” share personnel, phone numbers, and infrastructure while collectively routing traffic from five Regional Internet Registries. This is the story of how a phone number (+49 2451 9949570) connects a local hosting company to Iranian transit customers, Chinese IP lessees, Hong Kong reputation launderers, and a 628-IP scanning campaign that hit our honeypot.

42+IPv4 Prefixes
5RIRs Served
6,400+Routable IPs
628Honeypot Attackers
60CVEs (Single Host)
0PeeringDB Presence
AS198584PIO-HostingXSServerSkyLink DC Gray TransitIranian LIRsReputation Laundering Multi-RIRlibssh2 CampaignBulletproof

Chapter 1: One Phone Number, Three Companies, Two Countries

Begin with the simplest fact: a German telephone number appears in the RIPE database for three distinct organizations:

OrganizationRegistryAddressPhone
PIO-Hosting GmbHHRB 20998, MรถnchengladbachSรผchtelner Str. 65, 41066+49 2451 9949570
XSServer GmbHHRB 21403, AachenEm Koddes 1, รœbach-Palenberg+49 2451 9949570
SkyLink Data Center BVKvK (Netherlands)Eygelshoven, Netherlands+49 2451 9949570

Three entities. Two countries. One phone number. The German area code 02451 covers the town of รœbach-Palenberg โ€” population 24,000, on the Dutch border. XSServer is registered there. PIO-Hosting is 30km away in Mรถnchengladbach. SkyLink Data Center is across the border in Eygelshoven, Netherlands โ€” the same border region.

The personnel confirms what the phone number implies:

  • Marcel Edler โ€” XSServer GmbH management, PIO-Hosting sponsor
  • Rene Spellerberg โ€” XSServer GmbH associated
  • Dirk Bellgart โ€” SkyLink Data Center BV associated

XSServer sponsors PIO-Hosting's RIPE membership. In RIPE terminology, this means XSServer vouched for PIO's existence and took responsibility for its resource allocations. You don't sponsor strangers.

โ“ Why create three companies for what appears to be one operation?

Legal compartmentalization. If PIO-Hosting receives an abuse complaint, the infrastructure runs on XSServer hardware. If XSServer faces legal action, the ASN belongs to PIO. If either is shut down, SkyLink (in a different country) provides upstream transit. Each entity is a firewall โ€” not for packets, but for liability.

Chapter 2: 42 Prefixes, Five Registries, Zero PeeringDB

AS198584 was allocated on May 11, 2023 โ€” exactly one month after HBING's AS208949 (April 11, 2023). One month. This is not coincidence; this is a rollout schedule.

Despite routing 42+ IPv4 prefixes (6,400+ addresses) from every Regional Internet Registry:

RIRExample PrefixRegistrant
RIPE (Europe)176.65.128.0/21ZeXoTeK IT-Services
ARIN (Americas)66.92.164.0/24Internet Utilities NA LLC
APNIC (Asia-Pacific)103.161.34.0/24Guosheng IDC
AFRINIC (Africa)41.x.x.0/24via Internet Utilities
LACNIC (Latin America)VariousLease arrangements

...PIO-Hosting has zero presence on PeeringDB. No peering policy. No traffic statistics. No facility listings. No IX participation.

Every legitimate network operator lists on PeeringDB. It's free, it's industry standard, and it's how you establish peering relationships. The only reason to avoid it is if you don't want the transparency that comes with it.

๐Ÿ“– Read Between the Lines

  • A legitimate hosting company with 6,400+ IPs would benefit enormously from PeeringDB presence โ€” it reduces transit costs and improves latency. Avoiding it costs money. The only return on that cost is opacity.
  • Routing from all 5 RIRs means either a massive global transit deal (expensive, visible) or leasing third-party IP space (the IPXO model). The latter creates intentional confusion about who actually controls the addresses.
  • Being allocated exactly one month after HBING suggests the same operator filed both applications sequentially, waiting for the first to complete before submitting the second.

Chapter 3: SkyLink Data Center โ€” The Dutch Upstream That Isn't Dutch

SkyLink Data Center BV operates AS44592 from Eygelshoven, Netherlands โ€” a small town literally touching the German border. The company claims 1-5 Tbps of capacity. Its technical contact shares the same +49 (German) phone number as XSServer and PIO.

SkyLink is PIO-Hosting's primary upstream transit provider. In BGP terms, this means:

Internet โ†’ SkyLink (AS44592, "NL") โ†’ PIO-Hosting (AS198584, "DE") โ†’ Customer prefixes

But if SkyLink and PIO share personnel and phone numbers, this "upstream" relationship is a fiction. You cannot be your own upstream in any meaningful regulatory sense. It's the equivalent of a company lending money to its own subsidiary and claiming it as arm's-length revenue.

Dirk Bellgart appears as SkyLink's contact. The same infrastructure runs out of the same border region. The "Dutch" upstream is about as Dutch as PIO-Hosting is independent of XSServer.

๐Ÿ“Ž Source: bgp.he.net AS44592 ยท RIPE DB org ORG-SDCB3-RIPE

โ“ Why register in two different countries when the operation is in the same building?

Jurisdictional arbitrage. If German authorities (BKA, BfV) investigate PIO-Hosting's customer traffic, the upstream is "in the Netherlands." Dutch authorities (KLPD) must be separately engaged. The request must go through international legal assistance treaties (MLAT). By the time both countries coordinate, the customer has moved to a different prefix. For an operation handling Iranian transit and reputation-laundered IPs, this 2-week delay is the entire product.

Chapter 4: ZeXoTeK IT-Services โ€” Where the Attacks Originate

Our honeypot data traces back to a specific German LIR: ZeXoTeK IT-Services GmbH (HRB 30659 Zweibrรผcken, Hauptstrasse 29, 76891 Erlenbach, Germany). Director: Jens Winter.

ZeXoTeK operates the 176.65.128.0/21 block via PIO-Hosting's AS198584. From this block:

IPThreat ScoreCVEsAbuse ReportsClassification
176.65.131.189100/10060586C2 Panel
176.65.131.188100/100โ€”450+C2 Panel
176.65.136.3192/100โ€”200+Scanner

IP 176.65.131.189 alone has 60 CVEs open across ports 8080/8090, confirmed C2 infrastructure, and 586 AbuseIPDB reports. This is not a compromised server โ€” servers with 60 open CVEs running C2 panels are intentionally configured for malicious operations.

The 628-IP Campaign

All PIO-Hosting infrastructure participates in a single massive scanning campaign identified by HASSH fingerprint 14b2ddda386a4d10 (libssh2_1.11.0). This campaign spans 628 unique IPs across 48 countries. The shared HASSH proves identical tooling โ€” every node runs the same SSH brute-force client.

SSH Key Sharing

IP 176.65.131.189 (ZeXoTeK/PIO) shares SSH key fingerprint 44:c9:7f:6c:5d:53:4f:5d:38... with Scaleway France infrastructure. This is the strongest operator-identity signal possible โ€” the same private key deployed across jurisdictions means the same human operates both.

๐Ÿ“Ž Source: Honeypot forensics (threat_intel DB) ยท AbuseIPDB reports ยท Shodan enrichment ยท HASSH cluster analysis

โ“ Is Jens Winter aware his IP space hosts C2 panels?

With 586 AbuseIPDB reports on a single IP and Spamhaus listings on the block, the answer is unambiguous: yes. German law (ยง13 TMG, ยง10 TMG) requires hosting providers to act on knowledge of illegal activity. Either Winter actively condones it (making ZeXoTeK a bulletproof reseller) or he has never once checked abuse reports for blocks he personally registered. Neither interpretation is innocent.

Chapter 5: IPv4 Superhub โ€” The Reputation Laundromat

Among PIO-Hosting's customer base sits IPv4 Superhub Limited (Hong Kong Company Registry #2749673), at Unit 1302, 13/F APEC Plaza, Kwun Tong, Kowloon.

Their website (ipv4superhub.com) explicitly advertises:

"IP Reputation Repair โ€” We specialize in Spamhaus SBL/PBL delisting, SORBS removal, and abuse report resolution."

This is literally a reputation laundering service. The business model: buy IP blocks with destroyed reputation (cheap because they're blacklisted), route them through a new AS (PIO-Hosting provides this), get them delisted from Spamhaus, sell them at clean-IP prices.

The profit margin is enormous. Blacklisted IPv4 space trades at $15-20/IP. Clean space trades at $35-45/IP. A /24 (256 IPs) goes from ~$4,000 blacklisted to ~$10,000 clean. IPv4 Superhub's cut plus PIO's transit fees make this a $6,000+ profit per /24 "cleaned."

๐Ÿ“Ž Source: ipv4superhub.com (Wayback archived) ยท HK Company Registry #2749673 ยท RIPE ORG-ISL74-RIPE

๐Ÿ“– Read Between the Lines

  • IPv4 Superhub's service only works if the transit provider doesn't respond to abuse reports. If PIO-Hosting actioned Spamhaus listings, the IPs would be re-blacklisted immediately. The business relationship proves PIO ignores abuse complaints by design.
  • Routing blacklisted IPs through a fresh ASN (allocated May 2023) is the key innovation โ€” Spamhaus blacklists individual IPs and sometimes whole ASNs. A new ASN has no history. It's clean by definition.
  • This is why AS198584 was created: not to host websites, but to provide a reputation reset mechanism for tainted IP space.

Chapter 6: The Iranian Transit โ€” Four LIRs Through Germany

In June 2026, four Iranian LIRs began routing through AS198584:

LIRBlockMaintainer
lir-ir-salehi91.206.28.0/24lir-ir-salehi-1-MNT
lir-ir-seyeddavood91.206.29.0/24lir-ir-seyeddavood-1-MNT
lir-ir-mazdab91.207.x.0/24lir-ir-mazdab-1-MNT
lir-ir-nahorVariouslir-ir-nahor-1-MNT

Additionally, an InterLIR Marketplace block (212.102.x.0/24) with Iranian contact information routes via AS198584.

The Legal Question

EU Council Regulation (EC) No 267/2012 imposes comprehensive sanctions on Iran. Article 23(2) prohibits "making available, directly or indirectly, funds or economic resources" to designated persons or entities. Internet transit is an economic resource.

The question isn't whether German companies can provide IP transit to Iranian entities โ€” that depends on who those entities are and what they do. The question is: did PIO-Hosting/XSServer perform any due diligence whatsoever?

Four Iranian LIRs onboarded simultaneously suggests a bulk arrangement, not individual customer relationships. Someone (possibly via InterLIR marketplace) brokered this. The timing โ€” June 2026 โ€” coincides with EU-Iran nuclear deal tensions.

๐Ÿ“Ž Source: RIPE BGP data ยท EU Regulation 267/2012 ยท InterLIR marketplace records

โ“ Is providing BGP transit to Iranian LIRs actually illegal under EU sanctions?

It depends. If the LIRs are connected to IRGC (Islamic Revolutionary Guard Corps), sanctioned banks, or designated entities โ€” yes, it's a criminal offense under German law (ยง18 AWG) carrying up to 10 years imprisonment. If they're purely private enterprises providing civilian internet โ€” it's a gray area that requires specific license applications. The critical point: PIO-Hosting's structure (no KYC visible, no PeeringDB, bulletproof reputation) suggests they didn't ask the question. Not asking is not a defense.

Chapter 7: The Chinese Ghost โ€” Guosheng IDC

GSJZ (China) Technology Co., Limited (ORG-GIL15-AP) appears as a RIPE registrant for PIO-Hosting sub-leased blocks. Registered address: RM4, 16/F Ho King Commercial Centre, 2-16 Fayuen Street, Mong Kok, Kowloon, Hong Kong.

The entity has:

  • A dead domain (gsjz.net โ€” not resolving)
  • A Gmail abuse contact (unusual for any legitimate registrant)
  • IPs (103.161.34.x) that geolocate to Netherlands but are registered under APNIC (Asia-Pacific)
  • No visible web presence, customer base, or service description

The geographic discrepancy is the signature: APNIC-registered blocks physically hosted in Europe, transited via a German ASN, registered to a Hong Kong shell with a dead domain. This is precisely the "phantom" pattern that triggered our investigation.

๐Ÿ“Ž Source: APNIC WHOIS ORG-GIL15-AP ยท DNS resolution (gsjz.net NXDOMAIN) ยท GeoIP comparison (Maxmind vs RDAP)

โ“ What is GSJZ/Guosheng IDC actually doing with European-hosted Asian IP space?

The most charitable interpretation: arbitrage. APNIC IPs are cheaper than RIPE IPs due to regional allocation politics. Buy APNIC space, host it in Frankfurt where the servers physically are, profit from the price difference. The less charitable interpretation: jurisdiction shopping. Asian IP space governed by APNIC policies, physically in Germany governed by EU law, registered to a Hong Kong company governed by HK law. Three jurisdictions, no single authority has full visibility. Abuse complaints go to APNIC, which forwards to a Gmail address that doesn't respond, while the actual server sits in a German datacenter untouched.

Chapter 8: The Smoking Gun โ€” Vincentas Grinius Routes Through Both

The structural proof linking PIO-Hosting to HBING comes from a single RIPE maintainer object: netutils-mnt.

Internet Utilities NA LLC (Wilmington, Delaware) routes ARIN blocks (66.92.164.0/24, 72.9.233.0/24) via AS198584 (PIO-Hosting). The administrative contact: VINCENTAS GRINIUS, 6th Floor, 9 Appold Street, London EC2A 2AP.

The same netutils-mnt object also routes prefixes via AS208949 (HBING LIMITED) โ€” the UK bulletproof operator from our previous installments.

Vincentas Grinius is the co-founder of IPXO UAB (Lithuania, formerly HEFICED) โ€” the world's largest IP address marketplace, managing 14 million+ IPv4 addresses and reporting $55 million revenue.

EntityRegistryRole
IPXO UABLithuania #307097001IP marketplace platform
Internet Utilities EUSlovenia/UK #12540160European transit entity
Internet Utilities NA LLCDelaware, USAAmericas transit entity
netutils-mntRIPE maintainerRoutes via BOTH bulletproof ASNs

One person. One maintainer object. Two bulletproof ASNs. $55 million in revenue.

๐Ÿ“Ž Source: RIPE WHOIS netutils-mnt ยท UK Companies House #12540160 ยท IPXO UAB registry ยท ARIN RDAP ยท CAIDA/UCSD 2024 "Sublet Your Subnet"

๐Ÿ“– Read Between the Lines

  • IPXO sits on the RIPE Anti-Abuse Working Group. The co-founder of a platform whose transit entities route through bulletproof networks participates in setting RIPE abuse policy. This is regulatory capture in its purest form.
  • The academic paper "Sublet Your Subnet" (CAIDA/UCSD 2024) documents IPXO/HEFICED's role in enabling IP address abuse through sub-leasing. The research community has noticed.
  • $55M revenue flowing through entities that transit via bulletproof ASNs hosting C2 panels, Iranian LIRs, and reputation launderers. The revenue isn't from web hosting โ€” it's from providing the infrastructure layer that makes these operations possible.
  • If IPXO is the marketplace and PIO/HBING are the transit providers, then netutils-mnt is the receipt. It's the one object in the RIPE database that proves the commercial relationship between a $55M company and bulletproof hosting.

Chapter 9: The Architecture of Impunity

Zoom out. The complete structure is:

XSServer GmbH (DE, HRB 21403) โ€” operations team
    โ†“ sponsors RIPE membership
PIO-Hosting GmbH (DE, HRB 20998) โ€” AS198584 holder
    โ†‘ transit from
SkyLink Data Center BV (NL, AS44592) โ€” "upstream" (same phone)
    
Customers of AS198584:
โ”œโ”€โ”€ ZeXoTeK (DE) โ†’ 176.65.x.x โ†’ C2 panels, 628-IP botnet campaign
โ”œโ”€โ”€ IPv4 Superhub (HK) โ†’ reputation laundering service
โ”œโ”€โ”€ Guosheng IDC (HK/CN) โ†’ dead-domain shell, APNIC space in Europe
โ”œโ”€โ”€ 4ร— Iranian LIRs โ†’ potential sanctions evasion
โ””โ”€โ”€ Internet Utilities / IPXO โ†’ $55M marketplace, routes via BOTH ASNs
    

Every layer adds a jurisdiction. Every entity adds a compliance boundary. Every relationship is technically legal when viewed in isolation. Combined, they form a bulletproof hosting platform masquerading as legitimate German infrastructure.

The German authorities (BKA, BfV) see a registered GmbH with a Handelsregister number. RIPE sees an NCC member in good standing. The Dutch see a data center. Hong Kong sees a technology company. Lithuania sees a successful IP marketplace startup. Nobody sees the whole picture โ€” because the structure is designed so no single authority can.

๐Ÿ”ฌ Methodology Note: This dossier synthesizes German corporate registry data (Handelsregister), RIPE NCC WHOIS records, BGP routing observations (Hurricane Electric, Robtex), honeypot forensics (HASSH clustering, SSH key analysis), deep OSINT enrichment (AbuseIPDB, Shodan, OTX, VirusTotal, GreyNoise), PeeringDB absence verification, and EU sanctions legislation review. All active scanning was conducted via Tor to avoid attribution to our infrastructure.
โš  Personal capacity. Research published independently โ€” not reflecting employer views. Derived from passive observation of attacks against personal infrastructure. Full disclaimer โ†’
โ† Previous The Phantom ASN โ€” 3 / 17 Next โ†’