๐ฉ๐ช TI-2026-026C โ The German Gray Zone: How Three Companies Share One Phone Number and 42 Prefixes from Five Continents
Executive Summary: In the heart of Germany's Rhineland, three companies โ PIO-Hosting GmbH, XSServer GmbH, and SkyLink Data Center BV โ share personnel, phone numbers, and infrastructure while collectively routing traffic from five Regional Internet Registries. This is the story of how a phone number (+49 2451 9949570) connects a local hosting company to Iranian transit customers, Chinese IP lessees, Hong Kong reputation launderers, and a 628-IP scanning campaign that hit our honeypot.
Chapter 1: One Phone Number, Three Companies, Two Countries
Begin with the simplest fact: a German telephone number appears in the RIPE database for three distinct organizations:
| Organization | Registry | Address | Phone |
|---|---|---|---|
| PIO-Hosting GmbH | HRB 20998, Mรถnchengladbach | Sรผchtelner Str. 65, 41066 | +49 2451 9949570 |
| XSServer GmbH | HRB 21403, Aachen | Em Koddes 1, รbach-Palenberg | +49 2451 9949570 |
| SkyLink Data Center BV | KvK (Netherlands) | Eygelshoven, Netherlands | +49 2451 9949570 |
Three entities. Two countries. One phone number. The German area code 02451 covers the town of รbach-Palenberg โ population 24,000, on the Dutch border. XSServer is registered there. PIO-Hosting is 30km away in Mรถnchengladbach. SkyLink Data Center is across the border in Eygelshoven, Netherlands โ the same border region.
The personnel confirms what the phone number implies:
- Marcel Edler โ XSServer GmbH management, PIO-Hosting sponsor
- Rene Spellerberg โ XSServer GmbH associated
- Dirk Bellgart โ SkyLink Data Center BV associated
XSServer sponsors PIO-Hosting's RIPE membership. In RIPE terminology, this means XSServer vouched for PIO's existence and took responsibility for its resource allocations. You don't sponsor strangers.
โ Why create three companies for what appears to be one operation?
Legal compartmentalization. If PIO-Hosting receives an abuse complaint, the infrastructure runs on XSServer hardware. If XSServer faces legal action, the ASN belongs to PIO. If either is shut down, SkyLink (in a different country) provides upstream transit. Each entity is a firewall โ not for packets, but for liability.
Chapter 2: 42 Prefixes, Five Registries, Zero PeeringDB
AS198584 was allocated on May 11, 2023 โ exactly one month after HBING's AS208949 (April 11, 2023). One month. This is not coincidence; this is a rollout schedule.
Despite routing 42+ IPv4 prefixes (6,400+ addresses) from every Regional Internet Registry:
| RIR | Example Prefix | Registrant |
|---|---|---|
| RIPE (Europe) | 176.65.128.0/21 | ZeXoTeK IT-Services |
| ARIN (Americas) | 66.92.164.0/24 | Internet Utilities NA LLC |
| APNIC (Asia-Pacific) | 103.161.34.0/24 | Guosheng IDC |
| AFRINIC (Africa) | 41.x.x.0/24 | via Internet Utilities |
| LACNIC (Latin America) | Various | Lease arrangements |
...PIO-Hosting has zero presence on PeeringDB. No peering policy. No traffic statistics. No facility listings. No IX participation.
Every legitimate network operator lists on PeeringDB. It's free, it's industry standard, and it's how you establish peering relationships. The only reason to avoid it is if you don't want the transparency that comes with it.
๐ Read Between the Lines
- A legitimate hosting company with 6,400+ IPs would benefit enormously from PeeringDB presence โ it reduces transit costs and improves latency. Avoiding it costs money. The only return on that cost is opacity.
- Routing from all 5 RIRs means either a massive global transit deal (expensive, visible) or leasing third-party IP space (the IPXO model). The latter creates intentional confusion about who actually controls the addresses.
- Being allocated exactly one month after HBING suggests the same operator filed both applications sequentially, waiting for the first to complete before submitting the second.
Chapter 3: SkyLink Data Center โ The Dutch Upstream That Isn't Dutch
SkyLink Data Center BV operates AS44592 from Eygelshoven, Netherlands โ a small town literally touching the German border. The company claims 1-5 Tbps of capacity. Its technical contact shares the same +49 (German) phone number as XSServer and PIO.
SkyLink is PIO-Hosting's primary upstream transit provider. In BGP terms, this means:
Internet โ SkyLink (AS44592, "NL") โ PIO-Hosting (AS198584, "DE") โ Customer prefixes
But if SkyLink and PIO share personnel and phone numbers, this "upstream" relationship is a fiction. You cannot be your own upstream in any meaningful regulatory sense. It's the equivalent of a company lending money to its own subsidiary and claiming it as arm's-length revenue.
Dirk Bellgart appears as SkyLink's contact. The same infrastructure runs out of the same border region. The "Dutch" upstream is about as Dutch as PIO-Hosting is independent of XSServer.
โ Why register in two different countries when the operation is in the same building?
Jurisdictional arbitrage. If German authorities (BKA, BfV) investigate PIO-Hosting's customer traffic, the upstream is "in the Netherlands." Dutch authorities (KLPD) must be separately engaged. The request must go through international legal assistance treaties (MLAT). By the time both countries coordinate, the customer has moved to a different prefix. For an operation handling Iranian transit and reputation-laundered IPs, this 2-week delay is the entire product.
Chapter 4: ZeXoTeK IT-Services โ Where the Attacks Originate
Our honeypot data traces back to a specific German LIR: ZeXoTeK IT-Services GmbH (HRB 30659 Zweibrรผcken, Hauptstrasse 29, 76891 Erlenbach, Germany). Director: Jens Winter.
ZeXoTeK operates the 176.65.128.0/21 block via PIO-Hosting's AS198584. From this block:
| IP | Threat Score | CVEs | Abuse Reports | Classification |
|---|---|---|---|---|
176.65.131.189 | 100/100 | 60 | 586 | C2 Panel |
176.65.131.188 | 100/100 | โ | 450+ | C2 Panel |
176.65.136.31 | 92/100 | โ | 200+ | Scanner |
IP 176.65.131.189 alone has 60 CVEs open across ports 8080/8090, confirmed C2 infrastructure, and 586 AbuseIPDB reports. This is not a compromised server โ servers with 60 open CVEs running C2 panels are intentionally configured for malicious operations.
The 628-IP Campaign
All PIO-Hosting infrastructure participates in a single massive scanning campaign identified by HASSH fingerprint 14b2ddda386a4d10 (libssh2_1.11.0). This campaign spans 628 unique IPs across 48 countries. The shared HASSH proves identical tooling โ every node runs the same SSH brute-force client.
SSH Key Sharing
IP 176.65.131.189 (ZeXoTeK/PIO) shares SSH key fingerprint 44:c9:7f:6c:5d:53:4f:5d:38... with Scaleway France infrastructure. This is the strongest operator-identity signal possible โ the same private key deployed across jurisdictions means the same human operates both.
โ Is Jens Winter aware his IP space hosts C2 panels?
With 586 AbuseIPDB reports on a single IP and Spamhaus listings on the block, the answer is unambiguous: yes. German law (ยง13 TMG, ยง10 TMG) requires hosting providers to act on knowledge of illegal activity. Either Winter actively condones it (making ZeXoTeK a bulletproof reseller) or he has never once checked abuse reports for blocks he personally registered. Neither interpretation is innocent.
Chapter 5: IPv4 Superhub โ The Reputation Laundromat
Among PIO-Hosting's customer base sits IPv4 Superhub Limited (Hong Kong Company Registry #2749673), at Unit 1302, 13/F APEC Plaza, Kwun Tong, Kowloon.
Their website (ipv4superhub.com) explicitly advertises:
"IP Reputation Repair โ We specialize in Spamhaus SBL/PBL delisting, SORBS removal, and abuse report resolution."
This is literally a reputation laundering service. The business model: buy IP blocks with destroyed reputation (cheap because they're blacklisted), route them through a new AS (PIO-Hosting provides this), get them delisted from Spamhaus, sell them at clean-IP prices.
The profit margin is enormous. Blacklisted IPv4 space trades at $15-20/IP. Clean space trades at $35-45/IP. A /24 (256 IPs) goes from ~$4,000 blacklisted to ~$10,000 clean. IPv4 Superhub's cut plus PIO's transit fees make this a $6,000+ profit per /24 "cleaned."
๐ Read Between the Lines
- IPv4 Superhub's service only works if the transit provider doesn't respond to abuse reports. If PIO-Hosting actioned Spamhaus listings, the IPs would be re-blacklisted immediately. The business relationship proves PIO ignores abuse complaints by design.
- Routing blacklisted IPs through a fresh ASN (allocated May 2023) is the key innovation โ Spamhaus blacklists individual IPs and sometimes whole ASNs. A new ASN has no history. It's clean by definition.
- This is why AS198584 was created: not to host websites, but to provide a reputation reset mechanism for tainted IP space.
Chapter 6: The Iranian Transit โ Four LIRs Through Germany
In June 2026, four Iranian LIRs began routing through AS198584:
| LIR | Block | Maintainer |
|---|---|---|
| lir-ir-salehi | 91.206.28.0/24 | lir-ir-salehi-1-MNT |
| lir-ir-seyeddavood | 91.206.29.0/24 | lir-ir-seyeddavood-1-MNT |
| lir-ir-mazdab | 91.207.x.0/24 | lir-ir-mazdab-1-MNT |
| lir-ir-nahor | Various | lir-ir-nahor-1-MNT |
Additionally, an InterLIR Marketplace block (212.102.x.0/24) with Iranian contact information routes via AS198584.
The Legal Question
EU Council Regulation (EC) No 267/2012 imposes comprehensive sanctions on Iran. Article 23(2) prohibits "making available, directly or indirectly, funds or economic resources" to designated persons or entities. Internet transit is an economic resource.
The question isn't whether German companies can provide IP transit to Iranian entities โ that depends on who those entities are and what they do. The question is: did PIO-Hosting/XSServer perform any due diligence whatsoever?
Four Iranian LIRs onboarded simultaneously suggests a bulk arrangement, not individual customer relationships. Someone (possibly via InterLIR marketplace) brokered this. The timing โ June 2026 โ coincides with EU-Iran nuclear deal tensions.
โ Is providing BGP transit to Iranian LIRs actually illegal under EU sanctions?
It depends. If the LIRs are connected to IRGC (Islamic Revolutionary Guard Corps), sanctioned banks, or designated entities โ yes, it's a criminal offense under German law (ยง18 AWG) carrying up to 10 years imprisonment. If they're purely private enterprises providing civilian internet โ it's a gray area that requires specific license applications. The critical point: PIO-Hosting's structure (no KYC visible, no PeeringDB, bulletproof reputation) suggests they didn't ask the question. Not asking is not a defense.
Chapter 7: The Chinese Ghost โ Guosheng IDC
GSJZ (China) Technology Co., Limited (ORG-GIL15-AP) appears as a RIPE registrant for PIO-Hosting sub-leased blocks. Registered address: RM4, 16/F Ho King Commercial Centre, 2-16 Fayuen Street, Mong Kok, Kowloon, Hong Kong.
The entity has:
- A dead domain (gsjz.net โ not resolving)
- A Gmail abuse contact (unusual for any legitimate registrant)
- IPs (103.161.34.x) that geolocate to Netherlands but are registered under APNIC (Asia-Pacific)
- No visible web presence, customer base, or service description
The geographic discrepancy is the signature: APNIC-registered blocks physically hosted in Europe, transited via a German ASN, registered to a Hong Kong shell with a dead domain. This is precisely the "phantom" pattern that triggered our investigation.
โ What is GSJZ/Guosheng IDC actually doing with European-hosted Asian IP space?
The most charitable interpretation: arbitrage. APNIC IPs are cheaper than RIPE IPs due to regional allocation politics. Buy APNIC space, host it in Frankfurt where the servers physically are, profit from the price difference. The less charitable interpretation: jurisdiction shopping. Asian IP space governed by APNIC policies, physically in Germany governed by EU law, registered to a Hong Kong company governed by HK law. Three jurisdictions, no single authority has full visibility. Abuse complaints go to APNIC, which forwards to a Gmail address that doesn't respond, while the actual server sits in a German datacenter untouched.
Chapter 8: The Smoking Gun โ Vincentas Grinius Routes Through Both
The structural proof linking PIO-Hosting to HBING comes from a single RIPE maintainer object: netutils-mnt.
Internet Utilities NA LLC (Wilmington, Delaware) routes ARIN blocks (66.92.164.0/24, 72.9.233.0/24) via AS198584 (PIO-Hosting). The administrative contact: VINCENTAS GRINIUS, 6th Floor, 9 Appold Street, London EC2A 2AP.
The same netutils-mnt object also routes prefixes via AS208949 (HBING LIMITED) โ the UK bulletproof operator from our previous installments.
Vincentas Grinius is the co-founder of IPXO UAB (Lithuania, formerly HEFICED) โ the world's largest IP address marketplace, managing 14 million+ IPv4 addresses and reporting $55 million revenue.
| Entity | Registry | Role |
|---|---|---|
| IPXO UAB | Lithuania #307097001 | IP marketplace platform |
| Internet Utilities EU | Slovenia/UK #12540160 | European transit entity |
| Internet Utilities NA LLC | Delaware, USA | Americas transit entity |
| netutils-mnt | RIPE maintainer | Routes via BOTH bulletproof ASNs |
One person. One maintainer object. Two bulletproof ASNs. $55 million in revenue.
๐ Read Between the Lines
- IPXO sits on the RIPE Anti-Abuse Working Group. The co-founder of a platform whose transit entities route through bulletproof networks participates in setting RIPE abuse policy. This is regulatory capture in its purest form.
- The academic paper "Sublet Your Subnet" (CAIDA/UCSD 2024) documents IPXO/HEFICED's role in enabling IP address abuse through sub-leasing. The research community has noticed.
- $55M revenue flowing through entities that transit via bulletproof ASNs hosting C2 panels, Iranian LIRs, and reputation launderers. The revenue isn't from web hosting โ it's from providing the infrastructure layer that makes these operations possible.
- If IPXO is the marketplace and PIO/HBING are the transit providers, then netutils-mnt is the receipt. It's the one object in the RIPE database that proves the commercial relationship between a $55M company and bulletproof hosting.
Chapter 9: The Architecture of Impunity
Zoom out. The complete structure is:
XSServer GmbH (DE, HRB 21403) โ operations team
โ sponsors RIPE membership
PIO-Hosting GmbH (DE, HRB 20998) โ AS198584 holder
โ transit from
SkyLink Data Center BV (NL, AS44592) โ "upstream" (same phone)
Customers of AS198584:
โโโ ZeXoTeK (DE) โ 176.65.x.x โ C2 panels, 628-IP botnet campaign
โโโ IPv4 Superhub (HK) โ reputation laundering service
โโโ Guosheng IDC (HK/CN) โ dead-domain shell, APNIC space in Europe
โโโ 4ร Iranian LIRs โ potential sanctions evasion
โโโ Internet Utilities / IPXO โ $55M marketplace, routes via BOTH ASNs
Every layer adds a jurisdiction. Every entity adds a compliance boundary. Every relationship is technically legal when viewed in isolation. Combined, they form a bulletproof hosting platform masquerading as legitimate German infrastructure.
The German authorities (BKA, BfV) see a registered GmbH with a Handelsregister number. RIPE sees an NCC member in good standing. The Dutch see a data center. Hong Kong sees a technology company. Lithuania sees a successful IP marketplace startup. Nobody sees the whole picture โ because the structure is designed so no single authority can.
๐ Series Navigation
โ 026A: The Phantom ASN (Overview) ยท โ 026B: The Bulletproof Archipelago (HBING) ยท 026C: The German Gray Zone (PIO-Hosting) ยท 026D: The IP Marketplace โ ยท 026E: The Offshore Chain โ ยท 026F: The Sanctions Question โ