๐งฌ TI-2026-026K โ The Predecessor Network: How One Border Data Center Became the Backbone of an International Bulletproof Operation
Executive Summary: Every criminal enterprise has a genealogy. The Phantom ASN network did not emerge from vacuum in 2023 โ it evolved from a lineage of organizations operating from the same data center on the German-Dutch border, with overlapping personnel, shared phone numbers, and a decade of documented hosting activity. This dossier traces the corporate family tree: from SkyLink Data Center BV (AS44592, est. ~2014) through XSServer GmbH (HRB 21403 Aachen, est. 2022) to PIO-Hosting GmbH (AS198584, allocated May 2023), and finally to HBING Ltd (British Virgin Islands) โ the offshore opacity layer that completes the architecture. Three corporate identities. Two managing directors. One phone number. One data center. One operation.
Along the way we discover MR 1337 GmbH โ a hidden company named in hacker leetspeak, run by the same two men. We find ZeXoTeK IT-Services GmbH โ a Ukrainian-German entity whose single IP accumulated 4,931 abuse reports, whose RIPE maintainer manages 7 of 17 malicious PIO IPs. We trace Guosheng IDC โ a Chinese IDC leasing IP blocks that somehow end up announced from Eygelshoven. And we ask the questions that corporate registries never answer: Who is really behind this, and what are they actually doing?
Chapter 1: The Foundation โ SkyLink Data Center BV (AS44592)
The physical foundation of the Phantom ASN ecosystem is SkyLink Data Center BV, a Dutch company operating AS44592 since approximately 2014. Its location: converted industrial halls at Eygelshoven, Netherlands โ a former mining town pressed against the German border, 1.2 km from German territory, 4.5 km from รbach-Palenberg.
SkyLink presents itself as a legitimate data center. And in infrastructure terms, it is serious:
| Attribute | Value | Source |
|---|---|---|
| ASN | AS44592 (10+ years operational) | bgp.tools |
| BGP Peers | 450 networks | PeeringDB |
| Upstream Carriers | 7 | bgp.tools |
| IPv4 Prefixes | 194 announced | RIPE routing tables |
| Power Capacity | 1-2.2 MW | PeeringDB facility data |
| Traffic Volume | 1-5 Tbps | PeeringDB self-reported |
| Internet Exchanges | 16 IXPs | PeeringDB IX list |
| RIPE Admin Contact | Dirk Bellgart (DB24958-RIPE) | RIPE DB |
| Contact Phone | +49 2451 9949570 | RIPE DB |
450 peers. 16 internet exchanges. Up to 5 Tbps. Legitimate companies like Pronkin.net (AS202413) openly advertise "located at SkyLink data center." This is real infrastructure.
โ Why a German Phone Number for a Dutch Data Center?
SkyLink Data Center BV is a Dutch entity. Its RIPE admin contact phone: +49 2451 9949570. A German number. The +49 2451 prefix maps to รbach-Palenberg, Germany โ 4.5 km from Eygelshoven across the border.
This is not geographic coincidence โ it's a jurisdictional strategy. German police have jurisdiction over the people (who live in Germany). Dutch police have jurisdiction over the servers (which sit in the Netherlands). Neither has jurisdiction over both simultaneously without cross-border cooperation agreements that take months to establish.
Sources: PeeringDB AS44592; RIPE DB handle DB24958-RIPE; German numbering plan +49 2451 = รbach-Palenberg
โ Who Is Dirk Bellgart?
The RIPE database lists Dirk Bellgart (DB24958-RIPE) as the administrative contact for SkyLink Data Center BV. He is the registered keeper of 194 IPv4 prefixes, the face of a 450-peer BGP network, the person responsible for abuse handling.
But Bellgart does not appear as a director of XSServer GmbH or PIO-Hosting GmbH in the German Handelsregister. Those roles belong to Marcel Edler and Renรฉ Spellerberg. So who is Bellgart? An employee? A technical contractor? A nominee whose name appears on public-facing records while the actual decision-makers stay one step removed? The corporate registries name Edler and Spellerberg. The RIPE database names Bellgart. Nobody names all three together in any single document.
Sources: RIPE DB DB24958-RIPE; Amtsgericht Aachen HRB 21403 (XSServer directors: Edler, Spellerberg โ no Bellgart)
โ What If SkyLink Is the Permanent Entity and Everything Else Is Disposable?
XSServer registered in 2022. PIO-Hosting received its ASN in May 2023. SkyLink has been operating since ~2014 โ at least 8 years before any of the others appeared.
In the bulletproof hosting lifecycle, the physical infrastructure is the only thing that cannot be regenerated quickly. Peering agreements take years to build. IXP memberships take months. 194 prefixes represent thousands of RIPE interactions. SkyLink is the anchor โ the asset that survived whatever came before XSServer and will survive whatever comes after PIO-Hosting. When PIO-Hosting accumulates enough heat, it will be dissolved. SkyLink will remain. A new GmbH will inherit the prefixes. The cycle continues.
Sources: bgp.tools AS44592 historical data; PeeringDB facility record; RIPE NCC AS198584 allocation date (May 2023)
๐ Reading Between the Lines
- SkyLink peers with 450 networks. For context, a typical mid-size European ISP peers with 50-150 networks. SkyLink's peering footprint is closer to a Tier 2 carrier than a single-building data center. Why does a converted industrial hall in a former mining town need Tier 2-level peering?
- The answer: because its customers need traffic to be accepted everywhere without question. Extensive peering means routes are propagated globally. Global route acceptance means IP blocks hosted here can reach any target on earth โ including targets that would filter traffic from known-bad ranges if it came through fewer paths.
- SkyLink shares a BGP upstream (AS44592) with AS53356 (an entity that also transits PIO-Hosting's AS198584). This forms a closed routing loop: PIO announces โ SkyLink transits โ downstream arrives. All traffic stays within the family.
Chapter 2: The Operating Company โ XSServer GmbH (HRB 21403)
On June 10, 2022, XSServer GmbH was registered at the District Court of Aachen under HRB 21403. Address: Em Koddes 1, รbach-Palenberg โ 4.5 km from SkyLink. Managing directors:
| Name | Role | Residence | Source |
|---|---|---|---|
| Marcel Ingo Edler | Geschรคftsfรผhrer | รbach-Palenberg, DE | NorthData |
| Renรฉ Spellerberg | Geschรคftsfรผhrer | Wรผrselen, DE | CompanyHouse |
Capital: โฌ25,000 (legal minimum). VAT: DE314405351. The XSServer website states its facility is "located near Aachen in Holland." Contact phone: +49 2451 9949570 โ the same number as SkyLink's RIPE admin.
โ What Is XSServer's Actual Business Model?
XSServer GmbH is registered as a "hosting company." Its website offers rootservers, VPS, colocation, DDoS protection. Standard hosting fare. But its rating on WHTop.com: 4.4 out of 10, ranked 6,648th of 6,868 hosting providers โ bottom 3%.
A company in the bottom 3% of its industry does not stay in business by being good at what it officially does. It stays in business because what it actually sells is something different from what its website advertises. The customers who pay XSServer aren't buying uptime or support quality. They're buying tolerance โ the guarantee that their servers won't be suspended regardless of what they're used for.
Sources: xsserver.eu; WHTop.com hosting rankings; XSServer DDoS protection marketing ("filtered GRE tunnels")
โ Why Does XSServer Market "DDoS Protection" So Prominently?
XSServer's website prominently features DDoS protection with "filtered GRE tunnels" and dedicated anti-DDoS infrastructure. Most small hosting companies bury DDoS protection in their feature list. XSServer leads with it.
In legitimate hosting, DDoS protection defends your website from attackers. In bulletproof hosting, DDoS protection defends your criminal infrastructure from rival criminals trying to take it offline. Botnet operators routinely DDoS competing botnets. C2 servers get targeted by vigilantes. If you're hosting criminal infrastructure, your biggest threat isn't law enforcement โ it's other criminals. That's what the "filtered GRE tunnels" are for.
โ What Does "alleinvertretungsberechtigt" Mean โ and Why Does It Matter?
Both the CompanyHouse and NorthData entries for XSServer note that each director is "alleinvertretungsberechtigt" โ each is individually authorized to represent the company alone, without the other's consent.
In German corporate law, this means either Edler or Spellerberg can independently sign contracts, open bank accounts, dissolve the company, or transfer assets โ without the other knowing. This is unusual for a two-person GmbH. It is standard practice when the operators need the ability to act unilaterally and quickly โ for example, to dissolve the company overnight if law enforcement appears at one director's door while the other is across the border.
Sources: CompanyHouse โ Edler profile (alleinvertretungsberechtigt); German GmbH law ยง35 GmbHG
โ Why Register XSServer in 2022 When SkyLink Already Existed?
SkyLink was operational since ~2014. It already had the data center, the BGP peers, the IP allocations, the RIPE membership. Why create XSServer GmbH in 2022?
One explanation: SkyLink BV is a Dutch company. Dutch corporate transparency requirements increased with the UBO (Ultimate Beneficial Owner) registry, which became mandatory in September 2020. By creating a German GmbH (XSServer) as the RIPE LIR and operating entity, the operators moved the customer-facing business into German jurisdiction โ where โฌ25,000 minimum capital creates a perfect liability firewall โ while keeping the infrastructure in the Netherlands. The timing fits: UBO registry goes live in 2020. Operators observe the compliance implications. XSServer registers in 2022. A new jurisdiction, a new shield.
Sources: Dutch UBO Registry (Handelsregister UBO-register), effective Sept 2020; XSServer registration date June 2022 (Amtsgericht Aachen)
๐ Reading Between the Lines
- โฌ25,000 registered capital for a company routing 1-5 Tbps of traffic. The capitalization is the legal minimum, designed to minimize liability exposure โ not to reflect actual operations worth millions in infrastructure.
- XSServer explicitly markets DDoS protection as a primary feature. In bulletproof hosting, DDoS protection defends criminal infrastructure from rival criminals. This is the tell.
- Both directors have "alleinvertretungsberechtigt" โ sole authority. In a two-person company, this creates a dead man's switch: if one is arrested, the other can independently dissolve the entity and move assets.
Chapter 3: The Hidden Entity โ MR 1337 GmbH
Corporate registry searches on Edler and Spellerberg reveal what network analysis cannot: they co-direct MR 1337 GmbH, another German company registered at the same Aachen court. Same directors. Same minimum capital. Same jurisdiction.
| Field | MR 1337 GmbH | XSServer GmbH |
|---|---|---|
| Directors | Marcel Edler, Renรฉ Spellerberg | Marcel Edler, Renรฉ Spellerberg |
| Capital | โฌ25,000 | โฌ25,000 |
| Court | Aachen | Aachen |
| Region | Aachen area | รbach-Palenberg |
โ What Is "1337" and What Does It Reveal About the Operators' Self-Image?
In hacker culture, 1337 is "leet" (L=1, E=3, E=3, T=7) โ elite. It originated in 1980s bulletin board systems to signal membership in the hacking community.
Naming your German GmbH "MR 1337" is the equivalent of naming your shell corporation "Mr. Elite Hacker, Inc." This is not a name chosen by businesspeople trying to appear legitimate. This is a name chosen by people who identify with hacker culture, who see their work as part of that world, and who are either confident enough to signal it openly or careless enough to leave it in public registries.
Sources: NorthData โ Marcel Edler (MR 1337); NorthData โ Renรฉ Spellerberg (MR 1337)
โ What Does MR 1337 GmbH Actually Do?
MR 1337 GmbH appears in the Handelsregister. It has directors, capital, a registered address. What it does not have: a website, a public service offering, a customer-facing product. No search engine returns any service or product associated with MR 1337 GmbH.
A company with no public presence, no product, no website, run by the same people who run XSServer and operate out of SkyLink. Three possibilities: (1) It's a holding company that owns assets or contracts that Edler and Spellerberg want separated from XSServer's liability exposure. (2) It's the entity that contracts directly with customers whose activities would be too risky to invoice through XSServer. (3) It's a dormant reserve โ pre-registered so that when XSServer or PIO-Hosting needs to be dissolved, a successor entity is already available, already compliant, already able to sign new contracts on day one. All three explanations point to the same conclusion: MR 1337 GmbH exists to do what XSServer cannot be seen doing.
โ What If MR 1337 GmbH Is the Real Company, and XSServer Is the Storefront?
We see XSServer because it has a website. We see PIO-Hosting because it has an ASN. We see SkyLink because it has PeeringDB entries. MR 1337 GmbH has none of these. It is invisible unless you search the directors' names.
The most dangerous companies are the ones you cannot find by looking at their products. MR 1337 may be where the financial flows converge โ where revenues from bulletproof hosting customers land before being distributed to the operational entities. German GmbH audit requirements for companies under certain thresholds are minimal. A company with โฌ25,000 capital and no external investors faces effectively no mandatory audit. It can receive and disburse funds without public disclosure of its financial statements.
Sources: German HGB ยง267 (small company exemptions); NorthData showing no financial filings for MR 1337 GmbH
๐ Reading Between the Lines
- Two men. At minimum three companies (XSServer, MR 1337, PIO-Hosting). One phone number shared with a fourth entity (SkyLink BV). All within a 10-km radius near Aachen.
- The โฌ25,000 minimum capital ร 3 entities = โฌ75,000 total liability exposure. For an operation routing terabits of traffic and facilitating millions in cybercrime losses. The corporate structures aren't designed for business efficiency โ they're designed for liability containment and rapid dissolution.
- "MR 1337" is cultural self-identification. These aren't businesspeople who accidentally attract bad customers. These are operators who see themselves as part of the hacker ecosystem.
Chapter 4: The Customer-Facing Shell โ PIO-Hosting GmbH (AS198584)
In May 2023, RIPE NCC allocated AS198584 to PIO-Hosting GmbH. Sponsoring LIR: ORG-XG40-RIPE โ XSServer GmbH. PIO-Hosting immediately began announcing 28 IPv4 prefixes through SkyLink's infrastructure.
Our honeypot data tells the story that corporate filings don't:
| IP | Threat | Abuse | Hits | RDAP Org | Geo | BGP |
|---|---|---|---|---|---|---|
| 194.120.230.72 | 78 | 100% | 48 | RIPE-NCC-HM-MNT | ๐ณ๐ฑ | ๐ญ๐ฐ |
| 195.62.32.180 | 85 | 100% | 48 | PIO-Hosting | ๐ณ๐ฑ | ๐ฉ๐ช |
| 194.120.230.28 | 90 | 100% | 42 | RIPE-NCC-HM-MNT | ๐ณ๐ฑ | ๐ญ๐ฐ |
| 176.65.136.31 | 90 | 100% | 42 | PIO-Hosting | ๐ณ๐ฑ | ๐ฉ๐ช |
| 103.161.34.59 | 79 | 100% | 36 | Guosheng IDC | ๐ณ๐ฑ | ๐ญ๐ฐ |
| 176.65.131.188 | 86 | 100% | 36 | MNT-ZEXOTEK | ๐ณ๐ฑ | ๐ฉ๐ช |
| 176.65.131.189 | 90 | 100% | 12 | MNT-ZEXOTEK | ๐ณ๐ฑ | ๐ฉ๐ช |
| 176.65.128.179 | 82 | 100% | 12 | MNT-ZEXOTEK | ๐ณ๐ฑ | ๐ฉ๐ช |
| 176.65.136.174 | 85 | 100% | 12 | PIO-Hosting | ๐ณ๐ฑ | ๐ฉ๐ช |
17 unique PIO IPs in our threat intel database. All 17 at 100% abuse confidence. Every single one geolocated to NL but registered in DE or HK. Combined: 312+ honeypot sessions.
โ Why Do 100% of PIO-Hosting IPs in Our Database Have 100% Abuse Scores?
Zero out of 17 PIO-Hosting IPs in our threat intelligence database have an abuse confidence score below 100%. Not 95%. Not 99%. 100% across all 17.
The probability of 17 randomly selected IPs from a legitimate hosting provider all having maximum abuse scores is effectively zero. This is not a hosting company with a bad-customer problem. This is infrastructure that exists to generate malicious traffic. The customers aren't misbehaving โ the infrastructure is performing as designed.
โ Why Are Some PIO IPs Registered in Hong Kong?
Three PIO-Hosting IPs (194.120.230.28, 194.120.230.72, 103.161.34.59) show cymru_country=HK and rdap_country=HK despite being geolocated to the Netherlands and announced from a German ASN.
These IP blocks were originally allocated by APNIC (the Asia-Pacific RIR), registered to Hong Kong entities, and then routed through PIO-Hosting's European ASN. This is geographic IP laundering: blocks allocated in one region are announced from another, making geographic filtering ineffective. A firewall blocking "Hong Kong IPs" won't block them (they geolocate to NL). A firewall blocking "Dutch IPs" might block legitimate Dutch traffic. The discrepancy is the weapon.
Sources: RIPE + APNIC whois; cymru_country vs abuse_country enrichment; Shodan geolocation
โ What If PIO-Hosting Doesn't Exist to Make Money from Hosting?
PIO-Hosting's website (pio.hosting) exists but offers minimal information. The Scamalytics fraud profile lists PIO-Hosting with associated organizations including "Superhub Limited" โ another entity that appears in no corporate filing we can find.
Consider the alternative: PIO-Hosting's purpose isn't to profit from monthly hosting fees. Its purpose is to launder IP addresses โ to take blocks from various sources (APNIC allocations, ZeXoTeK holdings, Guosheng leases, HBING BVI allocations) and announce them through a single German ASN via a Dutch data center. The "hosting" is a cover story. The actual service is: providing a legitimate-looking BGP origin for IP blocks that would otherwise be too suspicious to route. This would make PIO-Hosting an IP laundering service rather than a hosting company.
โ The 628-IP Campaign โ What Are PIO's Customers Part Of?
Our campaign detection identified hassh-14b2ddda386a4d10: a HASSH cluster of 628 IPs across 48 countries using libssh2_1.11.0. PIO-Hosting IPs are members of this campaign. So are IPs from AS16276 (OVH), AS32475 (SingleHop), AS40676 (Psychz), AS36352 (ColoCrossing).
628 IPs across 48 countries, all sharing the same SSH client fingerprint, generating 16,253 attack attempts. This is not "bad customers" โ this is a globally distributed scanner/botnet operation. PIO-Hosting isn't just hosting some of these nodes โ its infrastructure is embedded in a 628-node attack network that spans legitimate providers worldwide. The question isn't "why is PIO bad?" The question is: is PIO-Hosting the coordination point for this 628-node operation, or just one of many providers being abused? The SSH key sharing evidence (Chapter 7) suggests the former.
Sources: Campaign hassh-14b2ddda386a4d10; 628 IPs, 48 countries, 16,253 attempts
๐ Reading Between the Lines
- PIO-Hosting's website is nearly empty. Legitimate hosting companies invest in marketing because they need customers. PIO doesn't need to attract customers โ its customers find it through word of mouth in underground forums. The empty website is a compliance checkbox, not a customer acquisition tool.
- Scamalytics associates PIO-Hosting with "Superhub Limited" โ a ghost entity. Shell companies associating with phantom companies: this is organizational fog designed to prevent any single investigation from mapping the full picture.
- The 15/15 geographic discrepancy rate (all IPs show different countries for geo vs RDAP/BGP) is not an accident. It's a feature โ every IP address in this network is deliberately configured to confuse automated geographic analysis.
Chapter 5: The Ukrainian Connection โ ZeXoTeK IT-Services GmbH (AS8649)
ZeXoTeK IT-Services GmbH operates AS8649 and the RIPE maintainer MNT-ZEXOTEK. Despite the "GmbH" designation, ZeXoTeK has Ukrainian admin contacts. It manages 4 IPv4 prefixes (~10,000 IPs). 7 of 17 PIO-Hosting IPs that attacked our honeypot are registered under MNT-ZEXOTEK.
โ 4,931 Abuse Reports on a Single IP โ How Is ZeXoTeK Still Operating?
AbuseIPDB shows that 176.65.134.34 (ZeXoTeK, AS8649) received 4,931 abuse reports from 135 distinct sources. That is 37 unique organizations reporting the same IP every single day for four months.
4,931 reports from 135 sources is not a "failure to respond to abuse." It's a policy of ignoring abuse. Under RIPE NCC guidelines, a resource holder must maintain accurate abuse-c contact information and respond to abuse reports. ZeXoTeK demonstrably does neither. The question is: why does RIPE NCC continue to honor ZeXoTeK's resource allocations? The answer: RIPE has no enforcement mechanism beyond deregistration, and deregistration would simply push ZeXoTeK's IP blocks to another maintainer โ perhaps one already in the family.
Sources: AbuseIPDB โ 4,931 reports, 135 sources; ipapi.is AS8649 โ 9,984 IPs
โ Is ZeXoTeK a German Company or a Ukrainian One?
The name says "GmbH" โ Gesellschaft mit beschrรคnkter Haftung, a German legal form. But the RIPE admin contacts list Ukrainian addresses. The RIPE maintainer name is MNT-ZEXOTEK. The ASN (8649) is assigned to "ZeXoTeK IT-Services GmbH" with country "DE."
ZeXoTeK occupies a deliberate ambiguity. For German courts, it's a German entity subject to German law. For Ukrainian authorities, the contacts are Ukrainian. For RIPE NCC, the maintainer is just a database handle. Each authority sees the part of ZeXoTeK that suggests someone else has jurisdiction. This is the same pattern seen in every entity in this network: jurisdiction is not a location but a strategy.
โ What Is the Financial Relationship Between ZeXoTeK and PIO-Hosting?
ZeXoTeK manages IP blocks (under MNT-ZEXOTEK) that are announced through PIO-Hosting's ASN (198584), via SkyLink's physical infrastructure (AS44592). No public filing, partnership agreement, or contractual disclosure documents this arrangement.
There are two models: (1) ZeXoTeK is a customer of PIO-Hosting, paying for BGP transit to announce its own IP blocks โ in which case PIO-Hosting knowingly provides transit for an entity with 4,931 abuse reports on a single IP. (2) ZeXoTeK and PIO-Hosting share common beneficial ownership, and the separate corporate identities exist to distribute legal risk across jurisdictions (Germany + Ukraine + Netherlands). Both models describe a criminal enterprise. The distinction matters only for prosecutors deciding whom to charge.
๐ Reading Between the Lines
- A Ukrainian IT company, registered as a German GmbH, maintaining RIPE objects for IP blocks announced from a German ASN via a Dutch data center. Four countries. Zero clear jurisdiction.
- 4,931 abuse reports on one IP. 135 independent reporters. This number is not "many reports." It is a statistical impossibility under any model where abuse handling functions at all. The only explanation: abuse reports at ZeXoTeK are received and deliberately discarded.
- ZeXoTeK's 7 IPs on PIO's ASN generated 102 honeypot sessions โ more per-IP than PIO-Hosting's own IPs. ZeXoTeK isn't a passive tenant; its blocks are among the most actively malicious on the entire ASN.
Chapter 6: Their Own Servers Are Full of Holes โ The Vulnerability Paradox
Shodan passive scanning reveals that PIO-Hosting's own infrastructure โ the servers attacking our honeypot โ are themselves riddled with known vulnerabilities:
| IP | Threat | Open Ports | CVEs |
|---|---|---|---|
| 176.65.131.189 | 90 | 8080, 8090 | 58 CVEs (incl. CVE-2019-11043 RCE) |
| 194.120.230.28 | 90 | 8080, 8090, 31210 | 31 CVEs (incl. CVE-2023-44487 HTTP/2 Rapid Reset) |
| 176.65.131.188 | 86 | 80 | 56 CVEs |
| 195.62.32.180 | 85 | 8080 | 26 CVEs |
| 176.65.136.174 | 85 | 80, 123, 161, 5272, 6500, 8000, 8080, 8089, 31210 | CVE-2023-44487, CVE-2025-23419 |
| 176.65.128.179 | 82 | 22, 137, 445, 631, 9091, 18062, 31210 | CVE-2023-44487, CVE-2021-23017 |
58 CVEs on a single IP. Including remote code execution vulnerabilities from 2019 that remain unpatched in 2026. Ports 137 (NetBIOS), 445 (SMB), 631 (CUPS) โ services that should never be internet-facing.
โ Why Are Attack Servers Running 58 Unpatched CVEs?
These servers attack our honeypot over SSH with credential stuffing. They are offensive infrastructure. Yet they run PHP versions from 2018, have NetBIOS and SMB exposed to the internet, and carry remote code execution vulnerabilities dating back 7 years.
Two explanations, both damning: (1) These servers are themselves compromised โ they were hacked by the botnet operators who then use them as attack proxies. The original tenant never patched them, and the hijackers don't care. This means PIO-Hosting's customers are victims of their own provider's ecosystem. (2) The attack infrastructure is intentionally cheap and disposable โ unpatched because no one invests in maintaining attack servers. When one gets burned (blocklisted or seized), you spin up another. The CVEs are a feature: they keep the infrastructure cheap, replaceable, and deniable.
โ What Are Ports 31210, 9091, and 18062 Used For?
Multiple PIO IPs expose uncommon ports: 31210 (appears on 3 IPs), 9091, 18062. These are not standard HTTP/SSH/mail ports. They don't correspond to well-known services.
Port 31210 is commonly associated with Kubernetes NodePort services or custom C2 (Command & Control) frameworks. Port 9091 is used by Transmission (BitTorrent daemon) and some C2 panels. Port 18062 is non-standard and potentially a custom application. These ports, combined with the attack traffic these IPs generate, suggest these servers are not just SSH scanners โ they're multi-purpose nodes in a larger infrastructure that includes C2 communication, data exfiltration, and possibly botnet coordination.
Sources: Shodan port scan data; IANA port assignments; C2 framework documentation
Chapter 7: The Offshore Layer โ HBING Ltd and Guosheng IDC
HBING Limited: British Virgin Islands. AS138915. 3,328 IPs across 11 ranges in 8 countries. Connected to "Internet Utilities Europe and Asia Limited" (Slovenia).
| HBING IP | Threat | Geo | RDAP | Org |
|---|---|---|---|---|
| 102.129.200.117 | 93 | ๐ณ๐ฑ | ๐บ๐ธ | IPXO Incident Response |
| 102.129.200.101 | 88 | ๐ณ๐ฑ | ๐บ๐ธ | IPXO Incident Response |
| 45.88.0.252 | 83 | ๐ณ๐ฑ | ๐ต๐ฑ | lir-vg-itweb-1-MNT |
| 45.148.146.52 | 79 | ๐ณ๐ฑ | ๐ต๐ฑ | lir-vg-itweb-1-MNT |
| 45.148.145.60 | 78 | ๐ณ๐ฑ | ๐ง๐ช | lir-vg-itweb-1-MNT |
โ Why Does a BVI Company Need 3,328 IPs Across 8 Countries?
The BVI population: 30,000. Total BVI IPv4 space: 96,893 addresses. HBING alone controls 3.4% of all BVI IP allocations.
HBING isn't a hosting company serving BVI customers. It's an IP holding vehicle โ a legal structure designed to hold IP allocations in a jurisdiction where beneficial ownership is not publicly disclosed, then route those IPs through physical infrastructure in jurisdictions where law enforcement cooperation is slow. The BVI was chosen not for its internet infrastructure (it has almost none) but for its opacity laws.
Sources: Hurricane Electric AS208949; IpToolsKit โ HBING; WorldIP.io BVI allocation stats
โ What Is "lir-vg-itweb-1-MNT" and Who Is Behind It?
Three HBING IPs list lir-vg-itweb-1-MNT as their RIPE maintainer. The "vg" suggests Virgin Islands (country code VG). "itweb" suggests an IT/web company. This maintainer also appears on IPs announced by AS198584 (PIO-Hosting).
The same RIPE maintainer (lir-vg-itweb-1-MNT) appears on both HBING IPs and PIO-Hosting IPs. This is the bridge โ the technical connection between the BVI offshore shell and the German customer-facing entity. Someone with access to both the HBING corporate structure and the PIO-Hosting technical infrastructure manages this maintainer. That someone connects the entire network: BVI โ Germany โ Netherlands โ Ukraine โ China.
โ How Did Chinese IP Blocks (Guosheng IDC) End Up on a German ASN Announced from the Netherlands?
Guosheng IDC lease is a Chinese Internet Data Center. Their IP blocks (103.161.34.x) are APNIC allocations โ registered in the Asia-Pacific region. Yet they appear on AS198584 (PIO-Hosting, Germany), geolocated to the Netherlands, physically in Eygelshoven.
The supply chain: Chinese IDC obtains APNIC allocation โ Leases blocks to intermediary โ Intermediary assigns to RIPE maintainer โ PIO-Hosting announces via BGP from Eygelshoven โ Traffic flows through SkyLink. At each step, jurisdiction changes. The Chinese company is subject to Chinese law. The RIPE maintainer is subject to RIPE policies. PIO-Hosting is subject to German law. The data center is in Dutch jurisdiction. No single authority can trace the complete chain. This is IP laundering through jurisdictional fragmentation.
Sources: APNIC whois 103.161.34.0/24; RIPE DB AS198584 announced prefixes; Guosheng IDC RDAP data
Chapter 8: The Forensic Proof โ SSH Key Sharing Across the Network
Corporate registries show organizational relationships. SSH key sharing proves operational relationships. When the same private key appears on multiple IPs, the same operator (or toolkit) controls them.
| PIO IP | Shares Key With | Network | Cluster |
|---|---|---|---|
| 194.120.230.28 | 172.104.175.234 | Linode | 3 IPs |
| 195.62.32.212 | 154.16.180.28 | External | 3 IPs |
| 176.65.136.174 | 136.243.133.118 | Hetzner | 2 IPs |
| 195.62.32.180 | 5.161.147.167 | Hetzner | 2 IPs |
| 176.65.128.179 | 103.57.224.219 | External | Key reuse |
| 92.246.87.54 | 89.37.117.71 | External | 2 IPs |
Entity links: 29 shared SSH keys, 21 shared OTX pulses, 11 temporal correlations, 39 registered-by relationships for AS198584.
โ Why Are PIO-Hosting Attackers Also on Linode and Hetzner?
SSH key fa:a2:16:79:ba:98:... appears on both 194.120.230.28 (PIO-Hosting, 100% abuse, 42 honeypot hits) and 172.104.175.234 (Linode โ a legitimate provider with active abuse enforcement).
The same operator rents infrastructure from both PIO-Hosting and Linode. They use Linode for operations that need to appear legitimate (maybe phishing pages, C2 panels with domain fronting, or data exfiltration endpoints). They use PIO-Hosting for operations that would get them immediately suspended elsewhere (SSH credential stuffing, brute force attacks, botnet control). When Linode suspends them (which it does โ Linode has ~90% abuse response rate), they move those operations to PIO (0% response rate). PIO-Hosting is the operator of last resort โ the provider that never says no.
โ What If PIO-Hosting Operators Are Also Operators of the Attack Infrastructure, Not Just Hosts?
29 shared SSH keys across the network. 39 registered-by relationships. The attack IPs share keys not just with each other but with IPs on completely different networks.
There is a line between "hosting company that tolerates abuse" and "criminal enterprise that operates attack infrastructure." The SSH key evidence pushes toward the latter. If PIO-Hosting were simply negligent โ failing to respond to abuse reports โ the SSH keys on their IPs would be diverse (each customer has their own keys). Instead, we see clusters of shared keys linking PIO IPs to each other and to external infrastructure. This pattern is consistent with a single coordinated operator managing both the hosting infrastructure and the attack campaigns running on it. The hosts aren't just tolerating the abuse โ they may be generating it.
๐ Reading Between the Lines
- SSH key sharing between PIO-Hosting and Hetzner/Linode proves the customers use PIO specifically for attack traffic they can't run elsewhere. PIO exists as the arm that does the dirty work.
- 29 shared keys across 17 IPs is not "some bad customers." A legitimate hosting provider with 17 IPs in a threat database would have 17 different SSH keys (different customers). Shared keys = shared operators = coordinated infrastructure.
- The 628-IP campaign (hassh-14b2ddda386a4d10) includes PIO IPs alongside OVH, SingleHop, Psychz, and ColoCrossing. If PIO is the coordination point, it's running a 628-node distributed attack network across 48 countries from a converted hall in Eygelshoven.
Chapter 9: The CyberBunker Precedent โ History Repeating
In September 2019, German police seized CyberBunker โ a bulletproof hosting operation run by Herman-Johan Xennt from a former NATO bunker. The parallels are not metaphorical โ they are structural:
| Attribute | CyberBunker (2013-2019) | SkyLink/XSServer/PIO (2014-present) |
|---|---|---|
| Border strategy | NLโDE jurisdictional gap | DEโNL jurisdictional gap |
| Shell companies | 3+ rebrands | 5+ entities |
| Physical facility | Converted bunker | Converted industrial halls |
| Time operational | ~6 years before seizure | 10+ years, no action |
| Marketing | "Bulletproof hosting" | "DDoS protection," colocation |
โ Why Was CyberBunker Shut Down But SkyLink Hasn't Been?
CyberBunker hosted darknet drug markets. SkyLink/PIO hosts credential-stuffing botnets and SSH scanners. Both cause immense harm. Only one was raided.
Drug trafficking creates individual victims, media narratives, and political pressure. Credential stuffing creates abstract, distributed losses across millions of accounts โ no single victim is harmed enough to trigger an investigation. The total damage from credential stuffing may exceed drug trafficking in monetary terms, but it's invisible. The difference isn't the scale of harm. It's the visibility of harm. Same border region. Same strategy. Different law enforcement priority. CyberBunker got raided because it was photogenic for a press conference. SkyLink survives because SSH botnets are boring.
Sources: Wikipedia โ CyberBunker; Ars Technica
โ Did CyberBunker's Seizure Teach the SkyLink Operators What Not to Do?
CyberBunker was seized in 2019. XSServer GmbH was registered in 2022 โ three years later, in the same border region, with a more sophisticated corporate structure.
CyberBunker made a critical mistake: it hosted content that created criminal liability for the operators themselves (aiding drug trafficking). The SkyLink ecosystem learned from this. SSH botnets, credential stuffing, and DDoS-for-hire create civil liability for the targets but rarely criminal liability for the hosting provider. By staying below the criminal threshold โ hosting attacks rather than contraband โ the SkyLink operators avoid the legal trigger that brought down CyberBunker. The 2019 seizure wasn't a warning to stop. It was a playbook for what to avoid.
Chapter 10: The Lifecycle Model โ How Bulletproof Infrastructure Regenerates
The SkyLinkโXSServerโPIO-Hosting lineage follows a documented pattern:
- Foundation Layer (permanent): Physical data center โ SkyLink. 10+ years, 450 peers. This never changes.
- Operating Layer (semi-permanent): RIPE LIR โ XSServer (ORG-XG40-RIPE). Holds IP allocations and ASN registrations.
- Customer-Facing Layer (disposable): The brand โ PIO-Hosting. Accumulates complaints until dissolution.
- Offshore Layer (opaque): IP holdings โ HBING Ltd (BVI). Hidden beneficial ownership.
- Shadow Layer (invisible): Financial entity โ MR 1337 GmbH. No public product, no website, no visibility.
โ When PIO-Hosting Dies, What Comes Next?
At 100% abuse scores across all known IPs, PIO-Hosting has accumulated more heat than most bulletproof providers survive. FluxHosting rebranded after similar exposure. MaxiDed was seized.
The prediction: PIO-Hosting GmbH will be dissolved at the Aachen Amtsgericht. Within weeks, a new GmbH โ registered by Edler and Spellerberg, or by nominees โ will appear at the same court. It will apply for the same RIPE sponsorship from XSServer (ORG-XG40-RIPE). The same IP prefixes will be re-announced from the same data center through the same BGP peers. The 450-peer SkyLink network won't miss a beat. The only thing that changes is the name on the abuse-c line. MR 1337 GmbH may be that successor, pre-positioned and waiting.
โ What Would It Take to Actually Stop This Operation?
Dissolving PIO-Hosting won't work (successor ready). Deregistering the ASN won't work (new ASN, same prefixes). Blocking the IP ranges won't work (new ranges from HBING/Guosheng).
The only intervention that would disrupt this ecosystem is physical: seizing the data center in Eygelshoven, as German police did with CyberBunker in Traben-Trarbach. Everything else is reversible. But this requires Dutch law enforcement to act on the data center while German law enforcement simultaneously acts on the corporate entities โ coordinated cross-border action that requires BKA-Europol-FIOD cooperation. The jurisdictional gap that protects the operation is the same gap that prevents investigation. The architecture is, in itself, the defense.
โ How Much Money Is This Operation Making?
SkyLink routes 1-5 Tbps through 16 IXPs. PIO-Hosting announces 28 prefixes. ZeXoTeK manages ~10,000 IPs. HBING holds 3,328 IPs. Bulletproof hosting pricing ranges from $200-500/server/month, significantly above legitimate hosting rates.
Conservative estimate: if even 500 of these IPs are active customer deployments at $300/month, that's $150,000/month or $1.8M/year in revenue โ flowing through entities with a combined registered capital of โฌ75,000. The revenue-to-capitalization ratio is 24:1. This is a serious business disguised as a minimum-viable legal structure. And this estimate only counts direct hosting fees โ not premium "DDoS protection" charges, not IP leasing fees through HBING, not whatever MR 1337 GmbH invoices for.
๐ Reading Between the Lines
- Three GmbHs with โฌ25,000 each = โฌ75,000 total liability. For an operation worth $1.8M+/year. The corporate structures aren't designed for business โ they're designed for disposability.
- The five-layer architecture (SkyLink โ XSServer โ PIO-Hosting โ HBING โ MR 1337) creates five separate intervention points, each in a different jurisdiction. No single authority can act on all five simultaneously.
- FluxHosting, Ecatel (Netherlands), MaxiDed โ all followed this exact lifecycle: multiple rebrands, same data center, same personnel, continuous abuse. The SkyLink network is on the same trajectory, just earlier in its lifecycle and more sophisticated in its corporate architecture.
- The data center is in the Netherlands. The companies are in Germany. The offshore shell is in BVI. The IP blocks come from China and Ukraine. Which regulator is responsible? All of them. Which one acts? None of them.
Chapter 11: The Complete Timeline
| Year | Event | Significance |
|---|---|---|
| ~2014 | SkyLink Data Center BV established (AS44592), Eygelshoven | Physical foundation โ converted industrial halls |
| 2017 | XSServer brand appears (AS207959), domains registered | Operating identity for the Aachen-border data center |
| 2019 | CyberBunker seized โ same region, same border model | Precedent; teaches operators what to avoid |
| 2020 | Dutch UBO registry goes live โ corporate transparency increases | Motivates shift to German GmbH structure |
| Jun 2022 | XSServer GmbH registered at Aachen (HRB 21403) | Formal incorporation โ Edler + Spellerberg |
| 2022 | MR 1337 GmbH registered โ same directors, same court | Hidden entity; hacker-culture naming |
| May 2023 | PIO-Hosting GmbH receives AS198584, sponsored by XSServer | Customer-facing bulletproof ASN born |
| 2023 | HBING Ltd (BVI) begins managing IP blocks on AS198584 | Offshore opacity layer completed |
| 2023-24 | ZeXoTeK IP blocks appear on AS198584 | Ukrainian entity adds jurisdictional complexity |
| 2024 | First PIO-Hosting IPs appear in honeypot telemetry | Active malicious use confirmed |
| 2024-25 | 4,931 abuse reports on single ZeXoTeK IP (176.65.134.34) | Industrial-scale abuse tolerance documented |
| 2025 | 17 PIO IPs tracked โ 100% abuse scores, 312+ sessions | Systematic attack infrastructure confirmed |
| 2025-26 | 628-IP campaign detected sharing HASSH with PIO IPs | Global botnet coordination from Eygelshoven |
| 2026 | SSH key sharing links PIO IPs to Linode/Hetzner | Same operators across bulletproof + legitimate providers |
๐ Series Connections โ The Phantom ASN Ecosystem
026A โ Overview of the phantom infrastructure. 026K provides the corporate genealogy behind it.
026B โ The hosting archipelago. SkyLink is the physical anchor point.
026C โ German gray zone transit. XSServer and PIO are the German enablers.
026F โ Sanctions analysis. PIO-Hosting transits Iranian LIR prefixes.
026G โ People. Edler, Spellerberg, Bellgart: faces behind the curtain.
026J โ Abuse reports filed against PIO go to the same graveyard.
Sources & References
- PeeringDB โ AS44592 SkyLink Data Center
- bgp.tools โ AS44592 (10yr, 450 peers, 7 upstreams)
- XSServer GmbH official website
- XSServer network page (directors, HRB, VAT, phone)
- NorthData โ XSServer GmbH (HRB 21403, โฌ25K capital)
- NorthData โ Marcel Edler (MR 1337 GmbH link)
- NorthData โ Renรฉ Spellerberg (MR 1337 GmbH link)
- CompanyHouse โ Marcel Edler (alleinvertretungsberechtigt)
- Scamalytics โ PIO-Hosting GmbH (+ Superhub Limited)
- AbuseIPDB โ ZeXoTeK 176.65.134.34 (4,931 reports)
- ipapi.is โ AS8649 ZeXoTeK (9,984 IPs)
- Hurricane Electric โ AS208949 HBING
- IpToolsKit โ HBING (3,328 IPs, 8 countries)
- Wikipedia โ CyberBunker
- Ars Technica โ CyberBunker seizure (2019)
- RIPE Database: ORG-XG40-RIPE, DB24958-RIPE, AS207959, AS198584, AS44592, MNT-ZEXOTEK, lir-vg-itweb-1-MNT
- Shodan passive scan: 58 CVEs on 176.65.131.189, ports 31210/9091/18062
- LSN Honeypot: 17 PIO IPs, 312+ sessions, 100% abuse rate, 2024-2026
- Campaign hassh-14b2ddda386a4d10: 628 IPs, 48 countries, 16,253 attempts
- Dutch UBO Registry, effective September 2020 (motivation for corporate restructuring)
- German GmbH law: ยง35 GmbHG (vertretungsberechtigt), HGB ยง267 (small company audit exemptions)