The Anonymity Factory A B C D E F G H I J K L

Executive Summary

On a single /24 subnet โ€” 45.154.98.0/24, announced by AS210558 (1337 Services GmbH / rdp.sh) โ€” we find active Tor exit relays operating alongside active French bank phishing infrastructure, Russian scam stores, and spam operations generating thousands of abuse reports. The entire subnet sits on Spamhaus DROP (SBL687510), meaning responsible networks unconditionally refuse its traffic.

This is not coincidence. It is a business model.

1. The Provider

Corporate Identity
Company1337 Services GmbH
RegistryDistrict Court of Hamburg, HRB 164175
AddressLudwig-Erhard-Str. 18, 20459 Hamburg, Germany
ASNAS210558 (RIPE, allocated 2021-10-28)
Brandrdp.sh ("Cheap Windows RDP & Linux KVM VPS")
OwnerJulian Achter (confirmed via Tor relay metrics)
Twitter@rdpDOTsh
BGP50 IPv4 prefixes, 7 upstreams, 7 peers, Open policy

The Tor Project's Good/Bad ISPs page states: "1337 Services GmbH / RDP.sh (AS210558). These hosts already have many Tor nodes being hosted there." BGP.tools characterizes the network simply: "Server Hosting Tor services."

rdp.sh markets itself as privacy-focused, accepts cryptocurrency, offers "offshore hosting," and provides instant automated provisioning. Every customer's reverse DNS reads <IP>.powered.by.rdp.sh โ€” the brand literally stamps itself on every packet.

Certificate Transparency reveals the ecosystem: From 41 discovered subdomains โ€” xmr.rdp.sh (Monero mining), pterodactyl.rdp.sh (game servers), vnc.rdp.sh / terminal.rdp.sh (remote access), proxmox-proxy.rdp.sh (virtualization), looking glasses in 6+ countries (NL, FR, PL, US-MIA, US-PHX, UK). This is a diversified hosting operation serving cryptocurrency miners, gamers, Tor operators, and whoever else pays.

2. The Subnet

SBL687510
Spamhaus DROP
4,087
Abuse Reports (.176)
1,795
Spam Sites (.153)
100%
AbuseIPDB Score

45.154.98.0/24 โ€” netname SERVPERSO-CLOUD โ€” is maintained by SERVPERSO-MNT, the Belgian precursor entity documented in 030B. It exhibits a characteristic 4-country discrepancy:

LayerCountry
Company registrationDE (Hamburg)
BGP prefix originBE (Belgium)
Physical serversNL (Netherlands)
Phishing targetsFR (French banks)

The entire /24 is on Spamhaus DROP โ€” the most severe blacklist in existence. DROP means "Don't Route Or Peer." Any network following Spamhaus recommendations refuses ALL traffic from this range unconditionally. The listing indicates abuse so persistent and systemic that the provider has been deemed unreformable.

3. The Phishing Operation

45.154.98.153 โ€” The Phishing Farm

A single IP hosting multiple simultaneous fraud operations:

DomainTypeTarget
caisse-epargne-se-connecter.netBank phishingFrench savings bank (13.3M customers)
ned.moyuniversalnyy.storeScam storeRussian-language victims
invoiceninja.jantechcs.comInvoice fraudBusiness email compromise
immich.oldos.duckdns.orgDuckDNS C2Dynamic panel/tooling

Ports exposed: 80, 82, 83, 84, 9100, 9600 โ€” multi-port = multi-tenant phishing farm. Ports 82-84 are custom credential harvesting variants. Port 9100/9600 suggest exposed Elasticsearch or monitoring.

OTX intelligence: 50 threat feed pulses. Categorized as both "Anonymization_Network" and abuse source.

Caisse d'ร‰pargne is France's second-largest retail bank. The phishing domain caisse-epargne-se-connecter.net translates to "savings-bank-to-connect" โ€” a credential harvesting page designed to steal French banking logins. It sits on bulletproof infrastructure where abuse reports produce no action.

4. The Tor Exit

45.154.98.33 โ€” allium.top
Contacta78i2efsewr0neeknk@proton.me
Domainallium.top (Njalla-registered, currently dead)
DonationsXMR: 82sdVXSFUJcici...
Operating since2022-08-21 (4 years)
Exit capacity845.34 Mbit/s (0.21% of Tor exit consensus)
RelaysNgePTimE, SieNCoAd, ASqUADeo
Hosting costโ‚ฌ3.75/month (LiteServer)

The allium.top operator is a high-OPSEC privacy-conscious individual: random-string ProtonMail, Njalla domain privacy, Monero-only, opaque relay names with no semantic meaning (SieNCoAd, ASqUADeo, NgePTimE), no MyFamily declaration, dedicated abuse contact. This is the gold standard of Tor operator anonymity.

Three relays across three different ASNs:

NameHostnameASNCountry
NgePTimEtor-exit-2.allium.topAS53667Luxembourg
SieNCoAdtor-exit-1.allium.topAS210558Netherlands
ASqUADeotor-exit-3.allium.topAS60404Unknown
The irony: allium.top is likely a legitimate privacy operator โ€” transparent about costs, running for 4 years, contributing meaningfully to Tor's diversity. But by choosing rdp.sh hosting, their exit relay operates on a Spamhaus-DROP subnet next to bank phishing. Their traffic is dropped by any responsible network implementing DROP. The provider's reputation contaminates the legitimate operator.

5. The Convergence

On 45.154.98.0/24, within 120 IP addresses of each other:

  • .33 โ€” allium.top Tor exit (privacy infrastructure, 845 Mbit/s)
  • .153 โ€” Caisse d'ร‰pargne phishing + Russian scams + invoice fraud
  • .176 โ€” Unknown abuse (4,087 reports from 611 sources)
  • .30 โ€” rcrfgunleri.cfd (fraud domain)
  • .42 โ€” 96% AbuseIPDB confidence

All maintained by SERVPERSO-MNT. All announced by AS210558. All sold by rdp.sh. All under one company: 1337 Services GmbH, Hamburg.

The CrazyRDP Parallel

In November 2025, Dutch police shut down CrazyRDP โ€” a "bulletproof hosting service mainly used by cybercriminals and hackers." The parallels: RDP in the brand name, Netherlands-based servers, cheap instant provisioning, abuse-tolerant policies. rdp.sh operates the same model, in the same country, with the same customer profile. The difference? rdp.sh is still running.

6. The Supply Chain

Across the Anonymity Factory series (030A-030J), we've documented AS210558's position as the common infrastructure layer:

CustomerTypeDocumented In
2cb.su operator49+ Tor relays030D, 030E
allium.top3 Tor exits030J (this dossier)
Bronk / Bronk-ICT28 Tor relays030I
maxzrbn, sy.st, secretdropTor operators030F
Phishing operatorsBank fraud, scams030J (this dossier)
Spam operators1,795+ flagged sites030J (this dossier)

Julian Achter's 1337 Services GmbH doesn't run the Tor exits or the phishing pages. It provides the substrate โ€” the BGP-announced IP space, the abuse-tolerant hosting, the jurisdictional complexity. The factory doesn't make the product. It makes the factory floor.

7. The Economic Model

โ‚ฌ3.75
Cheapest VPS/month
50
IPv4 Prefixes
6+
Countries
4 yrs
Operating

The business model works because Spamhaus-DROP-listed IP space has negative value on the legitimate market โ€” no respectable provider wants it. But for operators who don't need legitimate routing (phishing pages accessed once via SMS link, Tor relays that only need to reach directory authorities), the reputation doesn't matter. The provider buys burned ranges cheaply, sells them to customers who don't care about reputation.

Trustpilot tells the story: "I don't recommend this provider at all if you want a normal VPS. It looks like they're specialised in supporting illegal cracking activities." โ€” This is a customer who expected legitimate hosting and discovered what the network actually serves.

8. The Question

This dossier is titled "The Phishing Question" because it poses the central dilemma of the entire Anonymity Factory investigation:

Does a provider that explicitly welcomes Tor relays โ€” a legal activity that strengthens internet privacy โ€” bear responsibility when the same infrastructure simultaneously enables bank phishing, credential theft, spam operations, and fraud?

The answer depends on who you ask:

  • The provider would say: "We host legal services. Tor is legal. We process abuse reports." (But the Spamhaus DROP listing proves abuse reports produce no meaningful action.)
  • The Tor operator would say: "We chose cheap hosting. We're independent of our neighbors." (But their exit capacity operates on infrastructure that responsible networks refuse to route.)
  • The phishing victim would say: "My bank credentials were stolen via a page hosted on infrastructure that claims to serve privacy." (And no abuse report will take it down.)
  • Spamhaus has already answered: DROP the entire range.

9. Series Assessment

"The Anonymity Factory" (030A through 030J) has documented a complete infrastructure ecosystem:

LayerEntityFunction
Corporate1337 Services GmbH (Hamburg, HRB 164175)Legal entity, LIR, ASN holder
TechnicalSERVPERSO-MNT (Belgian precursor)RIPE infrastructure management
Commercialrdp.shCustomer-facing VPS sales
IdentityJulian AchterOwner, relay operator
NetworkAS210558 + acquired rangesBGP announcement, routing
Privacy2cb.su, allium.top, Bronk, etc.~3% of Tor exit traffic
CriminalUnknown phishing/spam operatorsBank fraud, scams, spam

The factory operates because each layer provides plausible deniability for the others. The company is legal. Tor hosting is legal. The phishing operators are customers, not employees. The jurisdictional spread (DE/BE/NL/FR) means no single authority can act. And the Spamhaus DROP listing โ€” intended as the ultimate sanction โ€” paradoxically makes the space more attractive to criminals who don't need legitimate routing.

Methodology: This investigation used RIPE WHOIS, Spamhaus DROP lists, AbuseIPDB, Shodan passive scanning, PeeringDB, Certificate Transparency (crt.sh), Tor relay metrics (Onionoo, OrNetStats, 1aeo.com), CleanTalk, BGP.tools, NorthData corporate registry, OTX AlienVault, our honeypot enrichment pipeline, and vectorized cross-referencing across 9 prior dossiers. No active scanning was directed at the targets.
โš  Personal capacity. Research published independently โ€” not reflecting employer views. Derived from passive observation of attacks against personal infrastructure. Full disclaimer โ†’
โ† Previous The Anonymity Factory โ€” 10 / 12 Next โ†’