Executive Summary
On a single /24 subnet โ 45.154.98.0/24, announced by AS210558 (1337 Services GmbH / rdp.sh) โ we find active Tor exit relays operating alongside active French bank phishing infrastructure, Russian scam stores, and spam operations generating thousands of abuse reports. The entire subnet sits on Spamhaus DROP (SBL687510), meaning responsible networks unconditionally refuse its traffic.
This is not coincidence. It is a business model.
1. The Provider
| Company | 1337 Services GmbH |
| Registry | District Court of Hamburg, HRB 164175 |
| Address | Ludwig-Erhard-Str. 18, 20459 Hamburg, Germany |
| ASN | AS210558 (RIPE, allocated 2021-10-28) |
| Brand | rdp.sh ("Cheap Windows RDP & Linux KVM VPS") |
| Owner | Julian Achter (confirmed via Tor relay metrics) |
| @rdpDOTsh | |
| BGP | 50 IPv4 prefixes, 7 upstreams, 7 peers, Open policy |
The Tor Project's Good/Bad ISPs page states: "1337 Services GmbH / RDP.sh (AS210558). These hosts already have many Tor nodes being hosted there." BGP.tools characterizes the network simply: "Server Hosting Tor services."
rdp.sh markets itself as privacy-focused, accepts cryptocurrency, offers "offshore hosting," and provides instant automated provisioning. Every customer's reverse DNS reads <IP>.powered.by.rdp.sh โ the brand literally stamps itself on every packet.
xmr.rdp.sh (Monero mining), pterodactyl.rdp.sh (game servers), vnc.rdp.sh / terminal.rdp.sh (remote access), proxmox-proxy.rdp.sh (virtualization), looking glasses in 6+ countries (NL, FR, PL, US-MIA, US-PHX, UK). This is a diversified hosting operation serving cryptocurrency miners, gamers, Tor operators, and whoever else pays.
2. The Subnet
45.154.98.0/24 โ netname SERVPERSO-CLOUD โ is maintained by SERVPERSO-MNT, the Belgian precursor entity documented in 030B. It exhibits a characteristic 4-country discrepancy:
| Layer | Country |
|---|---|
| Company registration | DE (Hamburg) |
| BGP prefix origin | BE (Belgium) |
| Physical servers | NL (Netherlands) |
| Phishing targets | FR (French banks) |
The entire /24 is on Spamhaus DROP โ the most severe blacklist in existence. DROP means "Don't Route Or Peer." Any network following Spamhaus recommendations refuses ALL traffic from this range unconditionally. The listing indicates abuse so persistent and systemic that the provider has been deemed unreformable.
3. The Phishing Operation
A single IP hosting multiple simultaneous fraud operations:
| Domain | Type | Target |
|---|---|---|
caisse-epargne-se-connecter.net | Bank phishing | French savings bank (13.3M customers) |
ned.moyuniversalnyy.store | Scam store | Russian-language victims |
invoiceninja.jantechcs.com | Invoice fraud | Business email compromise |
immich.oldos.duckdns.org | DuckDNS C2 | Dynamic panel/tooling |
Ports exposed: 80, 82, 83, 84, 9100, 9600 โ multi-port = multi-tenant phishing farm. Ports 82-84 are custom credential harvesting variants. Port 9100/9600 suggest exposed Elasticsearch or monitoring.
OTX intelligence: 50 threat feed pulses. Categorized as both "Anonymization_Network" and abuse source.
Caisse d'รpargne is France's second-largest retail bank. The phishing domain caisse-epargne-se-connecter.net translates to "savings-bank-to-connect" โ a credential harvesting page designed to steal French banking logins. It sits on bulletproof infrastructure where abuse reports produce no action.
4. The Tor Exit
| Contact | a78i2efsewr0neeknk@proton.me |
| Domain | allium.top (Njalla-registered, currently dead) |
| Donations | XMR: 82sdVXSFUJcici... |
| Operating since | 2022-08-21 (4 years) |
| Exit capacity | 845.34 Mbit/s (0.21% of Tor exit consensus) |
| Relays | NgePTimE, SieNCoAd, ASqUADeo |
| Hosting cost | โฌ3.75/month (LiteServer) |
The allium.top operator is a high-OPSEC privacy-conscious individual: random-string ProtonMail, Njalla domain privacy, Monero-only, opaque relay names with no semantic meaning (SieNCoAd, ASqUADeo, NgePTimE), no MyFamily declaration, dedicated abuse contact. This is the gold standard of Tor operator anonymity.
Three relays across three different ASNs:
| Name | Hostname | ASN | Country |
|---|---|---|---|
| NgePTimE | tor-exit-2.allium.top | AS53667 | Luxembourg |
| SieNCoAd | tor-exit-1.allium.top | AS210558 | Netherlands |
| ASqUADeo | tor-exit-3.allium.top | AS60404 | Unknown |
5. The Convergence
On 45.154.98.0/24, within 120 IP addresses of each other:
- .33 โ allium.top Tor exit (privacy infrastructure, 845 Mbit/s)
- .153 โ Caisse d'รpargne phishing + Russian scams + invoice fraud
- .176 โ Unknown abuse (4,087 reports from 611 sources)
- .30 โ rcrfgunleri.cfd (fraud domain)
- .42 โ 96% AbuseIPDB confidence
All maintained by SERVPERSO-MNT. All announced by AS210558. All sold by rdp.sh. All under one company: 1337 Services GmbH, Hamburg.
In November 2025, Dutch police shut down CrazyRDP โ a "bulletproof hosting service mainly used by cybercriminals and hackers." The parallels: RDP in the brand name, Netherlands-based servers, cheap instant provisioning, abuse-tolerant policies. rdp.sh operates the same model, in the same country, with the same customer profile. The difference? rdp.sh is still running.
6. The Supply Chain
Across the Anonymity Factory series (030A-030J), we've documented AS210558's position as the common infrastructure layer:
| Customer | Type | Documented In |
|---|---|---|
| 2cb.su operator | 49+ Tor relays | 030D, 030E |
| allium.top | 3 Tor exits | 030J (this dossier) |
| Bronk / Bronk-ICT | 28 Tor relays | 030I |
| maxzrbn, sy.st, secretdrop | Tor operators | 030F |
| Phishing operators | Bank fraud, scams | 030J (this dossier) |
| Spam operators | 1,795+ flagged sites | 030J (this dossier) |
Julian Achter's 1337 Services GmbH doesn't run the Tor exits or the phishing pages. It provides the substrate โ the BGP-announced IP space, the abuse-tolerant hosting, the jurisdictional complexity. The factory doesn't make the product. It makes the factory floor.
7. The Economic Model
The business model works because Spamhaus-DROP-listed IP space has negative value on the legitimate market โ no respectable provider wants it. But for operators who don't need legitimate routing (phishing pages accessed once via SMS link, Tor relays that only need to reach directory authorities), the reputation doesn't matter. The provider buys burned ranges cheaply, sells them to customers who don't care about reputation.
8. The Question
This dossier is titled "The Phishing Question" because it poses the central dilemma of the entire Anonymity Factory investigation:
Does a provider that explicitly welcomes Tor relays โ a legal activity that strengthens internet privacy โ bear responsibility when the same infrastructure simultaneously enables bank phishing, credential theft, spam operations, and fraud?
The answer depends on who you ask:
- The provider would say: "We host legal services. Tor is legal. We process abuse reports." (But the Spamhaus DROP listing proves abuse reports produce no meaningful action.)
- The Tor operator would say: "We chose cheap hosting. We're independent of our neighbors." (But their exit capacity operates on infrastructure that responsible networks refuse to route.)
- The phishing victim would say: "My bank credentials were stolen via a page hosted on infrastructure that claims to serve privacy." (And no abuse report will take it down.)
- Spamhaus has already answered: DROP the entire range.
9. Series Assessment
"The Anonymity Factory" (030A through 030J) has documented a complete infrastructure ecosystem:
| Layer | Entity | Function |
|---|---|---|
| Corporate | 1337 Services GmbH (Hamburg, HRB 164175) | Legal entity, LIR, ASN holder |
| Technical | SERVPERSO-MNT (Belgian precursor) | RIPE infrastructure management |
| Commercial | rdp.sh | Customer-facing VPS sales |
| Identity | Julian Achter | Owner, relay operator |
| Network | AS210558 + acquired ranges | BGP announcement, routing |
| Privacy | 2cb.su, allium.top, Bronk, etc. | ~3% of Tor exit traffic |
| Criminal | Unknown phishing/spam operators | Bank fraud, scams, spam |
The factory operates because each layer provides plausible deniability for the others. The company is legal. Tor hosting is legal. The phishing operators are customers, not employees. The jurisdictional spread (DE/BE/NL/FR) means no single authority can act. And the Spamhaus DROP listing โ intended as the ultimate sanction โ paradoxically makes the space more attractive to criminals who don't need legitimate routing.