๐ก TI-2026-056E โ The Codebook Stations
Executive Summary
A numbers station requires transmitters, relay infrastructure, and receivers distributed across jurisdictions that cannot cooperate. This dossier maps the complete station network of the SSH codebook system: 326 transmitting IPs across 30+ countries, organized into four tiers by function. The geographic distribution is not random โ it is a deliberate jurisdictional arbitrage architecture that exploits the gaps between national law enforcement systems.
The stations are positioned at the exact intersections where no single legal authority has jurisdiction: Panama-registered entities operating from Switzerland. Seychelles corporations hosted in Netherlands. Kazakhstan-registered ASNs transmitting from Bulgaria. A $2-trillion American corporation's Belgian data center running coordinated botnet campaigns. The map is the message: impunity is geographic.
I. The Station Hierarchy โ Four Tiers
From the admin/admin credential signal (14,664 transmissions, 326 IPs, 102 days), the station network organizes into four functional tiers:
| Tier | Function | IPs | Transmissions | Share | Character |
|---|---|---|---|---|---|
| Tier 1: Primary | Core broadcast stations | 3 | 11,918 | 81.3% | Persistent, never stops, bulletproof |
| Tier 2: Secondary | Relay amplifiers | 12 | 2,065 | 14.1% | Regular but lower volume |
| Tier 3: Mesh | Rotating listeners | ~130 | ~400 | 2.7% | One-time IPs, rotating daily |
| Tier 4: Cloud Cover | Disposable probes | ~180 | ~280 | 1.9% | Legitimate cloud, short-lived |
II. Tier 1 โ The Primary Transmitters
Three stations generate 81.3% of all traffic. They have NEVER stopped transmitting in 102 days of observation:
STATION ALPHA: 179.43.139.58
โโโ Registration: Private Layer INC (Panama)
โโโ Physical: Zurich, Switzerland (IP2Location verified)
โโโ ASN: AS51852 (Private Layer INC, PA)
โโโ Transmissions: 4,464 admin/admin + 3,446 admin/123456 = 7,910 total
โโโ Uptime: 102 days continuous
โโโ Threat Score: 78.0
โโโ Abuse Score: 100
โโโ Known For: Monday evening burst (2,917 in 2 hours)
โโโ Jurisdiction Gap: Registered in PANAMA โ Operates from SWITZERLAND
โ Panama doesn't extradite for cybercrime
โ Switzerland requires Swiss court order to disconnect
โ NO SINGLE AUTHORITY CAN ACT
STATION BRAVO: 87.251.64.176
โโโ Registration: ISAEV Igor (Kazakhstan)
โโโ Physical: Poland (geolocation)
โโโ ASN: AS200730 (ISAEV, KZ)
โโโ Transmissions: 3,942 admin/admin
โโโ Uptime: 102 days continuous (4,078 total sessions)
โโโ Threat Score: 100.0
โโโ Tool: sshcustom_0.1 (only 4 IPs globally use this)
โโโ Known For: 29-minute heartbeat, zero commands EVER
โโโ Related: Kerberos-666 darknet market, drughub666 domain
โโโ Jurisdiction Gap: Registered in KAZAKHSTAN โ Operates from POLAND
โ Kazakhstan CERT has no enforcement capability
โ Polish authorities need MLAT with Kazakhstan
โ Individual named (ISAEV Igor) but unreachable
STATION CHARLIE: 185.246.128.133
โโโ Registration: w1n Ltd (United Kingdom)
โโโ Physical: Sweden (IP geolocation)
โโโ ASN: AS42237 (w1n ltd, GB)
โโโ Transmissions: 3,512 admin/admin + 1,851 admin/123456 = 5,363 total
โโโ Uptime: 102 days continuous (1,909 heartbeat sessions)
โโโ Threat Score: 97.0
โโโ Abuse Score: 100
โโโ Tool: Paramiko (HASSH 57e4cc8ee36c3d78, 4 IPs cluster)
โโโ Known For: 19-minute heartbeat, division of labor in cluster
โโโ Jurisdiction Gap: Registered in UK โ Operates from SWEDEN
โ UK Companies House has no server-level authority
โ Swedish ISP needs UK legal request
โ w1n Ltd is a ยฃ100 shell with no assets to seize
III. Tier 2 โ The Secondary Network
Twelve IPs provide backup/relay capacity, each transmitting 10-1,015 times:
| IP | Country | ASN | Attempts | Operator |
|---|---|---|---|---|
| 179.43.133.154 | CH | AS51852 | 1,015 | Private Layer (backup node) |
| 94.154.35.215 | NL | AS202412 | 560 | Omegatech LTD (Seychelles) |
| 80.66.66.10 | BG | AS209702 | 198 | SOLDATOV Alexey (Kazakhstan) |
| 37.77.150.119 | RU | AS198953 | 197 | Russian hosting |
| 185.246.130.20 | SE | AS42237 | 160 | w1n Ltd (secondary node) |
| 178.16.54.226 | NL | AS202412 | 126 | Omegatech (secondary) |
| 87.251.64.150 | PL | AS200730 | 114 | ISAEV (secondary node) |
| 130.12.180.51 | DE | AS202412 | 28 | Omegatech (Germany relay) |
| 45.148.10.121 | NL | AS48090 | 10 | Netherlands relay |
| 193.105.134.45 | SE | AS42237 | 6 | w1n (tertiary) |
| 103.85.72.144 | HK | AS152320 | 3 | Hong Kong relay |
| 80.66.66.70 | NL | AS209702 | 3 | SOLDATOV (Netherlands node) |
The SOLDATOV Discovery
AS209702 is registered to SOLDATOV ALEXEY VALEREVICH โ a named individual in Kazakhstan operating infrastructure from Bulgaria and Netherlands. This ASN has:
- IP 80.66.66.10 (BG): 198 admin/admin attempts, all success, zero commands
- IP 80.66.66.70 (NL): 3 admin/admin attempts
- Appeared in 3 published dossiers (037A Ghost Machines, 043M The Map, 051C The Stuffing Machine)
- CrowdSec active decisions, MikroTik banned
Pattern: Kazakhstan registration โ Bulgaria/Netherlands operation. Same jurisdictional gap as ISAEV (Kazakhstan โ Poland). Two Kazakh-registered operators, both transmitting the same credential, both operating from EU countries. This is either the same entity or the same playbook.
IV. Tier 3 โ The Rotating Mesh
Approximately 130 IPs transmit 1-3 times each, then never return. Geographic breakdown:
VIETNAM (Viettel Military): 56 IPs โ AS7552 (Viettel Group) + AS24086 (Viettel Corporation) 1-2 transmissions each, never repeat from same IP = MILITARY SIGNALS UNIT with IP rotation capability GOOGLE CLOUD (Belgium): 47 IPs โ AS396982 from St-Ghislain, Belgium data center 1 transmission each = DISPOSABLE CLOUD INSTANCES (launched, transmit, terminate) Average threat: 44.9 (moderate โ not flagged as malicious) 73% at abuse=100 in extended analysis UNITED STATES (mixed cloud): 66 IPs โ Multiple ASNs (DigitalOcean, AWS, Linode, Oracle) 1-2 transmissions each = DISTRIBUTED CLOUD COVER (blends with legitimate traffic)
The Google Cloud Belgium Anomaly
From TI-2026-032G "Google Cloud Anomaly":
"Google LLC / Google Cloud Platform. AS396982. $2T market cap. 157 IPs in threat DB, 77 at abuse=100. Belgium cluster (74 IPs, avg 44.9) at 2.3ร US threat rate. Employs TAG, Mandiant, VirusTotal, Project Zero โ yet hosts coordinated SSH botnet campaigns from St-Ghislain, Belgium (europe-west1)."
A company that employs the world's best threat intelligence teams simultaneously hosts 77 IPs confirmed at 100% abuse score. This is not oversight โ it is economics. Cloud billing doesn't distinguish between legitimate and malicious compute. The instances are paid for. They transmit once (costing pennies). They terminate before abuse review. Google Cloud is being used as a one-time-pad infrastructure โ each instance exists only long enough to send a single message.
V. The Jurisdictional Map โ Where No Law Reaches
The station network is designed around jurisdictional gaps โ places where the legal authority to act is split across borders that don't cooperate:
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ โ THE JURISDICTIONAL MAP โ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค โ โ โ REGISTRATION OPERATION GAP โ โ โโโโโโโโโโโโโ โโโโโโโโโ โโโ โ โ Panama โโโโโโโโโโโโ Switzerland No extradition treaty โ โ Seychelles โโโโโโโโ Netherlands No MLAT response โ โ Kazakhstan โโโโโโโโ Poland/BG No enforcement capacity โ โ United Kingdom โโโโ Sweden Shell company, no assets โ โ โ โ NAMED INDIVIDUALS: โ โ โข ISAEV Igor (KZ) โ AS200730 โ Kerberos-666, drughub666 โ โ โข SOLDATOV Alexey (KZ) โ AS209702 โ BG/NL operations โ โ โ โ SHELL COMPANIES: โ โ โข Private Layer INC (PA) โ $0 seizable assets โ โ โข w1n Ltd (GB) โ ยฃ100 formation, no employees โ โ โข Omegatech LTD (SC) โ Seychelles IBC, no transparency โ โ โ โ GOVERNANCE VACUUM: โ โ "No governance structure has jurisdiction over the โ โ complete entity" โ TI-2026-023A โ โ โ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
VI. The Epstein Parallel โ Same Jurisdictions, Same Purpose
From TI-2026-041A "The Epstein Architecture":
"Seychelles (41 IPs), Panama (8), St. Kitts (6), USVI (5) = 60 IPs from Epstein-associated offshore jurisdictions. Same havens that enabled Epstein shell companies now enable bulletproof hosting and cyber attack infrastructure. Not parallel systems โ same opacity service for different criminal functions."
Jeffrey Epstein used Seychelles IBCs to hide financial flows. Our credential broadcast stations use Seychelles IBCs (Omegatech) to hide operational control. Epstein used Panamanian structures to layer ownership. Private Layer uses Panamanian registration to layer legal liability. The corporate service providers are likely the same firms โ the same registered agents in Victoria, Mahรฉ who file both financial shells and hosting shells.
Seychelles IBC features (documented in TI-2026-024):
- No public beneficial ownership register
- No cooperation without MLAT (which takes 2-5 years)
- $1,000/year maintenance
- 24-48 hour formation
- No requirement to maintain local office or staff
- Bearer shares permitted until 2022
Cost of the entire broadcast infrastructure's legal protection: ~$3,000/year (three Seychelles/Panama shells at $1,000 each). Cost of taking it down through legal channels: $500,000+ in international legal fees over 3-5 years with no guarantee of success.
VII. The Geographic Shift โ Countries Taking Turns
From TI-2026-026O "The Temporal Architecture":
"The geographic shift analysis reveals that the country composition of the attacking fleet changes dramatically between the first and second half of observed periods."
The station network rotates geographic origin over time โ not randomly, but according to a pattern that maps to abuse response cycles. When a country's abuse teams start responding to complaints (typically 3-7 days after initial reports), traffic shifts to a different country's infrastructure. By the time Country A processes reports, the traffic has moved to Country B. When Country B responds, it moves to Country C. By the time Country C responds, Country A's blocklists have expired.
This is jurisdictional surfing โ using the differences in abuse response times between countries as a rotation schedule.
VIII. The Five-Country Privacy Axis
From TI-2026-030C, the infrastructure concentrates in five countries chosen for privacy-jurisdiction logic:
| Country | IPs | Role | Why Here |
|---|---|---|---|
| ๐จ๐ญ Switzerland | 7 | Primary broadcast | Strong privacy law, requires court order, no proactive monitoring |
| ๐ณ๐ฑ Netherlands | 26 | Secondary relay | Tor-friendly, AMS-IX peering, cheap bandwidth |
| ๐ธ๐ช Sweden | 9 | Heartbeat maintenance | Privacy-protective data law, limited abuse enforcement |
| ๐ต๐ฑ Poland | 9 | Persistent heartbeat | EU jurisdiction but slow abuse response |
| ๐ง๐ฌ Bulgaria | 2 | Backup relay | Lowest-cost EU hosting, Neterra colocation |
Notice: No China. No Russia (until recently). No Iran. The "axis of evil" narrative is empirically false. The broadcast stations operate from Western jurisdictions โ Switzerland, Sweden, Netherlands, Belgium, Poland. Countries where law enforcement requires due process, which means time, which means the infrastructure survives.
IX. The Vietnamese Listening Posts
56 Vietnamese IPs form the largest single-country mesh in Tier 3. All belong to Viettel โ Vietnam's military-owned telecom group:
AS7552 (Viettel Group): 37 IPs โ 1 transmission each AS24086 (Viettel Corp): 16 IPs โ 1 transmission each Total: 53 IPs โ 53 transmissions BEHAVIOR: โข Each IP transmits admin/admin exactly ONCE โข Never returns from same IP โข Spread across 53 different days (one new IP per day) โข All from residential/mobile IP pools (not servers) This is NOT scanning. This is RECEIVING. One check-in per day from a new rotated access point. Classic military signals intelligence collection pattern.
Viettel is not a random ISP. It is the People's Army of Vietnam's commercial telecom arm. Its cyber division (documented in TI-2026-051L) operates from military facilities. The one-IP-per-day pattern is consistent with a signals collection unit monitoring the broadcast โ checking in from a new rotated endpoint each day to avoid pattern detection while confirming they can still receive the signal.
X. The US Paradox โ 623 IPs from the Defender's Own Territory
From TI-2026-039E:
"Top attacking country is United States (623 IPs, 16,121 hits). The narrative that attacks come from China and Russia is empirically false in this dataset."
66 US IPs participate in the admin/admin broadcast. They come from: DigitalOcean, AWS, Google Cloud, Linode, Oracle. Major US cloud providers โ companies subject to US law, US court orders, and US intelligence community oversight.
Why use US infrastructure for a criminal broadcast system? Three reasons:
- Volume camouflage โ More SSH traffic originates from US cloud than any other country. One more connection from a DigitalOcean IP is invisible.
- Speed-of-light advantage โ US cloud has the lowest latency to the most SSH targets globally.
- Disposability โ $0.01/hour cloud instances. Launch, transmit, terminate. The instance exists for 60 seconds. Abuse reports arrive at a dead endpoint.
XI. The Complete Map
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ โ THE CODEBOOK STATION MAP โ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโค โ โ โ ๐จ๐ญ SWITZERLAND (Primary) ๐ต๐ฑ POLAND (Heartbeat) โ โ โโ 179.43.139.58 [4,464+3,446] โโ 87.251.64.176 [3,942] โ โ โโ 179.43.133.154 [1,015] โโ 87.251.64.150 [114] โ โ โ โ ๐ธ๐ช SWEDEN (Heartbeat) ๐ณ๐ฑ NETHERLANDS (Relay) โ โ โโ 185.246.128.133 [3,512+1,851] โโ 94.154.35.215 [560] โ โ โโ 185.246.130.20 [160] โโ 178.16.54.226 [126] โ โ โโ 193.105.134.45 [6] โโ 80.66.66.70 [3] โ โ โโ 45.148.10.121 [10] โ โ โ โ ๐ง๐ฌ BULGARIA (Backup) ๐ท๐บ RUSSIA (Recent) โ โ โโ 80.66.66.10 [198] โโ 37.77.150.119 [197] โ โ โ โ ๐ฉ๐ช GERMANY (Relay) ๐ญ๐ฐ HONG KONG (Asia relay) โ โ โโ 130.12.180.51 [28] โโ 103.85.72.144 [3] โ โ โ โ โ โ โ โ โ MESH/LISTENERS โ โ โ โ โ โ โ ๐ป๐ณ VIETNAM (53 rotated) ๐บ๐ธ USA (66 cloud) โ โ ๐ง๐ช BELGIUM (47 Google Cloud) ๐ฉ๐ช Germany (19 Hetzner) โ โ โ โ โ โ โ CONVERGENCE TRIANGLE โ โ โ โ โ ๐ฐ๐ช KENYA (41.139.202.227) [cart00ns+banana666+warnight]โ โ ๐ต๐ฆ PANAMA (181.78.121.148) [Same dictionary] โ โ ๐ช๐จ ECUADOR (177.234.209.102) [Same dictionary] โ โ โ โ โ โ โ REGISTRATION LAYER โ โ โ โ โ ๐ต๐ฆ Panama: Private Layer INC โ โ ๐ธ๐จ Seychelles: Omegatech LTD โ โ ๐ฌ๐ง United Kingdom: w1n Ltd โ โ ๐ฐ๐ฟ Kazakhstan: ISAEV Igor, SOLDATOV Alexey โ โ โ โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
XII. Synthesis โ The Architecture of Impunity
The station network is designed with one principle: no single jurisdiction can take it down.
- Registration states (Panama, Seychelles, Kazakhstan) have no technical enforcement capability
- Operating states (Switzerland, Sweden, Netherlands, Poland) have no legal authority over foreign-registered entities without multi-year MLAT processes
- Cloud providers (Google, DigitalOcean, AWS) have no incentive โ instances are paid, short-lived, and indistinguishable from legitimate usage
- Listener states (Vietnam) are military-operated and will not cooperate with Western requests
To take down this network, you would need simultaneous cooperation between: Panama, Switzerland, Seychelles, Netherlands, Sweden, Poland, Bulgaria, Kazakhstan, United Kingdom, Vietnam, and multiple US cloud providers. This cooperation has never occurred in the history of international law enforcement. The network knows this. That's why it was built this way.
Assessment: The codebook station map reveals a communication system distributed across 30+ countries with deliberate jurisdictional gap exploitation. Three primary stations (Switzerland, Poland, Sweden) have broadcast continuously for 102 days. A Vietnamese military listening post rotates daily. Google Cloud Belgium serves as disposable one-time-pad infrastructure. Named individuals (ISAEV Igor, SOLDATOV Alexey) register ASNs in Kazakhstan but operate from EU states. The architecture is legally invulnerable by design โ not by accident, but by architectural requirement. This is infrastructure built to survive anything except the internet itself being turned off.
Methodology
Geographic data from admin/admin credential intelligence (326 IPs, 102 days). ASN attribution via RDAP, CYMRU, AbuseIPDB. Jurisdictional analysis from TI-2026-023A, 024, 030C, 030D. Google Cloud anomaly from TI-2026-032G. Epstein parallel from TI-2026-041A. Vietnamese military from TI-2026-051L. Entity crosslinks (271K+ edges) for convergence triangle verification.
Cross-References
- ๐ก TI-2026-056A โ The Codebook
- ๐ก TI-2026-056B โ The Heartbeat Protocol
- ๐ก TI-2026-056C โ The Vocabulary Cipher
- ๐ก TI-2026-056D โ The Broadcast Schedule
- ๐ TI-2026-023A โ The VPN Laundromat
- ๐ TI-2026-032G โ Google Cloud Anomaly
- ๐ TI-2026-041A โ The Epstein Architecture
- ๐ TI-2026-043M โ The Map