The DMZHOST Trinity: One Operator, Three Shells, Two Autonomous Systems

TI-2026-088 ยท Honeypot Field Reports ยท Confidence: HIGH (network + registry primary sources)

A honeypot does not care what a company calls itself. It records what an address does. Over eight weeks our SSH sensor watched a set of addresses log in with stolen-looking root passwords, fingerprint the machine, and move on โ€” and every time we asked the registry who owns this, it answered with a different name. UNMANAGED LTD. TECHOFF SRV LIMITED. DMZHOST. Three names, two autonomous systems, one operation. This is the anatomy of that operation โ€” and of the paperwork built to keep you from seeing it as one.

The finding in one paragraph

AS47890 ("UNMANAGED-DEDICATED-SERVERS," holder UNMANAGED LTD, GB) and AS48090 ("DMZHOST," holder TECHOFF SRV LIMITED, GB) are two separately-incorporated UK companies that are, at the network layer, provably one operation. Both sit on the Spamhaus ASN-DROP list โ€” the most severe network-level verdict Spamhaus issues, meaning the entire address space should be dropped because the network is controlled by, or leased to, threat actors. Both are classified bulletproof (risk 92โ€“95/100). They are registered in Great Britain, routed out of Romania and the Netherlands, and their RDAP objects variously claim Andorra, Bulgaria, the Netherlands and the Seychelles. The two "separate" companies are welded together by a single shared network maintainer (TECHOFF-MNT), a single free-Gmail abuse desk (dmzhostabuse@gmail.com), and a single prefix โ€” 2.57.122.0/24 โ€” that is announceable from both autonomous systems at will. On top of this infrastructure runs a coordinated SSH credential-stuffing and server-profiling botnet; the loader it drops is documented separately in TI-2026-083C, "The Appraiser." This dossier is about the landlord, not the tenant.

1. What the honeypot saw

Between late May and late July 2026, addresses across four Romanian /24s (2.57.121.0/24, 2.57.122.0/24, 80.94.92.0/24, 92.118.39.0/24) and one Dutch /24 (195.178.110.0/24, plus 45.148.10.0/24) hammered our SSH service. The pattern was monotonous and identical across every node:

Multiple nodes sustain a threat score of 100 with successful root logins. Behaviour classifier verdict: botnet(c2_infrastructure), confidence 0.8โ€“0.9. This is not opportunistic noise; it is a managed operation running the same toolkit from every address.

[DOCUMENTED] The hosted addresses run one coordinated SSH operation. [DOCUMENTED] The hosting is deliberate and long-lived โ€” the same ranges appear in ~50 AlienVault OTX pulses each, including SSH Brute-Force Honeypot Live.

2. Three names โ€” and why the registry lies cleanly

Ask the registry who owns an attacking IP and you expect one answer. Here you get three, and they are interchangeable:

You queryThe registry answers
80.94.92.55 (announced by AS47890 / UNMANAGED LTD)RDAP org = TECHOFF SRV LIMITED
92.118.39.49 (announced by AS47890 / UNMANAGED LTD)RDAP org = DMZHOST
AS48090 itselfholder = DMZHOST โ€” TECHOFF SRV LIMITED
195.178.110.232 (AS48090)RDAP country = Andorra

An IP on the UNMANAGED autonomous system answers as TECHOFF, or as DMZHOST. This is not database rot. It is the operator using three labels across two networks so that any automated attribution โ€” the kind that files an abuse report to "the registered owner" โ€” fragments into three dead ends.

Our entity-resolution graph collapses the three labels to a single operator. The interchangeability is the identity. When sources disagree on who owns something, the disagreement is not noise to be resolved by picking a favourite โ€” it is the finding.

3. The corporate layer: two real shells, engineered apart

Here the story sharpens, and it is more interesting than "one company with aliases." The two names correspond to two genuinely separate UK companies:

UNMANAGED LTD โ€” Companies House #12461131, incorporated 13 February 2020. Registered office: Business First Northampton, Brindley Close, Rushden, NN10 6EN โ€” a "Business First" serviced/virtual-office address, not a data centre. SIC codes cover IT consultancy, facilities management, hosting and web portals. Sole director and 75%+ Person with Significant Control: BUNEA, Petru-Octavian, Romanian, born April 1988, resident England. Filings are current โ€” no strike-off, no overdue accounts. On paper, a tidy little British IT company.

TECHOFF SRV LIMITED โ€” Companies House #16090235, incorporated 20 November 2024 โ€” weeks before it assumed the DMZHOST (AS48090) org handle in RIPE (last-changed 2024-11-26). Registered office: 72 Halliwick Road, London N10 1AB. But its RIPE org object (ORG-TSL73-RIPE) lists a third address โ€” 35 Firs Avenue, London N11 3NE. Its SIC code is 96090, "Other service activities not elsewhere classified" โ€” a generic catch-all with nothing to do with hosting. Sole director and PSC: Luca Palo, Italian, born March 1995, resident Milan.

Two companies. Different directors, different nationalities, different addresses โ€” no overlap. A naive registry check reads two unrelated British firms. That is exactly the intended effect: the corporate separation is the disguise. If you attribute at the corporate layer, you conclude these are two different businesses that merely happen to both host abuse. You would be wrong.

[DOCUMENTED] UNMANAGED LTD and TECHOFF SRV LIMITED are legally distinct entities with no shared registered address or director. [INFERRED] The separation is deliberate compartmentalisation, not coincidence โ€” because the network layer betrays them.

4. The smoking gun: one prefix, two origins, one maintainer

Corporate registries can be gamed. Routing registries are harder, because the network has to actually work. And the network gives it away.

The RIPE whois record for 2.57.122.0/24 โ€” the /24 behind our single most-abused node โ€” reads:

โ€ฆand then it carries two route objects: origin: AS47890 and origin: AS48090 โ€” both mnt-by: TECHOFF-MNT.

Read that slowly. This is a TECHOFF-maintained block, named for dmzhost.co, that can be announced from the UNMANAGED autonomous system or the DMZHOST autonomous system, at the operator's discretion. The maintainer TECHOFF-MNT and the abuse handle dmzhostabuse@gmail.com therefore sit on both ASNs. The two "separate companies" share the one thing that cannot be faked without breaking the network: control of the route.

This is dual-origin routing, and it is a deliberate resilience-and-evasion design. If one ASN gets de-peered, blocklisted harder, or burned, the prefix flips to the sibling. It is the network-engineering equivalent of holding two passports.

[DOCUMENTED ยท HIGH] A single maintainer (TECHOFF-MNT) and a single abuse address control prefixes announced from both AS47890 and AS48090; 2.57.122.0/24 is dual-origin-announceable from both. This is the operational identity the corporate paperwork conceals.

And the abuse desk? A free Gmail address. A hosting operation of this scale routing its entire abuse function through dmzhostabuse@gmail.com is not an oversight โ€” a Gmail abuse contact on commercial infrastructure is, as it is across this ecosystem, the tell. It is the address to which the 81,943 AbuseIPDB reports against one of its IPs are, in theory, delivered.

5. Jurisdictional arbitrage: registered nowhere it operates

Trace the operation across jurisdictions and it dissolves on contact:

A single IP can read Romania by AbuseIPDB, Romania or Bulgaria by Team Cymru, and the Netherlands or Andorra by RDAP. The GB registration touches nothing operational. No British data centre, no British transit, no British director for the DMZHOST half. The United Kingdom is a letterhead.

This is jurisdictional arbitrage in its purest form: incorporate where the paperwork is cheap and respectable-sounding, route where the transit is tolerant, declare a scatter of small countries with weak abuse enforcement, and let every would-be reporter guess which national CERT, registrar or police force has authority. The answer is designed to be: none of them, alone.

6. The human thread: Bunea, and a network that carries his name

Most bulletproof dossiers dead-end at a shell. This one has a rare personal anchor. UNMANAGED LTD's sole director is Bunea Petru-Octavian. Spamhaus attributes AS47890 to the domain bunea.eu. And AS47890's downstream customer is AS42397 โ€” "BUNEA-HIGH-VOLUME-NETWORK."

The director's surname threads through the ASN's Spamhaus domain attribution and a named downstream autonomous system. A UK-registered "IT consultancy" whose network is attributed to a personal domain and feeds a "high-volume network" bearing the director's own name is not an arm's-length hosting reseller. [INFERRED ยท MEDIUM-HIGH] The British company is administrative cover for a Romania-run network personally associated with its director. The TECHOFF/DMZHOST half, by contrast, is a fresher construction โ€” an Italian-directed shell incorporated in November 2024 to take over an older offshore brand (dmzhost.co claims trading since 2009). One veteran operator, one newly-minted shell wearing an old brand.

7. What it hosts โ€” and the discipline of not over-claiming

The botnet on this infrastructure shares a wordlist, a Go-scanner HASSH, and a command-automation fingerprint. Those same signals also reach 91.92.40.0/24. It would be easy โ€” and wrong โ€” to fold 91.92.40 into "the DMZHOST botnet."

91.92.40.0/24 is announced by AS197170, TechTies Inc. โ€” Seychelles-registered, created 2026-05-29, abuse abuse@tech-ties.net, Spamhaus-attributed to hostslick.de (the German "HostSlick" offshore brand). It shares no maintainer, no org, no abuse contact with UNMANAGED/TECHOFF. It is a different bulletproof operator.

So what does the shared tooling mean? It means either one botnet tenant renting from multiple bulletproof hosts, or a commodity wordlist and scanner used by many crews. A weak-password dictionary and an off-the-shelf Go scanner are forgeable, copyable signals โ€” the kind that any unrelated operator running the same tool reproduces. They are evidence of a shared toolkit or a shared abuse-tolerant ecosystem, not of shared ownership.

We hold this line deliberately, because the opposite error โ€” fusing everyone who shares a public artifact into one imaginary mega-actor โ€” is how attribution graphs rot. DMZHOST and TechTies/HostSlick are two separate landlords in the same bad neighbourhood, and some of the same tenants knock on both doors.

[DOCUMENTED] 91.92.40.0/24 belongs to a distinct operator (TechTies/HostSlick, AS197170). [DOCUMENTED] Shared forgeable signals do not establish common ownership.

8. The institutional-anchor pass: who keeps a dropped network alive

Nothing operates without anchors in official structures. For a network on Spamhaus ASN-DROP โ€” a network the industry has formally recommended dropping in its entirety โ€” the interesting question is what keeps it reachable at all. The anchors:

The gap is the abuse function: a free Gmail address that, against 81,943 reports on a single IP, demonstrably does not act. The anchors that enable the network (RIR allocation, incumbent transit, tidy corporate filings) are robust; the anchor that would constrain it (a working abuse desk) is a webmail inbox. That asymmetry is the business model.

9. Seven questions

Who is it? Two legally separate UK shells โ€” UNMANAGED LTD (dir. Bunea, RO) and TECHOFF SRV LIMITED (dir. Palo, IT) โ€” operating AS47890 and AS48090 under the brand DMZHOST, merged at the network layer.

What did it do? Hosted a coordinated SSH credential-stuffing/server-profiling botnet; both ASNs earn Spamhaus ASN-DROP and bulletproof classification.

Where is it? Registered GB; routed RO (Orange Romania) and NL (FiberXpress); declared variously AD/BG/NL/SC. Nowhere it claims and everywhere it needs.

When? AS48090 since 2019, AS47890 since 2020; TECHOFF SRV LIMITED incorporated Nov 2024 to assume the DMZHOST brand; observed attacking continuously Mayโ€“July 2026.

How are the two ASNs one operator? Shared maintainer TECHOFF-MNT, shared Gmail abuse desk, and a dual-origin prefix (2.57.122.0/24) announceable from both.

Why the structure? Jurisdictional arbitrage and attribution fragmentation: separate shells defeat corporate-registry attribution; dual-origin routing defeats single-ASN takedown; a scatter of declared countries defeats single-jurisdiction enforcement.

Why should you care? Because the "UK company" label on an attacking IP means nothing here, and the tooling it hosts is the loader documented in TI-2026-083C โ€” the appraiser that decides whether your server is worth keeping.

10. The counter-narrative, steelmanned โ€” then defeated

The strongest innocent reading: "UNMANAGED LTD and TECHOFF SRV LIMITED are legitimate discount hosts. Bulletproof classification is guilt-by-association; any cheap unmanaged VPS provider accumulates abuse because customers misuse servers the host never inspects. Spamhaus ASN-DROP over-blocks. The three names are just resellers and rebrands. The Gmail abuse desk is amateurism, not malice."

It is a fair argument for a single budget host. It does not survive this evidence:

  1. A legitimate host does not dual-origin a customer prefix across two separately-incorporated companies' ASNs. That is not how reselling works; it is an operator-controlled failover between networks it both controls. Legitimate separation would show separate maintainers.
  2. A legitimate host answers abuse. 81,943 reports on one IP, last delivered 2026-07-20, with the IP still live and still attacking, is not a backlog โ€” it is a policy.
  3. A legitimate host does not need to declare Andorra. The country smear across AD/BG/NL/SC/RO has no operational purpose except to frustrate reporting.
  4. Independent convergence. Spamhaus (registry-level DROP), AbuseIPDB (six-figure reports), Team Cymru (names the shells and the virtual-office facade by hand), and our honeypot all arrive at the same place from different data. Guilt-by-association requires one accuser; this has four, disjoint.

The innocent reading explains a messy host. It cannot explain a coordinated one.

11. Read between the lines

12. What if

What if AS48090 is dropped hard tomorrow? The 2.57.122.0/24 route flips to AS47890; the DMZHOST brand migrates to a new TECHOFF-successor shell; nothing meaningful stops. Takedown of one ASN is a speed bump, by design.

What if you filed a perfect abuse report? It lands in a Gmail inbox with, on current evidence, no operational consequence. The constraining anchor does not answer.

What if you treated the three names as one from the start? You would have attributed correctly on day one โ€” which is precisely why the operation is built to make you treat them as three.

13. Documented vs inferred โ€” the honest ledger

ClaimStatusConfidence
AS47890 & AS48090 both on Spamhaus ASN-DROP, bulletproofDOCUMENTEDHIGH
Two legally separate UK companies, different directorsDOCUMENTEDHIGH
TECHOFF-MNT maintains prefixes on both ASNs; 2.57.122.0/24 dual-originDOCUMENTEDHIGH
Shared Gmail abuse desk (dmzhostabuse@gmail.com) across both ASNsDOCUMENTEDHIGH
GB-registered, RO/NL-routed, AD/BG/SC-declaredDOCUMENTEDHIGH
81,943 AbuseIPDB reports on 2.57.122.238DOCUMENTEDHIGH
91.92.40.0/24 is a separate operator (TechTies/HostSlick)DOCUMENTEDHIGH
Coordinated SSH botnet on the infrastructureDOCUMENTEDHIGH
GB registration is deliberate cover for a RO-run networkINFERREDMEDIUM-HIGH
Dual-origin routing is an intentional evasion designINFERREDHIGH
Director Bunea personally connected to the operationINFERREDMEDIUM-HIGH

14. Infrastructure & IOCs

Autonomous systems

Prefixes: 2.57.121.0/24, 2.57.122.0/24, 80.94.92.0/24, 92.118.39.0/24 (AS47890); 195.178.110.0/24, 45.148.10.0/24, 93.123.109.0/24 (AS48090). Note 2.57.122.0/24 = dual-origin (AS47890 + AS48090).

High-threat nodes (threat score 100): 2.57.122.238, 80.94.92.55, 2.57.122.209, 92.118.39.14, 92.118.39.71, 193.46.255.86 (AS47890); 195.178.110.228, 195.178.110.232, 195.178.110.217, 45.148.10.240 (AS48090).

Behavioural IOCs: HASSH 16443846184eafde36765c9bab2f4397 (Go scanner); command-automation hash 668c13b46ed6fac0; shared credential set root:123456 / root:1234 / es:12345678 / docker:123456 / centos:12345678 / ftpuser:12345.

Adjacent, distinct operator: AS197170 TechTies Inc. (SC) / HostSlick (hostslick.de) โ€” 91.92.40.0/24. Same ecosystem, different landlord.

15. Sources

TLP:WHITE. Every claim above anchors to a primary registry record, a blocklist, a report aggregator, or direct honeypot observation. Where sources disagree on a country or a name, the disagreement is recorded as the finding, not resolved by preference. Forgeable signals (shared wordlists, common scanners) are treated as toolkit/ecosystem evidence, never as proof of common ownership.

โš  Personal capacity. Research published independently โ€” not reflecting employer views. Derived from passive observation of attacks against personal infrastructure. Full disclaimer โ†’
โ† Previous Bulletproof Hosting โ€” 1 / 15 Next โ†’