Jurisdictional Arbitrage: One Operator, Six Countries, No Accountability

TI-2026-088I โ€” Bulletproof Hosting series ยท Addendum to TI-2026-088 "The DMZHOST Trinity"

Confidence: HIGH for the multi-jurisdiction discrepancy (direct multi-source enumeration, cross-checked with live RIPE whois); the deliberateness of the arbitrage is INFERRED and marked as such.

The finding in one paragraph

Ask a simple question of the DMZHOST network โ€” what country is it in? โ€” and the registries answer with six different countries, and they do not agree. The companies are registered in Great Britain. The IP address space routes and geolocates in Romania (AS47890) and the Netherlands (AS48090). The RIPE inetnum objects claim Andorra (for 195.178.110.0/24 and 45.148.10.0/24) and the Netherlands (for 2.57.122.0/24). Team Cymru's routing data places one prefix in Bulgaria. And Spamhaus's ASN-DROP file attributes the two ASNs to Romania (bunea.eu) and the Seychelles (dmzhost.co). Across 7 of 7 sampled IPs, the country of registration and the country of operation disagree; individual addresses carry three or four conflicting national claims each. This is not a data-quality problem, and it is not confusion. It is jurisdictional arbitrage โ€” a deliberate scattering of legal, routing, and registry geography so that no single national authority, abuse desk, or geo-filter can see, reach, or act on the whole operation at once. The incoherence is the defence.

1. The question that has six answers

There is no single true "location" of a network โ€” but there is supposed to be coherence between the layers. A legitimate Dutch hosting company registers in the Netherlands, routes in the Netherlands, and files RIPE objects claiming the Netherlands. DMZHOST's layers instead point in every direction at once. Laid out as a stack:

LayerWhat it claimsSource
Company registrationGB (both ASNs' holders)Companies House, RIPE org country
IP routing / geolocationRO (AS47890), NL (AS48090)AbuseIPDB, honeypot geo
Team Cymru prefix originBG (for 195.178.110.0/24)Team Cymru
RIPE inetnum object countryNL (2.57.122.0/24), AD (195.178.110.0/24, 45.148.10.0/24)live RIPE whois
Spamhaus ASN-DROP attributionRO / bunea.eu (AS47890), SC / dmzhost.co (AS48090)Spamhaus asndrop.json

Six countries โ€” GB, RO, NL, AD, BG, SC โ€” for one operator, spread across five independent data layers. Andorra and the Seychelles are the tells: neither is a plausible operating location for this traffic, and both are classic offshore/privacy jurisdictions chosen for what they don't require, not for where anything actually runs.

It is worth naming what each jurisdiction is actually for in this structure, because they are not interchangeable โ€” each is selected for a specific property. Great Britain supplies credibility: a Companies House number and a London address read as a legitimate European business (see 088G). Romania and the Netherlands supply the actual racks โ€” cheap, well-connected European hosting where the packets really originate. Andorra and the Seychelles supply opacity: micro-jurisdictions with minimal registry scrutiny and no hosting industry to speak of, named in inetnum objects and offshore branding precisely because they answer no one. Bulgaria appears as a routing-data artifact, a further smear that makes the picture noisier still. Each country contributes a different property โ€” trust, infrastructure, or opacity โ€” and no single country supplies more than one. That division of labour is the signature of design: a stale-record or lazy-geolocation story would scatter the countries randomly across the layers, but here each jurisdiction is doing a distinct, sensible-for-the-operator job. Randomness has no division of labour; strategy does.

[DOCUMENTED] The DMZHOST operator's geography splits across at least six countries (GB, RO, NL, AD, BG, SC) over five registry/routing layers that do not agree.

2. The mismatch, per address

The scatter is not an aggregate artifact; it reproduces on individual IPs. Sampling the cluster, every address shows a registration-vs-operation mismatch, and several carry three or four national claims at once:

IPGeolocationCymru prefixRIPE inetnumASN registrationDistinct claims
2.57.122.209RORONLGBGB / NL / RO โ€” 3-way
92.118.39.71RORONLGBGB / NL / RO โ€” 3-way
80.94.92.55RORONLGBGB / NL / RO โ€” 3-way
2.57.122.238RORONLGBGB / RO
195.178.110.228NLBGADGBAD / BG / GB / NL โ€” 4-way
195.178.110.232NLBGADGBAD / BG / GB / NL โ€” 4-way
45.148.10.240NLROADGBAD / GB / NL / RO โ€” 4-way

7 of 7 sampled IPs mismatch; live RIPE whois confirms country: NL on the 2.57.122.0/24 inetnum and country: AD on the 195.178.110.0/24 and 45.148.10.0/24 inetnums, while the org object for TECHOFF SRV LIMITED separately lists country: GB. Take the cleanest single example: 195.178.110.232 geolocates in the Netherlands, is placed in Bulgaria by Team Cymru's routing, claims Andorra in its RIPE inetnum, and is registered to a Great Britain company. One address, four countries, none of them agreeing โ€” and it is the same AdaptixC2 node examined in 088D.

[DOCUMENTED] 7/7 sampled IPs show registration-vs-geolocation mismatch; several carry 3โ€“4 distinct national claims per address (e.g. 195.178.110.232: NL geo / BG Cymru / AD RDAP / GB registration).

3. Why the scatter is a defence, not an accident

Each layer of geography maps to a different mechanism of accountability, and scattering them breaks each mechanism in turn:

And beneath the geographic scatter sits the routing failover documented in 088F: a single maintainer, TECHOFF-MNT, signs route objects for both ASNs, so the operator can shift a prefix between AS47890 (RO-facing) and AS48090 (NL-facing) โ€” between jurisdictions โ€” faster than any single-country abuse or legal process can even be filed. The geography is not just scattered; it is scattered and mobile. A takedown effort has to hit a moving target that is legally British, operationally Romanian and Dutch, and offshore-claimed in Andorra and the Seychelles, all at once. No single authority has the reach.

The arbitrage also quietly exploits the gaps between the jurisdictions, not just the jurisdictions themselves. European abuse and law-enforcement cooperation is built on the assumption that a network's legal home and its operational home are the same place, or at least cooperating places โ€” an MLAT request flows from the country where harm occurred to the country where the responsible party sits. This operator breaks that assumption structurally: harm occurs against victims worldwide, the packets originate in RO/NL, the responsible company sits in GB, and the registry claims point to AD/SC โ€” four different legal domains, none of which both hosts the infrastructure and holds the registrant. The request that could compel action would have to originate in one country, name a registrant in a second, seize infrastructure in a third, and pierce an offshore claim in a fourth, with each handoff crossing a border where cooperation is slow, discretionary, or absent. The operator does not need any single jurisdiction to be lawless; it only needs the seams between lawful jurisdictions to be wide enough to fall through. Six countries provide a great many seams.

[INFERRED] The geographic scatter is a deliberate arbitrage that fractures abuse response, law enforcement, and geo-filtering across mutually non-cooperating jurisdictions โ€” not an artifact of stale records.

4. The one direction the scatter points โ€” Romania

For all the misdirection, the layers are not equally weighted, and two of them point the same way. Strip out the offshore-claim noise (AD, SC) and the corporate flag of convenience (GB), and the operational and sponsorship layers both resolve to Romania: AS47890 geolocates RO, Spamhaus attributes it to bunea.eu (cc RO), and its RIPE sponsoring-org is Bunea TELECOM SRL (Timiศ™oara, RO), sharing maintainer ro-btel2-1-mnt (088C). The arbitrage scatters six countries to obscure the operator, but the two layers that are hardest to fake โ€” where the traffic actually originates and who actually signed the RIPE sponsorship โ€” converge on Romania. The Netherlands is real too (AS48090's racks), but it is the secondary face; the sponsorship anchor and the primary routing both sit in RO. Andorra, Bulgaria, the Seychelles, and Great Britain are, to varying degrees, claims; Romania is where the load-bearing evidence lands.

5. Seven questions

Q1. Isn't multi-country data just normal for internet infrastructure? Some spread is normal โ€” a company can route abroad. Six countries across five layers, with the registration country matching none of the operational ones and two offshore-privacy jurisdictions (AD, SC) in the mix, is not normal spread. It is a pattern, and the pattern is avoidance.

Q2. Couldn't the mismatches just be stale RIPE records and lazy geolocation? Some individual fields could be stale โ€” but not all seven IPs, not across five independent sources, not with the registration country cleanly disjoint from every operational one. Staleness is random; this is systematic, and systematic disagreement is a choice.

Q3. Why claim Andorra of all places? Because Andorra is a small offshore jurisdiction with minimal registry scrutiny and no meaningful role in European hosting โ€” exactly the kind of country you name in an inetnum when the name's purpose is to satisfy a field, not to locate a server. The AD claim is not where anything runs; it is where accountability is designed to evaporate.

Q4. Does the scatter actually stop anyone? It does not stop detection โ€” this dossier detected it. It stops action: it ensures that any one abuse desk, court, or blocklist sees only a fragment and cannot compel the rest. The operation is visible and unreachable at the same time, which is the whole point of bulletproof hosting.

Q5. If it points to Romania, why does the arbitrage work at all? Because "points to Romania" is an analytical conclusion drawn by correlating five sources; an abuse desk or an automated geo-filter does not do that correlation โ€” it acts on the single field in front of it, which says GB, or AD, or NL. The arbitrage defeats the systems that act on one field; it does not defeat a forensic analyst who reads them together.

Q6. Which layer should a defender trust? For operational response: the geolocation/routing (RO/NL) โ€” that is where packets are. For attribution: the sponsorship and Spamhaus/DNS anchors (RO, bunea.eu, Bunea TELECOM). Distrust the RIPE inetnum country (NL/AD) and the corporate registration (GB) as the layers most cheaply falsified.

Q7. What would change the reading? If the operational layers (routing, sponsorship) also scattered incoherently, "deliberate arbitrage" would weaken toward "chaotic records." Instead the misdirection layers scatter (GB/AD/BG/SC) while the load-bearing layers converge (RO) โ€” which is exactly the signature of arbitrage: noise where it's cheap, consistency where it's forced.

6. The counter-narrative, steelmanned โ€” then defeated

Steelman: "You are pattern-matching noise. Geolocation databases are notoriously wrong, RIPE inetnum country fields are often stale or arbitrary, Team Cymru and AbuseIPDB disagree on plenty of legitimate networks, and virtual-office companies routinely register in one country and rent racks in another. Every fact here has an innocent per-field explanation; stacking them into 'arbitrage' is a narrative you imposed."

Defeat: Each field does have an innocent explanation in isolation โ€” and the finding does not rest on any single field. It rests on the joint distribution: the registration country matching none of the operational countries, across seven of seven IPs, over five independent sources, with two offshore-privacy jurisdictions (AD, SC) appearing exactly where a claim is cheapest and no server runs. Innocent noise is random โ€” it would sometimes put the registration country and the routing country in agreement. This never does. And the innocent story cannot explain the structure: the misdirection layers (GB/AD/BG/SC) scatter while the hard-to-fake layers (RO routing, RO sponsorship) converge. Randomness does not produce that shape; a strategy does. The narrative was not imposed on the data โ€” it is the only account that fits the data's asymmetry.

7. Read between the lines

Jurisdictional arbitrage is the legal expression of the same idea that runs through every letter in this series: no single point of failure. The dual-origin prefix (088F) is routing redundancy; the two-shell corporate split (088J) is legal redundancy; the six-country scatter is jurisdictional redundancy. Each spreads the operation across enough independent domains that no one adversary โ€” a filter, a court, a registrar, an abuse team โ€” controls enough of them to matter. And each has the same crack: the redundancy hides the operator from any single view, but a forensic view that correlates all the layers finds the operator anyway, because the layers the operator cannot fake โ€” where the traffic originates, who signed the sponsorship โ€” keep pointing home. The arbitrage defeats the abuse desk and the geo-filter; it does not defeat the analyst who refuses to look at one field at a time. Read together, six countries collapse to one: Romania.

8. What if

What if abuse and enforcement correlated the layers instead of acting on one field? An abuse desk that read 195.178.110.232 as "NL-geo / BG-Cymru / AD-RDAP / GB-registrant" โ€” rather than picking one โ€” would immediately flag it as arbitrage and escalate rather than route a complaint into the GB void. A takedown that targeted the convergent layers (RO routing, the Bunea TELECOM sponsorship, the TECHOFF-MNT maintainer) rather than the scattered ones (the GB shell, the AD inetnum) would aim where a real accountable party actually sits. The defence only works against systems that look at one country at a time; the countermeasure is simply to stop doing that.

9. Documented vs inferred โ€” the honest ledger

ClaimStatus
Company registration = GB for both ASN holdersDOCUMENTED โ€” Companies House / RIPE org
Routing/geolocation = RO (AS47890) / NL (AS48090)DOCUMENTED โ€” AbuseIPDB, honeypot geo, registration_vs_geo_mismatch: true
RIPE inetnum claims NL (2.57.122.0/24) and AD (195.178.110.0/24, 45.148.10.0/24)DOCUMENTED โ€” live RIPE whois
Team Cymru places 195.178.110.0/24 in BGDOCUMENTED โ€” Team Cymru
Spamhaus attributes AS47890โ†’RO/bunea.eu, AS48090โ†’SC/dmzhost.coDOCUMENTED โ€” Spamhaus asndrop.json
7/7 sampled IPs mismatch; several show 3โ€“4 country claimsDOCUMENTED โ€” multi-source per-IP enumeration
The scatter is deliberate arbitrage, not stale recordsINFERRED (HIGH) โ€” from the systematic asymmetry (misdirection scatters, load-bearing layers converge)
The operational/attribution centre is RomaniaINFERRED (HIGH) โ€” RO routing + Bunea TELECOM sponsorship + bunea.eu converge

10. Infrastructure & IOCs

Six-country scatter for one operator:
  GB  company registration (UNMANAGED LTD / TECHOFF SRV LIMITED)      <- flag of convenience
  RO  routing/geo AS47890 + Spamhaus bunea.eu + Bunea TELECOM sponsor  <- LOAD-BEARING (attribution home)
  NL  routing/geo AS48090 + RIPE inetnum 2.57.122.0/24                 <- real secondary
  AD  RIPE inetnum 195.178.110.0/24, 45.148.10.0/24                    <- offshore claim
  BG  Team Cymru prefix origin 195.178.110.0/24                        <- routing-data claim
  SC  Spamhaus AS48090 / dmzhost.co "Offshore / Total Privacy"         <- offshore brand claim

Cleanest per-IP illustrations (single IP, multiple countries):
  2.57.122.209    geo RO | cymru RO | rdap NL | reg GB          (3-way)
  195.178.110.232 geo NL | cymru BG | rdap AD | reg GB          (4-way; the AdaptixC2 node of 088D)

Failover coupling:  one maintainer TECHOFF-MNT signs route objects for BOTH ASNs (088F) โ€”
                    the operator can shift a prefix between RO-facing and NL-facing ASNs at will.

Defensive action: do not act on any single geography field for this operator. For response, use the routing/geolocation layer (RO/NL, where packets are); for attribution and enforcement, target the convergent layers โ€” RO routing, the TECHOFF-MNT maintainer, and the Bunea TELECOM SRL sponsorship โ€” not the scattered GB/AD/BG/SC claims, which exist to absorb effort. Flag any single IP presenting 3+ conflicting national claims as an arbitrage indicator in its own right.

11. Sources

LSN sec_intel_ip_dossier (per-IP geo/prefix/registrant/ASN-registration disagreement for AS47890/AS48090 IPs); live RIPE NCC whois (inetnum country claims NL/AD; org country GB); sec_intel_asn_dossier (registration_vs_geo_mismatch, top_geolocation_country RO/NL); AbuseIPDB (geolocation); Team Cymru (prefix origin BG); Spamhaus ASN-DROP JSON (RO/bunea.eu, SC/dmzhost.co). Cross-references: TI-2026-088C (Bunea sponsorship, RO anchor), 088F (single-maintainer failover), 088J (corporate-layer redundancy). TLP:WHITE.

โš  Personal capacity. Research published independently โ€” not reflecting employer views. Derived from passive observation of attacks against personal infrastructure. Full disclaimer โ†’
โ† Previous Bulletproof Hosting โ€” 9 / 15 Next โ†’