Closing the Census โ And Why It Doesn't Close
TI-2026-088O โ Bulletproof Hosting series ยท Addendum to TI-2026-088 "The DMZHOST Trinity"
Confidence: HIGH on the identities and counts recovered by resuming the reverse queries (RIPE REST via a fresh egress + RIPEstat); deliberately careful on culpability โ this letter names a registration layer, distinguishes its confirmed-bulletproof outputs from its large mixed customer base, and accuses only what the evidence convicts.
The finding in one paragraph
088N ended with the census blocked โ RIPE rate-limited the reverse queries after five, leaving the brood at a floor of ~14 and four holders unresolved. This letter resumed the enumeration (RIPE hard-limits by source IP; a different egress and the separate RIPEstat service walk around it) intending to close the count. It did the opposite. Closing the identity gaps blew the scale wide open. The four unresolved "watchlist" holders resolved to named companies. The most active handle, mnt-bg-eurocrypt-1 โ which 088N could not attribute at all โ resolves to Euro Crypt EOOD, a Bulgarian company holding the legacy ASN AS25211. And the reverse queries revealed that the pool's handles are not small reseller accounts but industrial bulk-registration operations: VIA-REGISTRY-MNT alone maintains ~48 autonomous systems and 136 organisations; RTMNETWORKS-MNT (RTM Networks B.V., NL) maintains ~92; mnt-bg-eurocrypt-1 (Euro Crypt EOOD) maintains 3 ASNs, 45 orgs, and 43 domains. The confirmed-bulletproof brands this series has tracked โ TechTies, DEDIK, VPSVAULT, ZeXoTeK, and now ISAEV (AS200730, confirmed maintained by VIA-REGISTRY-MNT) โ are a subset of these registrars' output, mixed in among a mass of orgs the honeypot has never seen do anything at all. So the census does not close to a finite list of villains. It closes on a doctrine: the enabler layer is a set of legitimate-looking bulk registration businesses, individually deniable and mostly mixed, and you cannot blocklist a registrar's whole customer base. You name the handles, you convict the confirmed outputs, and you watch the yard. This is the honest terminus of the enabler arc โ not a shorter list, but a truer shape.
1. The identities, closed
Resuming the queries resolved every holder 088N had to leave as "unresolved" or "no standalone identity":
| Handle / ASN | Now resolves to | Note |
|---|---|---|
mnt-bg-eurocrypt-1 / AS25211 | Euro Crypt EOOD (BG) โ EuroCrypt-AS | the most active handle finally has a name; AS25211 is a legacy 16-bit ASN |
| AS47878 | ZeXoTeK IT-Services GmbH (nx4) | a second ZeXoTeK ASN โ it runs several |
| AS197160 | Markus Vogt (DE) | a named individual behind a German handle |
| AS207144 | SOFCOMPANY Ltd (BG) โ bg-sofcompany-1-mnt | 43 announced prefixes โ a substantial network |
| AS24750 | MyAcct LTD (BG) โ mnt-bg-myacct-1 | legacy 16-bit ASN, 17 prefixes |
| AS48452 | Telco power Ltd โ as-name TRAFFIC-NET | the RAZI Network LIR of 088M |
RTMNETWORKS-MNT / AS211344 | RTM Networks B.V. (NL) | a Dutch bulk registrar |
| AS43944 | Velox Ltd (VELOXAS) | legacy 16-bit ASN under eurocrypt |
| AS208737 | myPOS LIMITED (MYPOSAS) | an apparently-legitimate fintech name under the same handle โ see ยง4 |
Every handle in the pool is now a named entity. mnt-bg-eurocrypt-1 is not the identity-less void 088N suspected โ it is Euro Crypt EOOD, a registered Bulgarian company. The pool is a small family of named Bulgarian and Dutch/German registration businesses: Euro Crypt EOOD, Telco power Ltd / RAZI Network, SOFCOMPANY Ltd, MyAcct LTD, ZeXoTeK IT-Services GmbH, RTM Networks B.V., and the sprawling VIA-REGISTRY-MNT.
[DOCUMENTED] All previously-unresolved handles/holders are named (RIPEstat + Tor-routed RIPE REST).
2. The scale, opened
The reverse queries returned counts that reframe "brood" as the wrong word. This is not a family; it is a warehouse:
| Registrar handle | Autonomous systems | Organisations | Other |
|---|---|---|---|
VIA-REGISTRY-MNT | ~48 | 136 | 39 inet6num, 34 route6, 254 role objects |
RTMNETWORKS-MNT (RTM Networks B.V.) | ~6โ18 | 92 | 99 inetnum, 18 inet6num |
mnt-bg-eurocrypt-1 (Euro Crypt EOOD) | 3 | 45 | 80 inetnum, 43 domains, 80 route |
VIA-REGISTRY-MNT alone maintains roughly forty-eight autonomous systems and one hundred thirty-six organisations โ a bulk ASN-and-prefix registration service on an industrial scale, of which DEDIK (ORG-DSL56-RIPE) is one customer and ISAEV (AS200730) is another. That last link matters: 088K could not tie the ISAEV prefix (87.251.64.0/24) to the operators; the census now shows VIA-REGISTRY-MNT maintains ISAEV's autonomous system directly, placing it inside the same registration substrate. Three handles, taken together, touch on the order of fifty-plus ASNs and two-hundred-seventy-plus organisations. The true footprint of the substrate is not 15โ20 ASNs. It is an order of magnitude larger โ and still not fully enumerated (MLNL-MNT and GCN-LIR-MNT returned empty through the Tor exit and remain open).
[DOCUMENTED] The pool's handles maintain ~50+ ASNs and ~270+ orgs; VIA-REGISTRY-MNT maintains AS200730 (ISAEV), closing an open 088K thread at the registry layer.
3. The legacy-ASN habit, confirmed as a pattern
088L found a repurposed bank ASN; 088N found legacy blocks; the closed census confirms repurposing aged number resources is a standing habit of this substrate. Euro Crypt EOOD's own ASN is AS25211 โ a 16-bit legacy allocation. Under the same handle sit AS43944 (Velox Ltd) and, in the wider pool, AS24750 (MyAcct LTD) โ both legacy 16-bit ASNs, both far older than the 21xxxx numbers the fresh bulletproof brands ride. A 16-bit ASN reads to a naive reputation filter as an incumbent, an established network; acquiring or holding old iron and re-skinning it is the number-resource equivalent of the UK-shell and virtual-office facades (088G). The whole operation, from company registration to routing to weapons (088K), is an exercise in renting or borrowing trust signals it did not earn โ and aged autonomous systems are one more such signal.
[DOCUMENTED] Legacy 16-bit ASNs (AS25211 EuroCrypt, AS43944 Velox, AS24750 MyAcct) recur under the pool's handles.
4. The calibration that makes this honest โ the yard is not the convicts
Here is where the letter must be most careful, because the scale is precisely what tempts over-reach. Of the fifty-plus ASNs and hundreds of orgs the handles maintain, only a handful have any threat telemetry at all. Query the honeypot/threat database for the newly-named members โ Euro Crypt EOOD, Velox, myPOS, Velorum, SOFCOMPANY, MyAcct โ and the answer is uniform: not in the database. They have never attacked the estate, carry no Spamhaus listing in our records, appear in no campaign. And one of them โ myPOS LIMITED (AS208737, under the very same mnt-bg-eurocrypt-1 handle) โ is the name of an apparently-legitimate European payments company. A registration handle that maintains a fintech ASN and a bulletproof host is not evidence the fintech is criminal; it is evidence the registrar serves a mixed customer base.
That is the load-bearing distinction of this entire enabler arc, stated at its widest point: VIA-REGISTRY-MNT's 136 orgs are not 136 bulletproof operators. They are the customer list of a bulk registration business, in which a subset โ the ones with honeypot evidence, Spamhaus listings, and prior dossiers (TechTies, DEDIK, VPSVAULT, ZeXoTeK, ISAEV) โ are confirmed bulletproof, and the majority are unproven, quite possibly ordinary. The Costume Catalog taught this exact discipline: write down the yard so you recognise its vans, but do not clamp every van that ever parked there. Applied here, at 270 orgs, the discipline is not optional โ it is the only thing standing between an intelligence product and a defamation of a hundred businesses. This letter therefore names the registration layer and its scale as documented fact, convicts only the telemetry-confirmed subset, and treats the remainder as recognition targets โ the yard, not the convicts.
[CALIBRATED] ~5 confirmed-bulletproof outputs (TechTies, DEDIK, VPSVAULT, ZeXoTeK, ISAEV) within ~270 maintained orgs; the majority (incl. an apparent legitimate fintech) have zero threat telemetry and are NOT accused.
5. Why the census cannot close โ and why that is the answer
The instinct behind "enumerate the full brood" is that a bad ecosystem has a boundary you can draw around it. The closed census says otherwise, and the reason is structural. The bulletproof operators do not run their own registration infrastructure; they buy it from bulk registration services โ Via-Registry, RTM Networks, Euro Crypt, Telco power โ that also serve legitimate or unproven customers, at industrial volume, behind a registry that rate-limits the very queries needed to separate the wheat from the chaff. So there is no clean boundary to draw. The "brood" is not a finite set of costumed ASNs; it is a floating subset of a large, mixed, deliberately-hard-to-enumerate registration layer, and its membership changes as brands rotate. You cannot close the census because the thing you are counting is designed not to have edges โ the mix with legitimate customers is the camouflage, and the registry's rate limits are the moat. The correct output of the enumeration is therefore not a list but a method: track the handles (Euro Crypt EOOD, Telco power / RAZI, ZeXoTeK, RTM Networks, Via-Registry) as standing entities; watch which orgs they mint; and convict each output only on its own telemetry. The census closes by delivering that method and conceding โ accurately โ that a complete, static roster is neither achievable nor the right goal.
[DOCUMENTED / CONCEDED] No finite closed roster is achievable; the enabler is a large mixed registration layer. The deliverable is the tracked-handle method + the convicted subset.
6. Seven questions
Q1. You set out to close the census and now say it can't be closed โ didn't the task fail? The task succeeded: it resolved every open identity, quantified the true scale, and closed the ISAEV thread. What it disproved was the premise โ that a clean finite brood exists. Discovering that the enabler is a mixed industrial layer, not a countable gang, is a more accurate result than a falsely-tidy list. A census that reports "the population has no fixed edge, here is why, and here is how to track it anyway" is complete, not failed.
Q2. If most of the 270 orgs are innocent, why name the registrars at all? Because the registrars are the documented, persistent, trackable layer, and naming them is not accusing their customers. Euro Crypt EOOD and Via-Registry demonstrably provisioned confirmed-bulletproof brands; that is a fact about the registrar's output, stated without claiming its every customer is criminal. Naming the yard is how you recognise the next van; it is not clamping the yard.
Q3. Is myPOS being implicated? No โ explicitly not. myPOS is named as an example of the opposite point: that a bulk registration handle serves legitimate-looking names alongside bulletproof ones, which is exactly why blanket guilt-by-handle is wrong. Its appearance is evidence for the mixed-base finding and against over-reach.
Q4. How solid is the ISAEV โ Via-Registry link? It is a direct RIPE reverse-query result: VIA-REGISTRY-MNT is mnt-by on AS200730 (ISAEV). That is a provisioning-handle fact, the same class as every link in 088M/N โ it places ISAEV in the substrate, not that ISAEV and DEDIK are one operator.
Q5. Doesn't using Tor to beat RIPE's rate limit undermine the data's reliability? No โ Tor changed only the source IP, not the responses. RIPE served the same authoritative database records to a different requester. The rate limit is an anti-scraping control, not an integrity control; routing around it recovers the same facts the block was withholding, and RIPEstat (an official RIPE service) independently corroborated the identity resolutions.
Q6. Euro Crypt EOOD, Velox, MyAcct โ legitimate companies or shells? Undetermined, and left so. They are registered Bulgarian companies with real ASNs; whether they are genuine businesses that also serve bad customers, or shells built for the purpose, is not established by registry data alone. The honest label is "named registration entities in the substrate," not "criminal shells."
Q7. What actually closes the remaining gap? Enumerating MLNL-MNT and GCN-LIR-MNT (empty through this Tor exit); resolving the ~270 orgs against threat telemetry to size the convicted subset precisely; and standing up the tracked-handle watch so new mints are caught live. Each is mechanical; none changes the shape already found.
7. The counter-narrative, steelmanned โ then defeated
Steelman: "You've discovered that some hosting companies use bulk RIPE registration agents โ which every LIR and reseller on the continent does. Via-Registry maintaining 48 ASNs is what a registrar looks like, not a conspiracy. You've dressed ordinary registry plumbing as a bulletproof substrate and admitted most of it is innocent. There's no there there."
Defeat: The letter concedes the plumbing is ordinary and most customers unproven โ and that concession is why the finding survives. The claim is not "these 270 orgs are criminal." It is the two things the evidence does establish: first, that a small set of named, trackable registration handles (Euro Crypt EOOD, Via-Registry, Telco power, ZeXoTeK, RTM Networks) is the documented common provisioning origin of the specific confirmed-bulletproof brands three separate investigations independently flagged (TechTies, DEDIK, VPSVAULT, ZeXoTeK, ISAEV); and second, that this origin is industrial and mixed, which is precisely what makes the bulletproof problem hard โ the bad customers hide in a large legitimate base behind a rate-limited registry. "Registrars serve mixed bases" is not a refutation; it is the mechanism the finding identifies. Ordinary plumbing that reliably delivers to extraordinary tenants, at scale, behind a moat, is the story โ and the letter tells exactly that story, no more.
8. Read between the lines
The enabler arc โ M, N, O โ ends where deep investigations of criminal infrastructure often end: not at a villain, but at a market failure. There is no kingpin behind DMZHOST's second floor; there is a registration industry that will mint an ASN, sign a route object, and lend an aged number to anyone who pays, mixing them indistinguishably into a legitimate customer base, in a registry that makes bulk verification deliberately slow. The bulletproof operators are not the disease; they are a symptom of an enabler layer whose business model is to sell deniable provisioning at volume and ask no questions. That is why every takedown of an operator is followed by another wearing a fresh costume from the same wardrobe โ the wardrobe is the durable thing, and the wardrobe is mostly legal. The census could not close because the honest answer to "how big is the bulletproof brood" is "it is a rounding error inside a large, ordinary, mixed registration market that has no incentive to expel it." Naming that โ precisely, without over-accusing the innocent majority โ is the most useful thing the enumeration could produce. The seed led not to a person but to a layer, and the layer is the real subject.
9. What if
What if the accountability were placed on the registration layer rather than chased around the operator layer? A registrar that maintains 48 ASNs and 136 orgs, several of them repeatedly-dossiered bulletproof hosts, is answerable โ at RIPE, under a name (Via-Registry; Euro Crypt EOOD; Telco power / RAZI Network; RTM Networks B.V.) โ for its own due diligence, in a way no offshore operator shell ever is. The lever this arc uncovers is not another blocklist; it is a question RIPE can ask its own members: why does this handle keep provisioning ASN-DROP hosts? The tenant is trackable by its tool (L); the host by its maintainer (M); the substrate by these named registrars (N/O). Four layers, four levers โ and the deepest one is the most nameable, most legal, and least chased. That is the gap the census closes by exposing: the enabler is reachable precisely because it is not hiding โ it is a registered business, hiding its bad customers in plain sight among its good ones.
10. Documented vs inferred โ the honest ledger
| Claim | Status |
|---|---|
mnt-bg-eurocrypt-1 = Euro Crypt EOOD (BG); AS25211 legacy | DOCUMENTED โ RIPEstat + RIPE REST |
| Watchlist holders named: ZeXoTeK (AS47878), Markus Vogt (AS197160), SOFCOMPANY Ltd (AS207144, 43 prefixes), MyAcct LTD (AS24750, 17 prefixes) | DOCUMENTED โ RIPEstat |
VIA-REGISTRY-MNT maintains ~48 ASNs / 136 orgs (incl DEDIK, ISAEV/AS200730) | DOCUMENTED โ Tor-routed RIPE REST inverse |
RTMNETWORKS-MNT = RTM Networks B.V. (NL), ~92 orgs; mnt-bg-eurocrypt-1 45 orgs / 43 domains | DOCUMENTED โ RIPE REST inverse |
| Legacy 16-bit ASNs (AS25211, AS43944, AS24750) recur under the handles | DOCUMENTED โ RIPEstat |
| The ~270 maintained orgs are all bulletproof | REJECTED โ only ~5 have threat telemetry; the rest are unproven (incl an apparent fintech) |
| Euro Crypt / Velox / MyAcct / etc. are criminal shells | NOT CLAIMED โ named registration entities; culpability undetermined |
| The census can be closed to a finite bulletproof roster | REJECTED / CONCEDED โ the enabler is a large mixed registration layer without a clean edge |
| The registrars are answerable at RIPE for their provisioning of confirmed-bulletproof hosts | INFERRED (policy) โ a named, reachable due-diligence lever |
11. Infrastructure & IOCs
THE REGISTRATION SUBSTRATE (named handles; the persistent, trackable layer):
mnt-bg-eurocrypt-1 = Euro Crypt EOOD (BG) | AS25211 (legacy 16-bit) | 3 ASN / 45 org / 43 domains
lir-bg-telco-1-MNT = Telco power Ltd / RAZI Network (BG) | AS48452 "TRAFFIC-NET" (2008 block)
bg-sofcompany-1-mnt = SOFCOMPANY Ltd (BG) | AS207144 (43 prefixes)
mnt-bg-myacct-1 = MyAcct LTD (BG) | AS24750 (legacy 16-bit, 17 prefixes)
MNT-ZEXOTEK = ZeXoTeK IT-Services GmbH (DE) | AS8649, AS47878 (multiple ASNs) [Phantom 026]
mnt-de-xsserver-1 = XSServer GmbH (DE) | AS198584 PIO-Hosting [Phantom 026]
VIA-REGISTRY-MNT = Via-Registry (bulk) | ~48 ASNs / 136 orgs | maintains DEDIK + ISAEV/AS200730
RTMNETWORKS-MNT = RTM Networks B.V. (NL) | ~92 orgs
(open: MLNL-MNT, GCN-LIR-MNT โ empty via this Tor exit; also AS197160 = Markus Vogt, DE)
CONFIRMED-BULLETPROOF SUBSET (telemetry/Spamhaus/prior dossier):
AS197170 TechTies ยท AS209413 DEDIK ยท AS215925 VPSVAULT ยท AS8649 ZeXoTeK ยท AS200730 ISAEV
YARD (named, NOT accused โ zero threat telemetry): Euro Crypt EOOD, Velox Ltd, myPOS LIMITED, Velorum B.V.,
SOFCOMPANY Ltd, MyAcct LTD, + ~130 further VIA-REGISTRY orgs
LEGACY/REPURPOSED: AS25211 (EuroCrypt) ยท AS43944 (Velox) ยท AS24750 (MyAcct) ยท AS48452 (Telco power 2008)
METHOD NOTE: RIPE reverse-whois is IP-rate-limited (ERROR:201); recovered via a fresh egress (Tor) + RIPEstat
Defensive action: stand up a tracked-handle watch on Euro Crypt EOOD (mnt-bg-eurocrypt-1), Telco power / RAZI (lir-bg-telco-1-MNT), ZeXoTeK (MNT-ZEXOTEK), RTM Networks B.V. (RTMNETWORKS-MNT), and VIA-REGISTRY-MNT; any org they newly mint is a recognition target. Convict each output on its own telemetry โ do NOT blocklist the maintained set (it contains legitimate/unproven customers). Escalate the registrars as a RIPE due-diligence question, not the customer base. Treat the reverse-whois rate limit as an operational constraint; batch and rotate egress.
12. Sources
RIPE NCC RIPEstat (as-overview, announced-prefixes โ holder resolution for AS47878/197160/207144/24750/25211/43944/208737/200730/209267/211344, not rate-limited); RIPE NCC REST database (search.json inverse mnt-by, routed via a fresh egress to bypass the source-IP ERROR:201 daily limit โ object counts for VIA-REGISTRY-MNT, mnt-bg-eurocrypt-1, RTMNETWORKS-MNT); LSN threat_intel database (negative telemetry check on the named members). Cross-references: this series' 088K (ISAEV), 088M (the enabler), 088N (the brood); the Phantom ASN (TI-2026-026) and Costume Catalog (TI-2026-082) series. TLP:WHITE. The census is closed as a method, not a finite roster.