Round 8 — published

Round 8 Investigation: The Business Model

August 2026 — Seven rounds listened to customers and to UltaHost's own marketing. This one goes to the registries. Almost everything below comes from a primary record: ICANN's own compliance index and monthly registrar files, UK Companies House filings, RIPE's routing database, three threat-intelligence datasets, the free court record — and two pages on UltaHost's own website that sit awkwardly beside one another.

Published alongside a retraction.The same day this round went up, we corrected our own record: a claim that UltaHost was “stonewalling actual lawsuits” had no citation and the court record shows none, two companies we described as registered UK entities do not exist on the UK register, and a birthplace and ethnicity line we had published was uncited and relevant to nothing. Those changes are itemised in the changelog. We mention it here, at the top, because a report about a company that asserts more than it can support has no standing unless it applies the same test to itself.

8.1 They Sell What They Promise to Police

Start with the two documents that need no interpretation. Both were live on UltaHost's own website on . There is no intermediary, no leak, and no inference — this is the company describing itself, twice, in incompatible registers.

ultahost.com/dmca-ignored-vps

“Fast and Reliable Offshore DMCA Ignored VPS Hosting. Protect your data privacy and avoid copyright issueswith UltaHost's DMCA Ignored VPS. Enjoy secure, confidential hosting with optimal speed and unlimited bandwidth.”

Page title: “Best Offshore DMCA Ignored VPS Hosting”. Cryptocurrency is among the payment options offered site-wide.

ultahost.com/abuse-handling-policy

“As an ICANN-accredited registrar, UltaHost strictly adheres to Section 3.18 of the Registrar Accreditation Agreement(RAA), which mandates the timely handling of abuse reports…”

“For cases involving confirmed malicious intent (such as phishing attempts, malware distribution, financial scams, or child exploitation content), the domain will be immediately disabled without prior notice.”

The same page promises a reporter a resolution “within 10 days of receipt”.

Being precise about what this is

Selling DMCA-ignored hosting is not illegal, and it is not, strictly, a contradiction of RAA §3.18: a registrar's obligations over domain abuse are a different duty from a hosting provider's response to a copyright notice. A lawyer for the company could correctly point that out. What the two pages establish is the positioning — the avoidance of copyright enforcement is sold as a product feature, in the page title, while ICANN accreditation is cited as evidence of diligence. Everything in the rest of this report is a test of which of those two documents the infrastructure actually resembles.

8.2 What Is Actually Running on Their Network

UltaHost runs its own autonomous system, AS214036, assigned by RIPE in October 2024. That makes its contents measurable by anyone. We read three public datasets filtered to that ASN.

998
malware URLs (URLhaus)
Feb 2022 – Aug 2026
9
botnet C2 servers (ThreatFox)
all at 100% confidence
2,110
phishing scans (urlscan)
total reported as ≥10,000

The C2 list is the finding that matters, and it is different in kind from phishing volume. Of the nine command-and-control servers, five run commercial red-team frameworks: Cobalt Strike, Sliver (twice), Brute Ratel C4 and Havoc. These are post-exploitation tools — what an intruder uses afterbreaching a network — and they are the standard working kit of ransomware crews. The remainder are XWorm (twice), AsyncRAT and Bashlite.

One address, two frameworks

192.142.18.214 appears twice in ThreatFox, carrying two differentcommercial intrusion frameworks ten months apart. Seven of the nine C2 servers were first seen inside the window in which UltaHost was working through ICANN's cure process.

Where this evidence is weaker than it looks

  • The trend is down, not up. URLhaus volume peaked in 2025 (528 URLs) and stands at 79 in 2026. We are not claiming an escalation, and anyone citing the 998 total should know it is cumulative over four and a half years.
  • Most of it is botnet noise. Only 54 of the 998 carry Windows-crimeware tags; the bulk are Mirai/Gafgyt-family IoT scanning, which lands on cheap hosting everywhere.
  • 10,000 is a cap, not a count. urlscan's unfiltered total for the ASN is reported here as at least 10,000 because that is where anonymous results stop.
  • And a negative we went looking for. AS214036 is not on the Spamhaus ASN-DROP list. We checked, and we publish it.
  • No comparison group.We did not measure other hosts' ASNs. Nothing here says UltaHost is worse than its peers on these metrics — only that this is what is on its network while its abuse policy promises immediate suspension.

8.3 The Stronger Signal: Their Own cPanel Plane

Sharing an autonomous system proves little on its own. Any large network has customers it never meets, and “bad thing found on big network” is a weak argument that could be made about almost any host. So we went one layer deeper, to reverse DNS.

A number of scam domains scanned on urlscan resolve to hostnames like cp11.ams1.ultacp.com and cp5.fra1.ultacp.com. That is not merely UltaHost address space — it is UltaHost's own managed cPanel shared-hosting control plane, the product a paying customer is given a login to. Across 78 submissions we found 20 distinct domains, several scanned the same week we looked.

ClusterDomainsOn
Crypto presale, impersonating financial mediaspx40k-fxempire.com · spxpresale-cryptoslate.com · gro24h-cointelegraph.com · gro24h-cryptoslate.com · spx40k.comcp11.ams1
Fake banks (tagged advance-fee fraud / phishing)theroyalbankgroup.com · stridesglobalbk.onlinecp11.ams1
Fake chemical / pharmaceutical supplierslabchems.org · usalabchems.comcp11.ams1
Brand impersonationadobeviewer.com · adobe-docviewer.com · adob-viewer.com · aliexpressboost.comcp11.ams1
Other phishing / fraud tagged by scannersguia-gasescol.com · bright-tether.com · viounavtr.com · startcryptoworld.com · impactboxesau.comcp3.fra1 / cp11.ams1

Why the Adobe cluster is the sharpest of these

This site has already documented UltaHost's reply to a customer who reported abuse: that it does not investigate unless the reporter submits a trademark complaint or a court order. Three Adobe lookalikes and an AliExpress lookalike, on one of its own cPanel servers, are precisely the trademark case that answer invites. The company's own abuse policy, quoted in 8.1, promises that domains involved in “phishing attempts… or financial scams” are “immediately disabled without prior notice”.

Limits.A urlscan tag is a scanner's classification, not a court's. We are reporting what the scan records and the PTR records show — not what UltaHost knew, nor when. Several of these were scanned within days of our reading, so we cannot say how long they had been live, and a fast suspension after our snapshot would not be visible to us.

8.4 The Gambling Contradiction, With Infrastructure Evidence

ultahost.com/terms — prohibited uses

Promote gambling, casinos, gaming, sports betting, daily fantasy sports, lottery or chain letters regardless of content or origin and regardless of your citizenship or the legality of such activities within your country.”

A reverse-IP lookup on 84.200.154.40 returns 290 hostnames. Shared cPanel hosting generates several hostnames per site (www, mail, webmail…), so a hostname count overstates the number of actual sites. Deduplicated to registrable domains, it is 120 distinct domains— and every one of them carries an Indonesian gambling marker.

28
explicit markers
92
slot-brand naming shape
0
residual, non-gambling

The explicit set includes bo999slot.com, maxbet111.com, sbo222slot.net, winbet178.com and the 4D series — uranus4d.net, judo4d.org, dna4d.com— “4D” being the standard Indonesian lottery format. The remaining 92 follow the recognisable slot-brand convention of a short word plus two or three digits: angka169.com, hoki818.com, dewa268.com, gemoy666.com.

The same IP served credential-stealing malware

On , URLhaus recorded AgentTesla being served from lion44.net/wp-includes/theme-compat/… — a compromised WordPress installation on one of the gambling sites on that address. This is the shape of the wider risk: an unmaintained estate of grey-market sites on shared hosting becomes a malware platform whether or not anyone intended it.

Gambling domains also sit directly on the managed cPanel plane described in 8.3: 1xbet-ir.app and 1xbet-iran.app (1xBet, targeted at Iran), zigzagbonus.bet, pinupcasinorussia.click, 1035holiganbet.com, and three ganobet variants.

Our own method, including a mistake we made

Co-tenancy shows what shares an address, not who owns the content, and we make no claim that UltaHost knows about any specific domain. The claim is narrower and, we think, harder to wave away: content its own terms prohibit is running on its own shared hosting, at scale, on an address where every single site fits that description.

Our first classification pass undercounted. It required a word boundary before “slot”, which silently missed bo999slot and capital365slot; it had no rule for the 4D lottery convention at all; and it ignored .org. We found this by reading the domains the classifier had rejectedand noticing they were gambling sites too. The corrected classifier prints its residual so the “all 120” claim can be checked rather than trusted, and the reverse-IP service caps at 500 hostnames — so where we report 500 elsewhere, that is a floor and not a total.

8.5 The Registrar Record, From ICANN's Own Files

This site has reported the ICANN breach since Round 1. Reading ICANN's compliance index directly gives the full sequence for the first time, and it is longer than we had published.

The breach chain, as ICANN records it

  • 5 February 2025 — Notice of Breach issued
  • ○ 7 March 2025 — cure period extended
  • ○ 17 April 2025 — extended again
  • ○ 29 April 2025 — extended again
  • ○ 9 June 2025 — extended again
  • ○ 20 March 2026 — extended a fifth time
  • 23 March 2026 — “Breaches Cured”

Against a 21-day cure period, that is 411 days — about 13.5 months — with 5 separate extensions granted along the way.

Two honest readings of that follow, and we will give both. Granting extensions is within ICANN's discretion and is not misconduct by either party; the chain is evidence about ICANN's enforcement posture as much as about UltaHost. And “cured” is narrower than it sounds — it means the contractual points in the notice were satisfied: RDAP conformance, data escrow, abuse-report records. It is a finding about process, not a finding that abuse stopped, and ICANN does not claim otherwise.

The registrar's own monthly numbers

ICANN publishes a transaction report for every accredited registrar, every month. Filtering 19 months of the .com files to IANA ID 4331 produces two series worth putting side by side.

Month.com under managementDeleted, no grace period
Oct 202400
Apr 20259,4370
Oct 202521,03833
Dec 202522,9530
Jan 202623,669332
Feb 202623,8691,399
Mar 202624,3781,283
Apr 202625,1791,032

The second column is the interesting one. A normal expiry passes through a redemption grace period. A no-grace deletion skips it, which is characteristic of a registrar-initiatedremoval — the mechanism a registrar uses when it takes a domain down itself. Across the registrar's first fifteen reported months that figure never once exceeded 236, and was zero in eleven of them. From January 2026 it runs 332, 1,399, 1,283, 1,032— four consecutive months totalling more than 4,000 domains.

What we are not claiming

The deletions begin in the same window as the closing stretch of the cure process. We are placing two dated series next to each other and stopping there. ICANN's files give no reason for any deletion, and bulk removals are equally consistent with clearing a spam-registration wave, a payment-fraud chargeback batch, or an ordinary policy change. We do not assert causation, and no reader should infer it from the dates alone.

8.6 The UK Company Is Dormant

UltaHost's own terms of service extend the agreement across “UltaHost Dubai, UltaHost Istanbul, UltaHost Ltd UK, and UltaHost Inc USA”. One of those four is on a register we can read in full, and what it says is that it does almost nothing.

A dormant company, in UK law, is one that has had no significant accounting transactions in the financial year. ULTAHOST LTD (Companies House 14567126) has filed dormant accounts three years running: for the periods ended 31 January 2024, 31 January 2025 and 31 January 2026, the last of them filed on 7 April 2026.

The rest of the filing

  • Sole director and company secretary — the same individual, held as two separate officer records
  • 75–100% of shares, of voting rights, and of the right to appoint and remove directors
  • ● Turkish nationality, resident in Turkey; date of birth recorded as January 1992
  • ● Identity verified under the Economic Crime and Corporate Transparency Act on 21 November 2025
  • 0 other UK appointments for either officer record
  • ● No insolvency history, no registered charges, filings up to date — a compliant dormant company, not a delinquent one

An inference we refuse to draw

The registered office is 71-75 Shelton Street, Covent Garden — the best-known mass mail-forwarding address in the United Kingdom, shared by tens of thousands of entirely unrelated companies. “N companies registered at the same address as UltaHost” is therefore worthless as evidence, and we will not make that argument even though it would be the easiest paragraph in this report to write.

The only structurally valid test is officer-sharing: whether this director appears on the filings of other companies. We ran it, and it returns nothing. There is likewise no UK-registered ScriptSun, WoWonder, Wolvor or Doughouz company — we previously described two of those as “Ltd” entities on this site and have retracted it. If a wider corporate group exists, it is not visible on the UK register, and we are not going to imply one from a shared mailbox.

8.7 Two Platforms Sanctioned Their Reputation Management

Round 7 measured how the headline rating is assembled. The point worth restating in a report about the business model is simpler: this is not our characterisation. Two independent review platforms have each taken action and said so on the profile.

Trustpilot, January 2025

“This company's rating is unavailable due to a breach of our guidelines… We've removed a number of fake reviews for this company.

Sitejabber

“Ultahost has been reported to offer discounts, coupons, or other compensation in exchange for reviews.”

Set beside UltaHost's own published affiliate terms — commission per sale well above the industry norm, payable in cryptocurrency, already documented on this site — the compensation warning stops being an accusation and becomes a description of a disclosed incentive structure.

8.8 Responsive Where It Is Scored, Silent Where It Is Not

This is the pattern that ties the report together, and it is visible in three places at once.

ChannelPublicly scored?Observed responsiveness
Trustpilot reviewsYes — reply rate is displayedEvery one of 200 sampled reviews carried a company reply
BBB complaintsYes — but only in the letter gradeAt least one complaint unanswered; the grade is D+
Abuse reportsNoTrademark complaint or court order said to be required

A disclosure that cuts against us

The BBB letter grade measures complaint handling, not customer sentiment — and the same BBB profile also carries customer reviews that average well above what the grade implies. Leaving that out would be cherry-picking, so we state it. Our reading is not that the positive reviews are fake; it is that visible responsiveness is itself the thing under scrutiny in section 8.7, and a channel that scores you publicly gets a different level of attention from one that does not.

8.9 Litigation: Nothing in the Free Record

We searched for court cases and found none, and we are giving that the same prominence we would have given a hit. Sixteen queries against CourtListener v4 — “Ultahost”, “Ultahost, Inc”, “ScriptSun”, “WoWonder”, “Doughous” — across opinions, dockets and full document text returned zero. The UK's Find Case Law archive returned zero. Companies House shows no insolvency and no strike-off action.

We had this wrong, and we have corrected it

Until this week, this site's homepage stated that UltaHost was “stonewalling actual lawsuits filed against the company”. No citation existed for it anywhere on the site, and the search above finds no such lawsuits. That claim is retracted. What survives is narrower and properly sourced: a customer who won a card chargeback was threatened with legal action, reported on WebHostingTalk in December 2024.

Why this is “nothing found”, not “nothing exists”

  • RECAP is a large sample, not a census. It holds only those US federal dockets somebody has already paid to retrieve.
  • BAILII was not checked. It blocks automated retrieval and we did not work around it.
  • Turkey and the UAE — where the principals are based — publish no free, name-searchable judgment database.
  • ● A dispute settled privately, or filed in a US state court, leaves no trace in any of the above.

A same-surname warning, published so nobody else misuses it

Searching the surname in US dockets returns five bankruptcy filings. We attribute none of them to anyone. Two were filed in 1996 and 2002 — when a person born in January 1992 was four and ten years old, which rules them out arithmetically. A third, filed in 2025, shares a surname and nothing else we can establish. We mention them only because they are the first thing a careless search surfaces, and we would rather rule them out here than see them repeated as findings about this company.

8.10 The People Behind It

This section is now built on the statutory record rather than on data brokers, and it is shorter than it used to be as a result.

Elin Doughouz — what a register actually says

  • ● Sole director and sole company secretary of ULTAHOST LTD, appointed 3 January 2023 — two officer records for one person
  • ● Person with significant control: 75–100% of shares, votes, and the right to appoint and remove directors
  • ● Turkish nationality, resident in Turkey, date of birth January 1992
  • ● Identity verified under ECCTA on 21 November 2025
  • ● Appears in ICANN's breach correspondence as “Doughous” — a spelling split that matters, because searching only one form returns a false negative

Deen Doughouz is named as CTO and co-founder on LinkedIn and Younes Doughouzas a third co-founder on Crunchbase. Both rest on a single source each, and we label them that way rather than presenting them as established. Neither holds any appointment at ULTAHOST LTD on the UK register. The frequently repeated “three brothers” framing is not something we can source to a record, so we say “co-founders per Crunchbase” instead.

Two things we removed, and why

This site previously published a birthplace and an ethnicityfor the CEO. Neither carried a citation, and neither bears on a single claim in any of these eight rounds — so both are gone. We also previously gave a date of birth of “January 1, 1992”; the 1st of January is a well-known filler value in commercial people-data records, and the statutory register gives month precision only. It now reads January 1992. We do not publish the director's residential address, which is a matter of public record but is a different act from reporting a directorship. Accountability journalism about a company is not a licence to publish everything discoverable about the people who run it.

8.11 Unverified Leads, Labelled as Such

These are the most quotable items we found and the least proven. They are published as open questions, and nobody should cite them as findings — including us, in a later round, without doing the work first.

Unverified

A company-run subreddit

r/UltaHostHub appears to be operated by the company — nearly every post is from a staff account. The single apparent exception is a long, metrics-heavy testimonial. That is an astroturf candidate and nothing more: a detailed positive review from a real enthusiastic customer looks identical from the outside.

Unverified

A thread with missing comments

A price-increase discussion shows a comment count far above the number of comments actually rendered, with no [removed]placeholders. That is consistent with mass removal — and equally consistent with our own requests being rate-limited while we read it. It needs a logged-in check before it means anything, and we have not done one.

Ruled out

A false positive we are pre-empting

A widely-linked forum thread about an “ultahost[.]gl virus” concerns a CountLoader infection on a different domain with a different TLD, unconnected to this hosting company. It is not evidence about UltaHost, and we are saying so here because it is exactly the sort of thing that gets used to discredit an entire report.

8.12 Verify It Yourself — And Our Method

Every figure in this round comes from a record you can open without an account, with one exception noted below. Every one of these is free; only Companies House needs an account, and its key costs nothing.

SourceWhat we took from itWhere
ICANN compliance noticesBreach notice, five cure extensions, cure dateicann.org/compliance/notices
ICANN monthly registrar reports.com under management + no-grace deletions, IANA ID 4331icann.org/sites/default/files/mrr/com/
IANA registrar IDsAccreditation status for ID 4331iana.org/assignments/registrar-ids/
UK Companies HouseDormant filings, officers, PSC, other appointmentscompanies house — company 14567126
RIPE RDAPAS214036 registration, maintainer, abuse contactrdap.db.ripe.net/autnum/214036
RIPEstatAS214036 announced prefixes and neighboursstat.ripe.net — announced-prefixes
abuse.ch URLhausMalware URLs on the ASN, with dates and tagsurlhaus.abuse.ch/feeds/asn/214036/
abuse.ch ThreatFoxBotnet C2 servers on the ASNthreatfox.abuse.ch/browse/tag/AS214036/
urlscan.ioPhishing scans + reverse DNS of scanned pagesurlscan.io — page.asn:AS214036
HackerTarget reverse IPCo-tenant hostnames on 84.200.154.40api.hackertarget.com/reverseiplookup/
CourtListener v4US litigation record (0 results)courtlistener.com — “Ultahost”
Find Case Law (UK)UK judgment record (0 results)caselaw.nationalarchives.gov.uk
UltaHost — DMCA Ignored VPSThe offshore product page quoted in 8.1ultahost.com/dmca-ignored-vps
UltaHost — Abuse Handling PolicyThe RAA §3.18 and suspension quotes in 8.1ultahost.com/abuse-handling-policy
UltaHost — Terms of ServiceThe gambling prohibition quoted in 8.4ultahost.com/terms

Method, including its limits

  • Retrieval. Everything above was read directly over HTTP on , with no commercial scraping service involved. Companies House needs a free API key; the other ten need nothing. The scripts that did the reading are in the site's repository, and the figures on this page are printed by one of them rather than typed by hand.
  • Sample limits. The ICANN monthly reports cover 19 months to April 2026 — the latest published when we read them — so the .com and deletion figures are four months old by construction. The reverse-IP service caps at 500 hostnames, and urlscan's anonymous search caps at 10,000 results; where a figure sits at a cap we report it as a floor.
  • What we could not reach. Delaware's entity register is CAPTCHA-walled and publishes no officers. BAILII blocks automated reads. Turkey and the UAE publish no free searchable judgment database. AbuseIPDB's per-prefix check across all 86 prefixes was not completed. We report these as gaps rather than filling them with inference.
  • No comparison group.We measured no other hosting company's ASN, register or abuse record. Nothing here is a claim that UltaHost is worse than its competitors on any of these metrics. Every finding is an absolute comparison against UltaHost's own published terms, policies and marketing.
  • Search is circular here, so we avoided it. This site now ranks highly for most queries about UltaHost, and we have found third-party pages quoting our own figures back at us. Nothing in this round is corroborated from a search snippet; every number traces to a named primary record.
  • Archiving.We submitted the URLs cited here to the Internet Archive so the claims stay checkable if the originals change. Expect UltaHost's own product and policy pages to be the ones most likely to move; we retain dated local copies of all four pages we quote, and the verbatim quotes in 8.1 and 8.4 were checked as exact substrings of those stored copies before publication.

8.13 Editor's Conclusion

Seven rounds asked whether UltaHost treats its customers badly. Round 8 asks a different question — what the business actually is — and the registries answer it.

A company that sells the avoidance of copyright enforcement as a named product, and cites its ICANN accreditation on another page as proof that it polices abuse. An autonomous system carrying nine command-and-control servers, five of them the commercial intrusion frameworks ransomware crews use. Twenty scam domains on its own managed cPanel servers, including three Adobe lookalikes — the trademark complaint its own support reply says it requires before it will investigate. An IP address where all 120 sites are gambling operations, against terms that prohibit promoting gambling “regardless of the legality of such activities within your country”, one of them compromised and serving credential-stealing malware. Thirteen and a half months in breach of its registrar agreement across five extensions. And a UK arm presented to customers as one of four operating jurisdictions that has told Companies House, three years in a row, that it did essentially nothing.

Now the limits, because they are real and this report is worth less without them. The malware trend on the network is down, not up. Most of the URL volume is undifferentiated botnet noise. Co-tenancy shows what shares an address, never who owns it, and we cannot show what UltaHost knew about any specific domain or when. The deletion spike sits beside the cure window but we assert no causal link between them. The company is not on Spamhaus's drop list. There is no litigation against it in any record we can freely search. Its UK filings are late for nothing and compliant throughout. And the single most damaging structural allegation available to us — a web of shell companies — is one we could not substantiate and are therefore not making: the officer-sharing test returns nothing, and a shared mail-forwarding address is not evidence of anything at all.

What is left after all of that subtraction is still the finding. Nothing here requires a leak, an insider, or a theory of intent. It is a company's own product pages, its own terms of service, its own registrar filings and its own routing data, read in order — and read in order, they describe a business whose stated policies and actual infrastructure are two different things.