This was never intended to be multipart, but I figured after part 1, I may as well do the other IPs they're using. As it happens, one of the other IP ranges they've got is through AS56927.
The /24 in question, similar to the previous one, is 220.127.116.11/24. What's curious here, is that AS records show something interesting - an invisible link (AS52366 that AS records says doesn't exist. If we follow this, we see the /24 is leased to AS44872 TOPONLINE-AS JSC TOPONLINE, but again, the upstream is shown as "--No Registry Entry--", so who are they?. Perhaps we can do a simple tracert to find out? Lets pick a random IP on the /24 and see shall we?
Well this shows the immediate upstream, is dorinehosting.ro, but they're shown as GOLDENIDEAS upstream, with a completely different ASN (AS44088 DORINEX-AS SC Dorinex Pord SRL).
Is it possible that dorinehosting.ro are the missing ASN after all? They've certainly had their share of Zbot, fake casino software, fake meds etc recently. At this point it's unclear, but I suspect, given there appears to be a relation to NETSERV, the answer lies with dorinehosting.ro and Dorinex. If you can shed light on AS52366, please do get in touch.
In the meantime, the following are some of the fake meds etc sites I've found on this /24, alot of which thanks to Domi at cz.cc, have been suspended (I'm working on identifying the rest of them). You'll no doubt notice quite a few have moved to another Romanian ASN (18.104.22.168/24, AS29568 LogicNet Telecom SRL / COMTEL-AS), itself a fan of fake meds and other badness it seems.
Rest assured, I'll be coming back to this in the future.
Criminals: AS56860 ELETTROGRAF SC ELETTROGRAF SRL