NICENIC Zone Scan

July 25, 2026 · View on GitHub


Registrar TLP

License Pages


# NICENIC Zone Scan — Complete Registrar Investigation

Phase I · NICENIC INTERNATIONAL GROUP CO., LIMITED · IANA #3765

Complete-zone scan of a Chinese registrar enabling industrial-scale domain abuse


🔴 LIVE INVESTIGATION FEED · Auto-updated · Last fetch 2026-07-25

📦 Domains tracked
370,266
💰 Est. revenue
\$2,815,384
📡 Deployed
52.0%
✅ Confirmed phishing
6.9% (25,620)
⚡ Fresh (≤7d)
1.0%
🕵️ Serial regs
30

🏷️ Top TLD Zones

TLDCountAvg Reg PeriodEst. Revenue
.com199,226566d$1,791,042
.vip28,536371d$142,395
.icu23,810388d$23,572
.net16,832680d$168,152
.xyz16,057471d$23,925
.live11,804406d$117,922
.info11,758504d$46,914
.cfd9,857468d$49,186
.org8,126851d$81,179
.sbs7,502431d$37,435

🌍 Top Hosting Countries

US  ██████████████████     12,294 (34.9%)
RU  ████░░░░░░░░░░░░░░      2,837 (8.1%)
CA  ████░░░░░░░░░░░░░░      2,760 (7.8%)
NL  ███░░░░░░░░░░░░░░░      2,517 (7.2%)
GB  ███░░░░░░░░░░░░░░░      2,077 (5.9%)
DE  ██░░░░░░░░░░░░░░░░      2,008 (5.7%)
BG  ██░░░░░░░░░░░░░░░░      1,673 (4.8%)
SE  █░░░░░░░░░░░░░░░░░        804 (2.3%)

📈 Registration Burst Days

DateDomains× Average
2026-06-161,38214.3× 🚨
2026-06-081,25212.9× 🚨
2026-03-061,24512.8× 🚨
2025-12-041,21512.5× 🚨
2026-03-051,20712.4× 🚨

🎯 Top Targeted Brands & Keywords

coinbase (3,845) · claim (3,461) · login (2,252) · secure (1,720) · token (1,595) · wallet (1,527) · official (1,420) · swap (1,357) · ledger (1,338) · support (1,266) · kraken (1,235) · update (1,166) · crypto (1,155) · connect (1,105) · trust (940)

🕵️ Top Serial Registrants — 50 emails with ≥5 domains

#Registrant Email (redacted)Domains
1inf***@credicentrocoop.com97
2inf***@africaoil.com78
3inf***@vuz.info65
4m***@unternehmen.de38
5sup***@easybit.com35
6ang***@gmail.com30
7pre***@ethereum.org27
8sub***@shib.io25
9u00***@shib.io25
10a***@shib.io25

📥 Download Threat Intelligence

FileFormatDescription
data/all.txtTXTAll tracked domains
data/index.jsonJSONFull analytics snapshot
data/ioc/serial_registrants.jsonJSONRepeat registrants + their domains
data/ioc/shared_ips.jsonJSONBulletproof hosting clusters
data/ioc/brand_domains.jsonJSONDomains by targeted brand
data/ioc/stix-bundle.jsonSTIX 2.1MISP/OpenCTI ready bundle
data/ioc/serial_emails.txtTXTgrep-friendly: email⇥count
data/ioc/shared_ips.txtTXTgrep-friendly: ip⇥count⇥country

📊 Live web dashboard: see Pages link at top · Updated daily 02:00 UTC


📑 Table of Contents

Investigation

Evidence

Legal / Reuse

Background

NICENIC INTERNATIONAL GROUP CO., LIMITED (IANA registrar #3765) is a Chinese domain registrar with a long-documented track record of slow abuse response, permissive registration policies, and infrastructure that is systematically exploited by phishing operators, carding shops, crypto drainers, illegal gambling networks, and malware distributors.

While NICENIC holds significantly more domains than the average registrar under investigation, the scale is itself the signal: fast, cheap, anonymous registration at volume is the product. The registrar's zone composition reflects a portfolio optimised for abuse enablement rather than legitimate hosting.

This investigation enumerates every domain in NICENIC's zone, classifies content using AI-assisted analysis and threat-intelligence cross-referencing, and publishes structured evidence for enforcement, blocklist, and SIEM use.

Pipeline:

[NICENIC Zone File — 343,107 domains]


┌─────────────────┐   aiohttp, 600 concurrent, Googlebot UA
│ Phase 1 — HTTP  │   Output: lambda_results.jsonl
│ Fingerprint     │
└─────────────────┘


┌─────────────────┐   Playwright + stealth v2, isolated context/domain
│ Phase 2 — Render│   SOCKS5 pool + 2captcha (hCaptcha/Turnstile/reCAPTCHA)
│ + Screenshots   │   Output: deep_results.jsonl, screenshots/*.jpg
└─────────────────┘


┌─────────────────┐   Llama 3.1 (Groq) for content classification
│ Phase 3 — AI    │   Rule-based pre-filter + Groq for ambiguous cases
│ Classification  │   Output: enriched.csv categories + descriptions
└─────────────────┘


┌─────────────────┐   ipinfo.io (country + ASN per IP)
│ Phase 4 — GeoIP │   Output: ip_country, ip_asn fields
└─────────────────┘


┌─────────────────┐   Redaction: scan-server IP, API keys, local paths
│ Phase 5 — PII   │   Output: clean enriched.csv, data.json, IOC feeds
│ Redaction       │
└─────────────────┘

Subject

FieldValue
Registrar nameNICENIC INTERNATIONAL GROUP CO., LIMITED
IANA ID#3765
JurisdictionChina
WHOIS serverwhois.nicenic.net
Abuse contactabuse@nicenic.net
Zone size343,107 domains (scan date: June 2026)
Supported TLDsGeneric TLDs (gTLD) — .com, .net, .org, .xyz, .top, .shop, .app, .academy, and 100+ more
ICANN accreditationActive

Scope

This investigation covers the complete zone of all domains registered under NICENIC (IANA #3765) as enumerated from public zone data in June 2026. Every domain — alive or dead — is included.

Note: Screenshots and deep-render data were collected only for HIGH and MEDIUM severity domains (estimated 10–25% of zone) to constrain storage and runtime. Dead domains are enumerated and classified but not rendered.

Methodology

Phase 1 — HTTP Fingerprinting
  • Tool: Python 3.14 + aiohttp, 600 concurrent connections
  • User-Agent: Googlebot 2.1 (bypass naive bot-blocks)
  • Timeout: 5s connect, 8s read
  • Extracted: HTTP status, final URL, server headers, title, H1, meta description, form fields, body snippet (first 64 KB)
  • Cloudflare detection: cf-ray / __cf_bm presence in headers + body
  • Captcha detection: hCaptcha / reCAPTCHA / Turnstile keyword matching
  • Output: data/lambda_results.jsonl — one JSON object per domain
Phase 2 — Browser Render & Screenshots
  • Engine: Playwright 1.40 + headless Chromium
  • Stealth: playwright-stealth v2
  • Viewport: 1280 × 800
  • Settle delay: 2.5 s post-domcontentloaded; +5 s on Cloudflare JS challenge
  • Captcha solving: 2captcha — hCaptcha, reCAPTCHA v2/v3, Cloudflare Turnstile
  • Proxy pool: 2,600+ SOCKS5 exits, round-robin per domain
  • Output: docs/screenshots/<domain>.jpg (JPEG 80%, max 1280 px wide)
Phase 3 — AI Classification
  • Model: Llama 3.1 8B Instant (Groq API)
  • Batch size: 20 domains per Groq call
  • Categories: PHISHING_FINANCE, PHISHING_BRAND, CARDING, CRYPTO_DRAINER, CRYPTO_EXCHANGE, GAMBLING, ADULT, MALWARE, SPAM_PHARMA, SPAM_SEO, PARKING, DEAD, LEGITIMATE, UNKNOWN
  • Severity map: CRITICAL (4) — phishing/carding/malware; HIGH (3) — crypto/gambling; MEDIUM (2) — adult/spam-seo; LOW (1) — unknown; INFO (0) — parking/dead/legitimate
  • Pre-filter: Rule-based keyword matching assigns naive category before Groq; Groq refines uncertain cases
Phase 4 — GeoIP Enrichment
  • Provider: ipinfo.io API
  • Fields added: ip_country, ip_asn
  • Coverage: All live domains with resolved IPs

Headline Findings

MetricValue
Total domains in zone343,107
Alive (HTTP 200/3xx)37,844 (11%)
Dead / Parked / Error305,263 (89%)
CRITICAL severity10,377
HIGH severity7,928
MEDIUM severity622
Malicious (CRITICAL+HIGH+MEDIUM)18,927 (50.0% of alive)
Behind Cloudflare63,190 (83% of alive)
Screenshots captured37,844 alive domains — not published in repo (size)
Operator clusters identified2,939

Operator Clusters

2,939 operator clusters identified via favicon MurmurHash3 + server fingerprint combination. Clusters of 3+ domains sharing identical infrastructure are surfaced as likely operator groups.

Notable clusters:

ClusterDomainsDescription
Favicon 19217251831,043Single phishing operator — uniform credential-harvesting kit
IP 188.114.96.313,293Cloudflare anycast — bulk domain parking on shared exit
Carding infra544 CC shops83% behind Cloudflare DDoS protection

Full cluster data: data/clusters.json — includes favicon hash, server fingerprint, domain list, and category distribution per cluster.

Evidence Archive

FileRowsDescription
data/enriched.csv86,114Full enriched dataset — all classified domains with category, severity, IPs, country, AI descriptions
data/high_severity.csv20,480CRITICAL+HIGH filtered subset
data/dead_domains.csvDead / parked / error domain enumeration
data/clusters.json2,939Operator cluster map — favicon hash + server fingerprint groupings
ioc/domains_high.txt18,305Production blocklist — CRITICAL+HIGH domains
ioc/domains_all_malicious.txt18,927Production blocklist — CRITICAL+HIGH+MEDIUM
ioc/indicators.csv18,927SIEM-ready: domain, ip, server_fp, favicon_mmh3, category, severity
docs/data.jsonSlim per-domain dataset for the live report
pkg/raw_data/lambda_results.jsonl.gzPhase 1 raw HTTP fingerprint output (compressed)
pkg/raw_data/enriched.csv.gzCompressed enriched dataset
pkg/raw_data/high_severity.csv.gzCompressed CRITICAL+HIGH subset
SHA256SUMS.txtSHA-256 checksums of all published data files

IOC Feed

# HIGH severity domains (blocklist)
https://raw.githubusercontent.com/phishdestroy/nicenic-evidence/main/ioc/domains_high.txt

# HIGH + MEDIUM domains
https://raw.githubusercontent.com/phishdestroy/nicenic-evidence/main/ioc/domains_all_malicious.txt

# SIEM indicators (CSV)
https://raw.githubusercontent.com/phishdestroy/nicenic-evidence/main/ioc/indicators.csv

Enforcement Posture

NICENIC operates under Chinese jurisdiction. Effective enforcement requires multi-channel pressure:

ChannelAction
ICANN Contractual ComplianceRegistrar Compliance report — failure to respond to abuse reports per §3.18 RAA
FBI IC3ic3.gov — US-victim phishing and fraud
Europol EC3Cross-border cybercrime referral
CISA / NCSCNational-level threat-intel sharing
Spamhaus DBLBulk submission of HIGH domains
URLhaus / ThreatFoxAutomated daily IOC feed
Downstream hostersCloudflare, Fastly, AWS — abuse reports to hosting providers (not just registrar)
Brand ownersMicrosoft, PayPal, Amazon, Metamask — direct UDRP and legal action

ICANN's Registrar Accreditation Agreement §3.18 requires registrars to maintain and respond to abuse contacts within 24 hours. Documented non-response is grounds for accreditation suspension.

All data in this repository was collected exclusively from publicly accessible sources:

SourceMethod
Zone fileICANN CZDS — accredited access, permissible use
WHOISPublic WHOIS protocol (RFC 3912)
HTTP responsesPassive crawl of publicly reachable URLs
DNS recordsPassive DNS / authoritative queries
ScreenshotsRendered pages accessible to any browser

No non-public systems were accessed. No credentials were tested. No authentication was bypassed. No victim data was processed.

This publication is conducted under:

Regarding Reputational Impact

This research documents objectively verifiable facts: domain registration patterns, HTTP response content, and registrar abuse-response latency. These facts were publicly visible before this repository existed.

NICENIC INTERNATIONAL GROUP CO., LIMITED is an ICANN-accredited registrar operating under contractual obligations to the global internet community. Registrars that facilitate industrial-scale phishing infrastructure have no legitimate reputational interest in suppressing evidence of that facilitation. Publication of factual evidence of contractual non-compliance is not defamation — it is the function ICANN's transparency requirements were built to serve.

If NICENIC disputes any finding: submit documented evidence via phishdestroy.io. Findings supported by evidence will be corrected in a timestamped update.

Repository Structure

nicenic-evidence/
├── scan/
│   ├── phase1_http.py          # aiohttp mass scanner
│   ├── phase2_screenshots.py   # Playwright browser scan
│   ├── classify.py             # Groq AI classification
│   ├── fast_classify.py        # Rule-based pre-filter pass
│   ├── geoip_enrich.py         # ipinfo.io enrichment
│   ├── build_clusters.py       # Favicon+fingerprint cluster analysis
│   ├── build_ioc.py            # IOC feed generation
│   ├── build_domains_html.py   # Regenerate domains.html
│   ├── threat_intel.py         # TI cross-reference
│   ├── redact_creds.py         # PII/credential redaction
│   ├── finalize.py             # Final pipeline step
│   ├── compress_screenshots.py # PNG→JPEG compression
│   ├── merge_zone.py           # Zone data merge
│   ├── lambda_handler.py       # AWS Lambda variant
│   └── invoke_all.py           # Lambda orchestrator
├── docs/
│   ├── index.html              # Investigation landing page (GitHub Pages)
│   ├── domains.html            # Searchable domain table (76,117 domains)
│   ├── data.json               # Slim per-domain dataset
│   ├── build_datajson.py       # Regenerate data.json from enriched.csv
│   └── assets/                 # Hero image, OG card, favicons
├── data/
│   ├── enriched.csv            # Canonical enriched dataset (86,114 rows)
│   ├── high_severity.csv       # CRITICAL+HIGH subset (20,480 rows)
│   ├── dead_domains.csv        # Dead / parked enumeration
│   └── clusters.json           # Operator cluster map (2,939 clusters)
├── ioc/
│   ├── domains_high.txt        # CRITICAL+HIGH blocklist (18,305 domains)
│   ├── domains_all_malicious.txt # CRITICAL+HIGH+MEDIUM (18,927 domains)
│   └── indicators.csv          # SIEM-ready IOC feed (18,927 indicators)
├── pkg/
│   └── raw_data/               # Compressed raw scan output (.gz)
├── SHA256SUMS.txt              # Checksums of all published data files
├── PROVENANCE.md               # Chain-of-custody documentation
└── README.md                   # This file

🕸️ Network of Complicit Registrars

This investigation is part of a series documenting ICANN-accredited registrars that systematically obstruct anti-phishing enforcement or directly profit from fraud infrastructure. All three registrars share a documented pattern: direct requests backed by evidence are ignored, delayed, or met with active suppression.

#RegistrarIANAZoneConfirmed MaliciousRussian ConnectionInvestigation
1NICENIC INTERNATIONAL GROUP (this)#3765349,37618,927 (50% of alive)🇷🇺 #2 hosting country (8.5%)nicenic-evidence · Live Report
2Trustname.com / Fewmoretaps ÖÜ#43189,3431,114 HIGH (86% alive)🇷🇺 Russian-operated, Estonian shelltrustname-evidence · Live Report
3NameSilo, LLC#14795,251,494183,419🇷🇺 Russian team members, suppression campaignnamesilo-evidence · Live Report

🇷🇺 Russian Connection & Complicity Record

Russian Presence — CEO OSINT

Helen Ho, the CEO of NiceNIC, is directly associated with the email support@nicenic.net, which appears registered across multiple Russian-language platforms. She maintains an active VKontakte (VK) account under the handle:

nicenic_globalvk.com

VK is a Russian social network with no meaningful presence in China. For a CEO of a Chinese registrar to maintain an active VK account — and to be highly active on it — is strategically significant. Analysis of her follower network on VK reveals entities engaged in scam activity while using NiceNIC domain services.

Helen Ho's VK account is subscribed to the community «Типичный мошенник» ("Typical Scammer") — a Russian-language VK page dedicated to scam tutorials, fraud toolkits, and cybercriminal community content.

The CEO of an ICANN-accredited registrar, subscribed to a scammer community on a Russian social network, with followers who are active fraud operators using her registrar's services — is not an ambiguous data point. It is a documented conflict of interest at the executive level.

Additional key facts:

  • Russia is the #2 hosting country in NICENIC's zone: 3,113 deployed domains (8.5%)
  • NiceNIC is the preferred registrar of Russian-speaking fraud affiliate networks — documented in leaked Telegram screenshots where network instructors explicitly recommend NiceNIC to affiliates
  • The "Soulless" scam network registered 1,200+ identical phishing sites via NiceNIC
  • NICENIC accepts Bitcoin, Tether, Ethereum, Litecoin — specifically to sever financial audit trails and enable anonymous registration

“We Are Not Against Scamming”

On January 10, 2026, a post appeared from a NiceNIC-attributed account stating:

“We are not against scamming… we here to make cash.”

NiceNIC subsequently claimed the account was “hacked” by a user named “Juliani” to maintain ICANN deniability. The statement is consistent with the operational record regardless of its attribution.

Documented Obstruction

  • RAA §3.18 requires 24-hour acknowledgement of abuse reports. NICENIC’s effective response is measured in weeks or is absent entirely.
  • NICENIC’s abuse system forwards complaints directly to the registrants (the criminals) rather than investigating independently — and accepts registrant denials at face value to close tickets.
  • Auto-responder templates claim “insufficient evidence” even when full forensic packages are submitted: screenshots, AI classification, WHOIS, live HTTP proof, financial transaction hashes.
  • Trust Wallet heist (December 2025): $8.5M stolen — infrastructure hosted on NiceNIC. Domains remained live post-report.
  • Scattered Spider lookalike domains for ransomware supply-chain attacks registered via NiceNIC.
  • NICENIC’s phishing domain score: 1,141.74326× higher than the industry average of ~3.5.
  • No public abuse transparency report published by NICENIC for any reporting period.
  • ICANN Contractual Compliance complaint filed. NiceNIC’s continued accreditation depends on a process measured in months during which thousands of fraud domains remain live.
  • Direct requests with documented evidence: systematically ignored.

External Coverage

PublicationTitle
📰 PhishDestroy / Medium“NiceNIC Exposed: The ICANN-Accredited Registrar Powering the World’s Cybercriminal Ecosystem”
📰 DecodeCybercrime“NiceNIC: The Leading Bulletproof Domain Registrar Enabling Global Cybercrime”
📰 PhishDestroy.ionicenic-real — Full investigation

“NICENIC’s abuse response SLA is effectively infinite. This investigation makes it finite.”

InvestigationRegistrarZone SizeAliveMaliciousReport
Trustname / Fewmoretaps OÜIANA #43187,6411,114 HIGHphishdestroy.github.io/trustname-evidence
NameSiloIANA #14795,269,357658,733 (12.7%)183,419phishdestroy.github.io/namesilo-evidence
NICENIC INTERNATIONAL GROUP (this repo)IANA #3765343,10737,844 (11%)18,927 (50% of alive)phishdestroy.github.io/nicenic-evidence

PhishDestroy

Automated detection, classification, and public disclosure of domain abuse infrastructure.

phishdestroy.io · GitHub · LEGAL.md · TLP:CLEAR

"NICENIC's abuse response SLA is effectively infinite — we've made it finite."

MIT License · TLP:CLEAR · June 2026