Trustname.com / Fewmoretaps Oรœ

June 24, 2026 ยท View on GitHub


Trustname.com / Fewmoretaps Oรœ

Registrar Zone Evidence โ€” Phase II


IANA #4318 TLP CLEAR MIT


Live Report Phase I Article



๐Ÿ”ด LIVE INVESTIGATION FEED ยท Auto-updated ยท Last fetch 2026-06-24

๐Ÿ“ฆ Domains tracked
9,536
๐Ÿ’ฐ Est. revenue
\$80,029
๐Ÿ“ก Deployed
66.4%
โœ… Confirmed phishing
35.9% (3,428)
โšก Fresh (โ‰ค7d)
6.7%
๐Ÿ•ต๏ธ Serial regs
3

๐Ÿท๏ธ Top TLD Zones

TLDCountAvg Reg PeriodEst. Revenue
.com7,508418d$67,497
.icu620365d$614
.net438434d$4,376
.org369510d$3,686
.app81365d$1,134
.cam78365d$389
.pro54425d$431
.cyou50365d$50
.xyz35396d$52
.info34483d$136

๐ŸŒ Top Hosting Countries

US  โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–ˆ        506 (32.6%)
RU  โ–ˆโ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘        152 (9.8%)
GB  โ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘        131 (8.4%)
DE  โ–ˆโ–ˆโ–ˆโ–ˆโ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘        118 (7.6%)
NL  โ–ˆโ–ˆโ–ˆโ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘         97 (6.2%)
CA  โ–ˆโ–ˆโ–ˆโ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘         87 (5.6%)
BZ  โ–ˆโ–ˆโ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘         72 (4.6%)
UA  โ–ˆโ–ˆโ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘โ–‘         66 (4.2%)

๐Ÿ“ˆ Registration Burst Days

DateDomainsร— Average
2026-06-1523211.2ร— ๐Ÿšจ
2026-06-082029.8ร— ๐Ÿšจ
2026-06-172029.8ร— ๐Ÿšจ
2026-06-101919.2ร— ๐Ÿšจ
2026-06-041698.2ร— ๐Ÿšจ

๐ŸŽฏ Top Targeted Brands & Keywords

login (44) ยท binance (35) ยท ledger (31) ยท secure (30) ยท trust (29) ยท support (28) ยท official (27) ยท crypto (23) ยท coinbase (22) ยท vault (22) ยท connect (21) ยท wallet (17) ยท verify (16) ยท swap (13) ยท bridge (13)

๐Ÿ•ต๏ธ Top Serial Registrants โ€” 5 emails with โ‰ฅ5 domains

#Registrant Email (redacted)Domains
1m***@unternehmen.de23
2sup***@mxl.zendesk.com18
3sup***@stake.com13
4hel***@wingstop.com7
5s***@email.com5

๐Ÿ“ฅ Download Threat Intelligence

FileFormatDescription
data/all.txtTXTAll tracked domains
data/index.jsonJSONFull analytics snapshot
data/ioc/serial_registrants.jsonJSONRepeat registrants + their domains
data/ioc/shared_ips.jsonJSONBulletproof hosting clusters
data/ioc/brand_domains.jsonJSONDomains by targeted brand
data/ioc/stix-bundle.jsonSTIX 2.1MISP/OpenCTI ready bundle
data/ioc/serial_emails.txtTXTgrep-friendly: emailโ‡ฅcount
data/ioc/shared_ips.txtTXTgrep-friendly: ipโ‡ฅcountโ‡ฅcountry

๐Ÿ“Š Live web dashboard: see Pages link at top ยท Updated daily 06:00 UTC


๐Ÿ“‘ Table of Contents

Investigation

Evidence

Legal / Reuse


1 ยท Background

This repository is the Phase II evidence package of the PhishDestroy investigation into Trustname.com / Fewmoretaps Oรœ (IANA registrar ID #4318).

Phase I โ€” operator profile and corporate forensics is published as a standalone article on the PhishDestroy site: ๐Ÿ“ฐ phishdestroy.io/trustname-bulletproof-exposed

This README does not duplicate Phase I material. Refer to the Phase I article for entity, officer, financial, and infrastructure findings.

Phase II โ€” this repository โ€” quantifies the abuse footprint by enumerating every domain in the registrar's zone. Rather than sampling, every domain is processed through a four-stage technical pipeline:

       โ•ญโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ•ฎ      โ•ญโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ•ฎ      โ•ญโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ•ฎ      โ•ญโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ•ฎ
       โ”‚   1. AWS Lambda    โ”‚ โ”€โ”€โ”€โ–ถ โ”‚  2. Headless       โ”‚ โ”€โ”€โ”€โ–ถ โ”‚  3. CF Deep Scan   โ”‚ โ”€โ”€โ”€โ–ถ โ”‚  4. AI            โ”‚
       โ”‚   HTTP fingerprint โ”‚      โ”‚     Browser render โ”‚      โ”‚     + 2captcha     โ”‚      โ”‚     classification โ”‚
       โ”‚   80 conc / inv.   โ”‚      โ”‚     Playwright     โ”‚      โ”‚     SOCKS5 pool    โ”‚      โ”‚     Llama 3.1     โ”‚
       โ•ฐโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ•ฏ      โ•ฐโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ•ฏ      โ•ฐโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ•ฏ      โ•ฐโ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ”€โ•ฏ
              7,641                       7,641                       2,182                       2,434
              domains                     domains                     protected targets           classified

Phase II in one sentence: of the 2,583 domains under this registrar that actually serve content, 2,221 (86 %) are confirmed malicious โ€” phishing, carding, crypto drainers, malware distribution, illegal-drug sales, and unlicensed gambling. The remaining 5,058 are dead or parked. The complete per-domain dataset, screenshots, and operator-cluster analysis live in this repository.


2 ยท Subject

FieldValue
๐Ÿข Legal entityFewmoretaps Oรœ
๐ŸŒ DBATrustname.com
๐Ÿ†” ICANN / IANA ID#4318
๐Ÿ‡ช๐Ÿ‡ช JurisdictionEstonia (EU)

Operator identity, corporate-registry details, and financial profile are covered in Phase I: phishdestroy.io/trustname-bulletproof-exposed


3 ยท Scope and Coverage

ParameterValue
๐Ÿ“† Scan windowJune 2026
๐Ÿ“Š Domains in scope7,641 โ€” all domains under registrar management
๐ŸŽฏ SamplingNone โ€” complete-zone enumeration
๐ŸŒ Network coverageFull HTTP + headless browser for every domain
โ˜ Cloudflare-protected2,072 domains identified in the enriched dataset
๐Ÿงฉ Phase 3 re-scan targets2,182 blocked / challenged domains re-scanned via proxy + 2captcha
๐Ÿงฉ CAPTCHAs solved92 (hCaptcha ยท reCAPTCHA v2/v3 ยท Cloudflare Turnstile)
๐Ÿ“ท Screenshots captured1,953
๐Ÿค– AI-classified content2,434 domains
๐Ÿ›ก Threat-intel feedsSpamhaus DBL ยท SURBL ยท URLhaus ยท ThreatFox

4 ยท Methodology

๐Ÿ” Phase 1 โ€” HTTP Fingerprint (AWS Lambda)
RuntimePython 3.11 + `aiohttp$, \text{deployed} \text{to} \text{AWS} \text{Lambda}
\text{Concurrency}80 \text{requests} / \text{invocation} \times 77 \text{parallel} \text{invocations}
\text{User}-\text{Agent}\text{Googlebot} (\text{cloaking} \text{bypass})
$favicon_mmh3`MurmurHash3 32-bit of /favicon.ico โ€” Shodan-compatible
server_fpSHA-256 of server โ€– content-type โ€– x-powered-by
simhash64-bit body SimHash for near-duplicate detection
๐Ÿ–ฅ Phase 2 โ€” Browser Render (Playwright)
RuntimePlaywright 1.40 + playwright-stealth v2, headless Chromium
Isolationnew browser context per domain (prevents `TargetClosedError$ \text{cascade})
\text{Capture}\text{Full}-\text{page} \text{screenshot} 1280 \times 800, \text{DOM} \text{dump}, \text{form}-\text{field} \text{inventory}

\text{Form}-\text{field} \text{semantic} \text{flags}: $seed_phraseยทprivate_keyยทwallet_addrยทcard_numberยทcvvยทibanยทsort_codeยทrouting_numberยทpasswordยทotp_2faยทrecovery_emailยทssnยทpassport_numberยทdob`

โ˜ Phase 3 โ€” Cloudflare Deep Scan
Scope2,182 domains returning HTTP 403/503 from Phase 2
Proxy pool2,600+ rotating SOCKS5 exits
CAPTCHA2captcha API โ€” hCaptcha ยท reCAPTCHA v2/v3 ยท Cloudflare Turnstile
Result92 CAPTCHAs solved ยท 1,953 final screenshots
๐Ÿค– Phase 4 โ€” AI Classification
Modelllama-3.1-8b-instant via Groq API
Input(title, h1, meta_desc, body_text[:2000], form_labels)
OutputNatural-language description + category enum + severity score
DNSBLSpamhaus DBL ยท SURBL
RESTURLhaus ยท ThreatFox (Abuse.ch)

๐Ÿ“Š Headline Findings

MetricValue
๐Ÿงฎ Total domains scanned7,641
๐Ÿ’€ Dead / parked / error5,058 (66.2 %)
๐Ÿ’š Active with content2,583 (33.8 %)
๐Ÿ”ด HIGH severity1,114
๐ŸŸ  MEDIUM severity1,107
โš  Total malicious (HIGH + MEDIUM)2,221
๐Ÿšจ Malicious share of active content86.0 %
โ˜ Behind Cloudflare2,072
๐Ÿ“ท Screenshots captured1,953
๐Ÿงฉ CAPTCHAs bypassed92

๐Ÿ”ฅ Of the domains in this registrar's zone that actually serve content, only 1 in 7 is legitimate.

Category Breakdown

CategoryCountSeverityDescription
๐ŸŽฐGAMBLING733๐ŸŸ  MEDIUMUnlicensed casino/betting; Turkish bahis cluster
๐ŸŽฃPHISHING_GENERIC396๐Ÿ”ด HIGHCredential harvesting (login, OTP, password)
๐ŸฆPHISHING_FINANCE236๐Ÿ”ด HIGHBank/card/CVV harvesting
๐Ÿ’ณCARDING182๐Ÿ”ด HIGHClone-card shops, dumps markets, money-mule
๐Ÿช™PHISHING_CRYPTO178๐Ÿ”ด HIGHWallet/exchange phishing (Ledger, Solflare, Pump.fun)
๐ŸŽญCRYPTO_SCAM146๐Ÿ”ด HIGHFake investment platforms, "Elon Musk" casinos
โ˜ฃMALWARE_DIST105๐Ÿ”ด HIGHRAT shops, crackware, fake firmware updaters
โ„ขBRAND_ABUSE83๐ŸŸ  MEDIUMBrand impersonation, typosquatting
๐Ÿ”žADULT81๐ŸŸ  MEDIUMUnlicensed adult content, escort/cams
๐ŸšฐCRYPTO_DRAIN60๐Ÿ”ด HIGHWallet drainers, seed-phrase forms
๐Ÿ“จSPAM_INFRA56๐ŸŸ  MEDIUMEmail/SMS spam infrastructure
๐Ÿ”€PROXY_VPN48๐ŸŸ  MEDIUMProxy / VPN abuse services
๐Ÿ’ŠILLEGAL_DRUGS42๐Ÿ”ด HIGHRx drugs without prescription
๐Ÿ”„CRYPTO_MIXER28๐Ÿ”ด HIGHCryptocurrency mixing / laundering
๐ŸŸขACTIVE207๐ŸŸข LOWResponds, no confirmed malicious signal
๐Ÿ…ฟPARKING27โšช INFOParked / for sale
โŒERROR286โšช INFO5xx, connection refused, no content
โšซDEAD4,745โšช INFONo DNS / no response

๐Ÿ“„ Full per-domain data: data/enriched.csv


๐Ÿ•ธ Operator Clusters

Domains grouped by shared server fingerprint (SHA-256 prefix) and favicon MurmurHash3. Shared fingerprint = same hosting stack / same operator template โ€” evidence of coordinated infrastructure, not unrelated registrants.

Cluster KeyTypeDomainsPrimary Category
๐Ÿ”‘ 811e0897f489server_fp1,674๐ŸŽฐ GAMBLING โ€” Turkish bahis cluster
๐Ÿ”‘ 0ab5f121ab0dserver_fp305๐ŸŽฐ GAMBLING โ€” multilingual casino
๐Ÿ”‘ 4492f7f3e69cserver_fp161๐Ÿ’ณ CARDING
๐Ÿ”‘ d8c33640a2fcserver_fp149๐Ÿ’ณ CARDING
๐Ÿ”‘ 4b8db6e031ccserver_fp122๐Ÿฆ PHISHING_FINANCE โ€” 1xbet typosquats
๐Ÿ”‘ 24be2aa9d598server_fp104โŒ ERROR (dormant abuse infra)
๐Ÿ–ผ -736095526favicon_mmh388๐ŸŽญ CRYPTO_SCAM โ€” "Elon" casino cluster โ€” overlaps Phase I
๐Ÿ–ผ 1869784862favicon_mmh334๐Ÿช™ PHISHING_CRYPTO โ€” Solana drainer cluster
๐Ÿ”‘ a1b77bce0100server_fp28โ˜ฃ MALWARE_DIST โ€” Binance impersonation

๐ŸŽฏ A single server fingerprint 811e0897f489 accounts for 21.9 % of the entire registrar zone. The "Elon" favicon cluster identified here directly extends the six-domain operator group described in Phase I.

Full cluster data: case/CLUSTERS.md


๐Ÿ“ฆ Evidence Archive

All artefacts are content-addressed by SHA-256 to support chain-of-custody verification.

PathSizeSHA-256 (16)Contents
๐Ÿ“Š data/enriched.csv2.8 MB83ea143175d8a378Full enriched dataset โ€” all 7,641 domains, all columns
๐Ÿ“Š data/high_severity.csv748 KBecee3b68b2fb34c8HIGH-only filtered subset
๐Ÿ“Š data/dead_domains.csv742 KB5ee84646c6872591Dead / parked / error enumeration
๐Ÿšซ ioc/domains_high.txt19 KBec9e43c15ff3cffcProduction blocklist โ€” 1,114 HIGH domains
๐Ÿšซ ioc/domains_all_malicious.txt39 KBd27809c1a099c019HIGH + MEDIUM blocklist โ€” 2,221 domains
๐Ÿ›ก ioc/indicators.csv775 KB4e9dcd3840be9f9aSIEM indicators โ€” IP, server_fp, favicon_mmh3, category, severity
๐Ÿ” evidence/HASHES.txt168 KB131ff258bd0c058cSHA-256 of all 1,953 screenshots
๐Ÿ“ฆ pkg/raw_data/enriched.csv.gz560 KBa2a6f5fda9f364aaCompressed enriched dataset
๐Ÿ“ฆ pkg/raw_data/lambda_results.jsonl.gz509 KBc0add17921efada8Phase 1 โ€” HTTP fingerprint raw output
๐Ÿ“ฆ pkg/raw_data/deep_results.jsonl.gz1.1 MB60b943f03e7ac926Phase 2/3 โ€” browser render raw output
๐Ÿ“ฆ pkg/raw_data/threat_intel.jsonl.gz74 KB4a92dafe955b60d4Threat-intel cross-reference

๐Ÿ“‹ Detailed chain-of-custody documentation: PROVENANCE.md

๐Ÿ” Verification

# verify any archive
sha256sum pkg/raw_data/enriched.csv.gz
# expected prefix: a2a6f5fda9f364aaโ€ฆ

# verify all 1,953 screenshots against the manifest
cd docs/screenshots && sha256sum -c ../../evidence/HASHES.txt

๐ŸŽฏ Notable Confirmed Cases

DomainCategoryEvidence
๐Ÿ’ณ buyclonecards.bondCARDINGExplicit clone-card shop, CVV dumps market
โ˜ฃ thebtmob.comMALWARE_DISTActive BT-MOB RAT shop, malware-as-a-service
๐Ÿšฐ fragapi.comCRYPTO_DRAINSeed-phrase harvesting form (browser-confirmed)
๐Ÿšฐ instasolana.bondCRYPTO_DRAINSolana wallet drainer, 1,674-domain shared infra
๐Ÿช™ purnp-fun.comPHISHING_CRYPTOFake Pump.fun / Solflare phishing page
โ˜ฃ kmspico.zipMALWARE_DISTMalware under crack/keygen disguise
๐Ÿ’ณ rollmaneycontrol.bondCARDINGMoney-mule / fund-transfer fraud

Full per-domain narrative: case/HIGH_SEVERITY.md


โš– Enforcement Posture

This report is structured as an evidence package for criminal and financial-intelligence agencies, not as an ICANN compliance filing.

ICANN's mandate is technical stability of the DNS, not fraud policing. The Registrar Accreditation Agreement is a contract; an RAA ยง3.18 violation is a breach of contract, not a crime. Accreditation revocation is an administrative process measured in years.

Fewmoretaps Oรœ collects registration revenue from operators conducting wire fraud, credential theft, carding, and cryptocurrency theft โ€” establishing a knowing position in the criminal money flow. Criminal liability does not require ICANN action as a prerequisite.

AgencyJurisdictional Basis
๐Ÿ‡ช๐Ÿ‡ช Politsei- ja PiirivalveametPrimary registration jurisdiction ยท EU AML Directive
๐Ÿ‡ช๐Ÿ‡ช CERT-EE / RIANational CERT ยท cybercrime reporting authority
๐Ÿ‡ช๐Ÿ‡บ Europol EC3Cross-border cybercrime coordination ยท iForce referrals
๐Ÿ‡บ๐Ÿ‡ธ FBI IC3Wire fraud (18 U.S.C. ยง1343), CFAA โ€” US victims
๐Ÿ‡บ๐Ÿ‡ธ FinCENMoney-services business violations ยท USD flow tracing

๐Ÿ“‚ Repository Structure

trustname-evidence/
โ”œโ”€โ”€ ๐Ÿ“Š docs/                                 GitHub Pages site
โ”‚   โ”œโ”€โ”€ index.html                          Executive report โ€” metrics, charts, gallery
โ”‚   โ”œโ”€โ”€ domains.html                        Searchable per-domain table (7,641)
โ”‚   โ”œโ”€โ”€ data.json                           Slim dataset for the live report
โ”‚   โ”œโ”€โ”€ build_datajson.py                   Generator: enriched.csv โ†’ data.json
โ”‚   โ”œโ”€โ”€ sitemap.xml / robots.txt / .nojekyll
โ”‚   โ””โ”€โ”€ screenshots/                        Local mirror; ignored by git, publish via S3/Git LFS
โ”œโ”€โ”€ ๐Ÿ“ data/                                 Source datasets
โ”‚   โ”œโ”€โ”€ enriched.csv                        Full per-domain dataset
โ”‚   โ”œโ”€โ”€ high_severity.csv                   HIGH-only filtered subset
โ”‚   โ””โ”€โ”€ dead_domains.csv                    Dead / parked enumeration
โ”œโ”€โ”€ ๐Ÿšซ ioc/                                  Indicators of Compromise
โ”‚   โ”œโ”€โ”€ domains_high.txt                    1,114 HIGH blocklist
โ”‚   โ”œโ”€โ”€ domains_all_malicious.txt           2,221 HIGH + MEDIUM blocklist
โ”‚   โ””โ”€โ”€ indicators.csv                      SIEM-ready
โ”œโ”€โ”€ ๐Ÿ” evidence/
โ”‚   โ”œโ”€โ”€ screenshots/                        Local screenshot archive; ignored by git
โ”‚   โ””โ”€โ”€ HASHES.txt                          SHA-256 manifest
โ”œโ”€โ”€ ๐Ÿ“„ case/                                 Narrative reports
โ”‚   โ”œโ”€โ”€ INVESTIGATION.md
โ”‚   โ”œโ”€โ”€ HIGH_SEVERITY.md
โ”‚   โ””โ”€โ”€ CLUSTERS.md
โ”œโ”€โ”€ ๐Ÿ“ฆ pkg/raw_data/                         Compressed raw scan output
โ”‚   โ”œโ”€โ”€ enriched.csv.gz
โ”‚   โ”œโ”€โ”€ lambda_results.jsonl.gz
โ”‚   โ”œโ”€โ”€ deep_results.jsonl.gz
โ”‚   โ””โ”€โ”€ threat_intel.jsonl.gz
โ”œโ”€โ”€ ๐Ÿ”ง .github/workflows/pages.yml           Auto-build & deploy
โ”œโ”€โ”€ ๐Ÿ“„ PROVENANCE.md                         Chain of custody
โ”œโ”€โ”€ ๐Ÿ“„ VERIFY.md                             Hash verification and release signing
โ”œโ”€โ”€ ๐Ÿ“„ NOTICE.md                             TLP:CLEAR and evidence-use notice
โ”œโ”€โ”€ ๐Ÿ“„ CITATION.cff                          Citation metadata
โ”œโ”€โ”€ ๐Ÿ” SHA256SUMS.txt                        Repository SHA-256 manifest
โ”œโ”€โ”€ ๐Ÿ“œ LICENSE                               MIT
โ””โ”€โ”€ ๐Ÿ“– README.md

๐ŸŒ PhishDestroy

PhishDestroy.io Phase I Article Live Report

PhishDestroy is an independent anti-phishing and anti-fraud research project. Our work includes:

  • Domain abuse detection at scale โ€” complete-zone scans of accused-bulletproof registrars, real-time IOC feed publication, infrastructure clustering
  • Operator attribution โ€” corporate-registry forensics, payment-rail tracing, fake-review forensics, infrastructure mapping
  • Public evidence packages โ€” TLP:CLEAR, MIT-licensed, formatted for ICANN compliance, law-enforcement intake, and academic citation

๐ŸŒ Main site & research index: phishdestroy.io ๐Ÿ“š Investigation archive: phishdestroy.io/articles ๐Ÿ™ Code & datasets: github.com/phishdestroy

๐ŸŒ Mirrors and Long-Term Access

ChannelIdentifier
๐Ÿ™ GitHubphishdestroy/trustname-evidence
๐ŸŒ GitHub Pagesphishdestroy.github.io/trustname-evidence
๐Ÿ“ฐ PhishDestroy publicationphishdestroy.io/trustname-bulletproof-exposed
๐ŸŒ PhishDestroy main sitephishdestroy.io
โณ Wayback Machinesnapshot pinned on publication

๐Ÿ“š Citation

@misc{phishdestroy_trustname_2026,
  author       = {PhishDestroy Research},
  title        = {Fewmoretaps O\"U / Trustname.com --- Registrar Zone Evidence
                  (Phase II of the Trustname Investigation)},
  year         = 2026,
  month        = jun,
  howpublished = {GitHub},
  url          = {https://github.com/phishdestroy/trustname-evidence}
}

Plain text:

PhishDestroy. (2026). Fewmoretaps Oรœ / Trustname.com โ€” Registrar Zone Evidence
(Phase II of the Trustname investigation). GitHub.
https://github.com/phishdestroy/trustname-evidence

All data in this repository was collected exclusively from publicly accessible sources:

SourceMethod
Zone fileICANN CZDS โ€” accredited access, permissible use
WHOISPublic WHOIS protocol (RFC 3912)
HTTP responsesPassive crawl of publicly reachable URLs
DNS recordsPassive DNS / authoritative queries
ScreenshotsRendered pages accessible to any browser

No non-public systems were accessed. No credentials were tested. No authentication was bypassed. No victim data was processed.

This publication is conducted under:

Regarding Reputational Impact

This research documents objectively verifiable facts: domain registration patterns, HTTP response content, and registrar abuse-response latency. Trustname.com / Fewmoretaps Oรœ is an ICANN-accredited registrar bound by public accountability obligations.

Publication of factual evidence of contractual non-compliance with ICANN's abuse-response requirements is not defamation โ€” it is the function those requirements were designed to enable. Registrars that maintain functional abuse response pipelines have nothing to fear from this disclosure.

If Trustname disputes any finding: submit documented evidence via phishdestroy.io. Findings supported by evidence will be corrected in a timestamped update.

๐Ÿ“œ LicenseMIT โ€” see LICENSE
๐Ÿท TLPCLEAR โ€” unlimited distribution, no restrictions
๐Ÿค SharingResearchers, journalists, law enforcement, brand protection teams โ€” use freely
๐Ÿ“‹ Evidence noticeNOTICE.md
๐Ÿ” VerificationVERIFY.md
๐ŸŒ Contactphishdestroy.io

๐Ÿ•ธ๏ธ Network of Complicit Registrars

This investigation is part of a series documenting ICANN-accredited registrars that systematically obstruct anti-phishing enforcement or directly profit from fraud infrastructure.

#RegistrarIANAZoneConfirmed MaliciousRussian ConnectionInvestigation
1NICENIC INTERNATIONAL GROUP#3765349,37618,927 (50% of alive)๐Ÿ‡ท๐Ÿ‡บ #2 hosting country (8.5%)nicenic-evidence ยท Live Report
2Trustname.com / Fewmoretaps ร–รœ (this)#43189,3431,114 HIGH (86% alive)๐Ÿ‡ท๐Ÿ‡บ Russian-operated, Estonian shelltrustname-evidence ยท Live Report
3NameSilo, LLC#14795,251,494183,419๐Ÿ‡ท๐Ÿ‡บ Russian team members, suppression campaignnamesilo-evidence ยท Live Report

๐Ÿ‡ท๐Ÿ‡บ Russian Connection & Complicity Record

The Operators โ€” Belarusian, Not Estonian

Fewmoretaps ร–รœ is registered in Estonia but operated entirely by Belarusian nationals with zero legitimate business activity:

Original Founder (2021โ€“2023):

FieldDetail
NameVitali Tsyvinski
NationalityBelarus
Personal ID39403090187
RoleSole board member & shareholder
Signed2022 annual report on 13.01.2023

Current Owner / CEO (since 23.05.2023):

FieldDetail
NameKiryl Nestsiarovich ("Kir N.")
DOB09.09.1993
NationalityBelarus
Phone+375 29 2964411 (MTS mobile, Belarusian carrier)
Shareholding100%
StatusListed as CEO on trustname.com/about

Estonia is used exclusively as a jurisdiction of convenience. The company has one employee (Nestsiarovich himself), โ‚ฌ120 declared revenue in 2024 against โ‚ฌ175,310 in long-term liabilities, and is currently under liquidation.

Financial Reality vs. Marketing Claims

What Trustname.com claims:

  • "#1 fastest growing independent registrar in 2025"
  • "Trusted by millions"
  • Fortune 500 clients: McDonald's, Vodafone, Adidas, Yahoo, BCG
  • "Team of over 35 people"
  • Offices in London, Beverly Hills, Melbourne
  • "Since 1997"

What Estonian tax filings show:

  • โ‚ฌ120 total revenue (2024)
  • 1 employee (Nestsiarovich)
  • Incorporated 2021 โ€” not 1997
  • Company under liquidation proceedings
  • Virtual office address only
  • 30 fake website testimonials โ€” only 11 unique first names ("Jack" ร—5, "Lily" ร—6)

The gap between the marketing front and the corporate reality is not a discrepancy โ€” it is the business model.

Crypto Wallets (Accept Monero โ€” Untraceable)

AssetAddress
ETH0xdee6582dc53fa56180311393018121c6f1e8bd7c
LTCMEREvHtzqAUTJ1XvEevmci8UqMnDvfe2ri
ZECt1d19KevpcXpesr9XA9UUyMW9XGYVDxkK9S
XMR8B5N29BocrTjkRCeGCARnkhKgBeHBhg4oH7ay4RfXfnL7RqBdyiuL4k6iN4GVUVxt1EQJvZRqLg8n4qgCNWmYHQQDZmfytM

Accepting Monero (XMR) โ€” a cryptocurrency specifically designed to be untraceable โ€” while declaring โ‚ฌ120 annual revenue and holding an ICANN accreditation is not a compliance edge case. It is a structural violation of Estonian AML law and VASP licensing requirements.

Russian-Language Fraud Infrastructure

Active scam casino domains registered through IANA #4318 in April 2026, all shielded by registrar-owned privacy proxies:

DomainRegisteredNotes
noawin.com04-12-2026Privacy: Perfect Privacy LLC (St Kitts & Nevis)
henofex.com04-09-2026"Elon Musk" Casino scheme
jopexplay.com04-10-2026Cloudflare-blocked
bezowin159.pro04-13-2026Privacy: WHOIS Privacy Protection LLC
noswin152.pro04-08-2026โ€”
bazowin781.pro04-08-2026โ€”

Shared backend: gambler-partners.is โ€” Russian-language admin panel titled "Gambler | ะ“ะปะฐะฒะฝะฐั"

Trustname operates two registrar-owned privacy proxy services to shield its fraud customers:

  • harakiri.org โ€” Perfect Privacy LLC, Saint Kitts & Nevis โ€” accepts BTC, LTC, XMR, ZEC
  • whoispps.com โ€” WHOIS Privacy Protection LLC, Orlando FL โ€” "Physical mail is discarded"

Documented Obstruction

  • Domains with full evidence packages survive abuse reports without suspension.
  • Registration revenue and crypto payments flow from operators running wire fraud, credential theft, and casino scams โ€” knowing position in criminal money flow.
  • Company is under liquidation, yet ICANN accreditation remains active โ€” enforcement lag creates an operational window for ongoing abuse.
  • As an EU-registered entity subject to Estonian AML/CFT law and the EU's VASP framework, Fewmoretaps is operating a de facto unlicensed crypto exchange.
  • Direct abuse reports with evidence: ignored or met with form-letter non-responses.
  • Criminal liability under Estonian law does not require prior ICANN action.

"โ‚ฌ120 revenue. โ‚ฌ175,310 liabilities. Monero accepted. One employee. ICANN-accredited. Under liquidation. This is not a registrar โ€” it is a fraud infrastructure service with a compliance veneer."

Full Phase I investigation: phishdestroy.io/trustname-bulletproof-exposed

NameSilo Investigation


footer

PhishDestroy Research ยท Phase II ยท June 2026 ยท TLP:CLEAR