Trustname.com / Fewmoretaps Oร
June 24, 2026 ยท View on GitHub
๐ด LIVE INVESTIGATION FEED ยท Auto-updated ยท Last fetch
2026-06-24
๐ฆ Domains tracked9,536 |
๐ฐ Est. revenue\$80,029 |
๐ก Deployed66.4% |
โ
Confirmed phishing35.9% (3,428) |
โก Fresh (โค7d)6.7% |
๐ต๏ธ Serial regs3 |
๐ท๏ธ Top TLD Zones
| TLD | Count | Avg Reg Period | Est. Revenue |
|---|---|---|---|
.com | 7,508 | 418d | $67,497 |
.icu | 620 | 365d | $614 |
.net | 438 | 434d | $4,376 |
.org | 369 | 510d | $3,686 |
.app | 81 | 365d | $1,134 |
.cam | 78 | 365d | $389 |
.pro | 54 | 425d | $431 |
.cyou | 50 | 365d | $50 |
.xyz | 35 | 396d | $52 |
.info | 34 | 483d | $136 |
๐ Top Hosting Countries
US โโโโโโโโโโโโโโโโโโ 506 (32.6%)
RU โโโโโโโโโโโโโโโโโโ 152 (9.8%)
GB โโโโโโโโโโโโโโโโโโ 131 (8.4%)
DE โโโโโโโโโโโโโโโโโโ 118 (7.6%)
NL โโโโโโโโโโโโโโโโโโ 97 (6.2%)
CA โโโโโโโโโโโโโโโโโโ 87 (5.6%)
BZ โโโโโโโโโโโโโโโโโโ 72 (4.6%)
UA โโโโโโโโโโโโโโโโโโ 66 (4.2%)
๐ Registration Burst Days
| Date | Domains | ร Average |
|---|---|---|
2026-06-15 | 232 | 11.2ร ๐จ |
2026-06-08 | 202 | 9.8ร ๐จ |
2026-06-17 | 202 | 9.8ร ๐จ |
2026-06-10 | 191 | 9.2ร ๐จ |
2026-06-04 | 169 | 8.2ร ๐จ |
๐ฏ Top Targeted Brands & Keywords
login (44) ยท binance (35) ยท ledger (31) ยท secure (30) ยท trust (29) ยท support (28) ยท official (27) ยท crypto (23) ยท coinbase (22) ยท vault (22) ยท connect (21) ยท wallet (17) ยท verify (16) ยท swap (13) ยท bridge (13)
๐ต๏ธ Top Serial Registrants โ 5 emails with โฅ5 domains
| # | Registrant Email (redacted) | Domains |
|---|---|---|
| 1 | m***@unternehmen.de | 23 |
| 2 | sup***@mxl.zendesk.com | 18 |
| 3 | sup***@stake.com | 13 |
| 4 | hel***@wingstop.com | 7 |
| 5 | s***@email.com | 5 |
๐ฅ Download Threat Intelligence
| File | Format | Description |
|---|---|---|
data/all.txt | TXT | All tracked domains |
data/index.json | JSON | Full analytics snapshot |
data/ioc/serial_registrants.json | JSON | Repeat registrants + their domains |
data/ioc/shared_ips.json | JSON | Bulletproof hosting clusters |
data/ioc/brand_domains.json | JSON | Domains by targeted brand |
data/ioc/stix-bundle.json | STIX 2.1 | MISP/OpenCTI ready bundle |
data/ioc/serial_emails.txt | TXT | grep-friendly: emailโฅcount |
data/ioc/shared_ips.txt | TXT | grep-friendly: ipโฅcountโฅcountry |
๐ Live web dashboard: see Pages link at top ยท Updated daily 06:00 UTC
๐ Table of Contents
|
Investigation |
Evidence |
Legal / Reuse |
1 ยท Background
This repository is the Phase II evidence package of the PhishDestroy investigation into Trustname.com / Fewmoretaps Oร (IANA registrar ID #4318).
Phase I โ operator profile and corporate forensics is published as a standalone article on the PhishDestroy site: ๐ฐ phishdestroy.io/trustname-bulletproof-exposed
This README does not duplicate Phase I material. Refer to the Phase I article for entity, officer, financial, and infrastructure findings.
Phase II โ this repository โ quantifies the abuse footprint by enumerating every domain in the registrar's zone. Rather than sampling, every domain is processed through a four-stage technical pipeline:
โญโโโโโโโโโโโโโโโโโโโโโฎ โญโโโโโโโโโโโโโโโโโโโโโฎ โญโโโโโโโโโโโโโโโโโโโโโฎ โญโโโโโโโโโโโโโโโโโโโโโฎ
โ 1. AWS Lambda โ โโโโถ โ 2. Headless โ โโโโถ โ 3. CF Deep Scan โ โโโโถ โ 4. AI โ
โ HTTP fingerprint โ โ Browser render โ โ + 2captcha โ โ classification โ
โ 80 conc / inv. โ โ Playwright โ โ SOCKS5 pool โ โ Llama 3.1 โ
โฐโโโโโโโโโโโโโโโโโโโโโฏ โฐโโโโโโโโโโโโโโโโโโโโโฏ โฐโโโโโโโโโโโโโโโโโโโโโฏ โฐโโโโโโโโโโโโโโโโโโโโโฏ
7,641 7,641 2,182 2,434
domains domains protected targets classified
Phase II in one sentence: of the 2,583 domains under this registrar that actually serve content, 2,221 (86 %) are confirmed malicious โ phishing, carding, crypto drainers, malware distribution, illegal-drug sales, and unlicensed gambling. The remaining 5,058 are dead or parked. The complete per-domain dataset, screenshots, and operator-cluster analysis live in this repository.
2 ยท Subject
| Field | Value |
|---|---|
| ๐ข Legal entity | Fewmoretaps Oร |
| ๐ DBA | Trustname.com |
| ๐ ICANN / IANA ID | #4318 |
| ๐ช๐ช Jurisdiction | Estonia (EU) |
Operator identity, corporate-registry details, and financial profile are covered in Phase I: phishdestroy.io/trustname-bulletproof-exposed
3 ยท Scope and Coverage
| Parameter | Value |
|---|---|
| ๐ Scan window | June 2026 |
| ๐ Domains in scope | 7,641 โ all domains under registrar management |
| ๐ฏ Sampling | None โ complete-zone enumeration |
| ๐ Network coverage | Full HTTP + headless browser for every domain |
| โ Cloudflare-protected | 2,072 domains identified in the enriched dataset |
| ๐งฉ Phase 3 re-scan targets | 2,182 blocked / challenged domains re-scanned via proxy + 2captcha |
| ๐งฉ CAPTCHAs solved | 92 (hCaptcha ยท reCAPTCHA v2/v3 ยท Cloudflare Turnstile) |
| ๐ท Screenshots captured | 1,953 |
| ๐ค AI-classified content | 2,434 domains |
| ๐ก Threat-intel feeds | Spamhaus DBL ยท SURBL ยท URLhaus ยท ThreatFox |
4 ยท Methodology
๐ Phase 1 โ HTTP Fingerprint (AWS Lambda)
| Runtime | Python 3.11 + `aiohttp$, \text{deployed} \text{to} \text{AWS} \text{Lambda} |
| \text{Concurrency} | 80 \text{requests} / \text{invocation} \times 77 \text{parallel} \text{invocations} |
| \text{User}-\text{Agent} | \text{Googlebot} (\text{cloaking} \text{bypass}) |
| $favicon_mmh3` | MurmurHash3 32-bit of /favicon.ico โ Shodan-compatible |
server_fp | SHA-256 of server โ content-type โ x-powered-by |
simhash | 64-bit body SimHash for near-duplicate detection |
๐ฅ Phase 2 โ Browser Render (Playwright)
| Runtime | Playwright 1.40 + playwright-stealth v2, headless Chromium |
| Isolation | new browser context per domain (prevents `TargetClosedError$ \text{cascade}) |
| \text{Capture} | \text{Full}-\text{page} \text{screenshot} 1280 \times 800, \text{DOM} \text{dump}, \text{form}-\text{field} \text{inventory} |
\text{Form}-\text{field} \text{semantic} \text{flags}:
$seed_phraseยทprivate_keyยทwallet_addrยทcard_numberยทcvvยทibanยทsort_codeยทrouting_numberยทpasswordยทotp_2faยทrecovery_emailยทssnยทpassport_numberยทdob`
โ Phase 3 โ Cloudflare Deep Scan
| Scope | 2,182 domains returning HTTP 403/503 from Phase 2 |
| Proxy pool | 2,600+ rotating SOCKS5 exits |
| CAPTCHA | 2captcha API โ hCaptcha ยท reCAPTCHA v2/v3 ยท Cloudflare Turnstile |
| Result | 92 CAPTCHAs solved ยท 1,953 final screenshots |
๐ค Phase 4 โ AI Classification
| Model | llama-3.1-8b-instant via Groq API |
| Input | (title, h1, meta_desc, body_text[:2000], form_labels) |
| Output | Natural-language description + category enum + severity score |
| DNSBL | Spamhaus DBL ยท SURBL |
| REST | URLhaus ยท ThreatFox (Abuse.ch) |
๐ Headline Findings
| Metric | Value |
|---|---|
| ๐งฎ Total domains scanned | 7,641 |
| ๐ Dead / parked / error | 5,058 (66.2 %) |
| ๐ Active with content | 2,583 (33.8 %) |
| ๐ด HIGH severity | 1,114 |
| ๐ MEDIUM severity | 1,107 |
| โ Total malicious (HIGH + MEDIUM) | 2,221 |
| ๐จ Malicious share of active content | 86.0 % |
| โ Behind Cloudflare | 2,072 |
| ๐ท Screenshots captured | 1,953 |
| ๐งฉ CAPTCHAs bypassed | 92 |
๐ฅ Of the domains in this registrar's zone that actually serve content, only 1 in 7 is legitimate.
Category Breakdown
| Category | Count | Severity | Description | |
|---|---|---|---|---|
| ๐ฐ | GAMBLING | 733 | ๐ MEDIUM | Unlicensed casino/betting; Turkish bahis cluster |
| ๐ฃ | PHISHING_GENERIC | 396 | ๐ด HIGH | Credential harvesting (login, OTP, password) |
| ๐ฆ | PHISHING_FINANCE | 236 | ๐ด HIGH | Bank/card/CVV harvesting |
| ๐ณ | CARDING | 182 | ๐ด HIGH | Clone-card shops, dumps markets, money-mule |
| ๐ช | PHISHING_CRYPTO | 178 | ๐ด HIGH | Wallet/exchange phishing (Ledger, Solflare, Pump.fun) |
| ๐ญ | CRYPTO_SCAM | 146 | ๐ด HIGH | Fake investment platforms, "Elon Musk" casinos |
| โฃ | MALWARE_DIST | 105 | ๐ด HIGH | RAT shops, crackware, fake firmware updaters |
| โข | BRAND_ABUSE | 83 | ๐ MEDIUM | Brand impersonation, typosquatting |
| ๐ | ADULT | 81 | ๐ MEDIUM | Unlicensed adult content, escort/cams |
| ๐ฐ | CRYPTO_DRAIN | 60 | ๐ด HIGH | Wallet drainers, seed-phrase forms |
| ๐จ | SPAM_INFRA | 56 | ๐ MEDIUM | Email/SMS spam infrastructure |
| ๐ | PROXY_VPN | 48 | ๐ MEDIUM | Proxy / VPN abuse services |
| ๐ | ILLEGAL_DRUGS | 42 | ๐ด HIGH | Rx drugs without prescription |
| ๐ | CRYPTO_MIXER | 28 | ๐ด HIGH | Cryptocurrency mixing / laundering |
| ๐ข | ACTIVE | 207 | ๐ข LOW | Responds, no confirmed malicious signal |
| ๐ ฟ | PARKING | 27 | โช INFO | Parked / for sale |
| โ | ERROR | 286 | โช INFO | 5xx, connection refused, no content |
| โซ | DEAD | 4,745 | โช INFO | No DNS / no response |
๐ Full per-domain data: data/enriched.csv
๐ธ Operator Clusters
Domains grouped by shared server fingerprint (SHA-256 prefix) and favicon MurmurHash3. Shared fingerprint = same hosting stack / same operator template โ evidence of coordinated infrastructure, not unrelated registrants.
| Cluster Key | Type | Domains | Primary Category |
|---|---|---|---|
๐ 811e0897f489 | server_fp | 1,674 | ๐ฐ GAMBLING โ Turkish bahis cluster |
๐ 0ab5f121ab0d | server_fp | 305 | ๐ฐ GAMBLING โ multilingual casino |
๐ 4492f7f3e69c | server_fp | 161 | ๐ณ CARDING |
๐ d8c33640a2fc | server_fp | 149 | ๐ณ CARDING |
๐ 4b8db6e031cc | server_fp | 122 | ๐ฆ PHISHING_FINANCE โ 1xbet typosquats |
๐ 24be2aa9d598 | server_fp | 104 | โ ERROR (dormant abuse infra) |
๐ผ -736095526 | favicon_mmh3 | 88 | ๐ญ CRYPTO_SCAM โ "Elon" casino cluster โ overlaps Phase I |
๐ผ 1869784862 | favicon_mmh3 | 34 | ๐ช PHISHING_CRYPTO โ Solana drainer cluster |
๐ a1b77bce0100 | server_fp | 28 | โฃ MALWARE_DIST โ Binance impersonation |
๐ฏ A single server fingerprint
811e0897f489accounts for 21.9 % of the entire registrar zone. The "Elon" favicon cluster identified here directly extends the six-domain operator group described in Phase I.
Full cluster data: case/CLUSTERS.md
๐ฆ Evidence Archive
All artefacts are content-addressed by SHA-256 to support chain-of-custody verification.
| Path | Size | SHA-256 (16) | Contents |
|---|---|---|---|
๐ data/enriched.csv | 2.8 MB | 83ea143175d8a378 | Full enriched dataset โ all 7,641 domains, all columns |
๐ data/high_severity.csv | 748 KB | ecee3b68b2fb34c8 | HIGH-only filtered subset |
๐ data/dead_domains.csv | 742 KB | 5ee84646c6872591 | Dead / parked / error enumeration |
๐ซ ioc/domains_high.txt | 19 KB | ec9e43c15ff3cffc | Production blocklist โ 1,114 HIGH domains |
๐ซ ioc/domains_all_malicious.txt | 39 KB | d27809c1a099c019 | HIGH + MEDIUM blocklist โ 2,221 domains |
๐ก ioc/indicators.csv | 775 KB | 4e9dcd3840be9f9a | SIEM indicators โ IP, server_fp, favicon_mmh3, category, severity |
๐ evidence/HASHES.txt | 168 KB | 131ff258bd0c058c | SHA-256 of all 1,953 screenshots |
๐ฆ pkg/raw_data/enriched.csv.gz | 560 KB | a2a6f5fda9f364aa | Compressed enriched dataset |
๐ฆ pkg/raw_data/lambda_results.jsonl.gz | 509 KB | c0add17921efada8 | Phase 1 โ HTTP fingerprint raw output |
๐ฆ pkg/raw_data/deep_results.jsonl.gz | 1.1 MB | 60b943f03e7ac926 | Phase 2/3 โ browser render raw output |
๐ฆ pkg/raw_data/threat_intel.jsonl.gz | 74 KB | 4a92dafe955b60d4 | Threat-intel cross-reference |
๐ Detailed chain-of-custody documentation: PROVENANCE.md
๐ Verification
# verify any archive
sha256sum pkg/raw_data/enriched.csv.gz
# expected prefix: a2a6f5fda9f364aaโฆ
# verify all 1,953 screenshots against the manifest
cd docs/screenshots && sha256sum -c ../../evidence/HASHES.txt
๐ฏ Notable Confirmed Cases
| Domain | Category | Evidence |
|---|---|---|
๐ณ buyclonecards.bond | CARDING | Explicit clone-card shop, CVV dumps market |
โฃ thebtmob.com | MALWARE_DIST | Active BT-MOB RAT shop, malware-as-a-service |
๐ฐ fragapi.com | CRYPTO_DRAIN | Seed-phrase harvesting form (browser-confirmed) |
๐ฐ instasolana.bond | CRYPTO_DRAIN | Solana wallet drainer, 1,674-domain shared infra |
๐ช purnp-fun.com | PHISHING_CRYPTO | Fake Pump.fun / Solflare phishing page |
โฃ kmspico.zip | MALWARE_DIST | Malware under crack/keygen disguise |
๐ณ rollmaneycontrol.bond | CARDING | Money-mule / fund-transfer fraud |
Full per-domain narrative: case/HIGH_SEVERITY.md
โ Enforcement Posture
This report is structured as an evidence package for criminal and financial-intelligence agencies, not as an ICANN compliance filing.
ICANN's mandate is technical stability of the DNS, not fraud policing. The Registrar Accreditation Agreement is a contract; an RAA ยง3.18 violation is a breach of contract, not a crime. Accreditation revocation is an administrative process measured in years.
Fewmoretaps Oร collects registration revenue from operators conducting wire fraud, credential theft, carding, and cryptocurrency theft โ establishing a knowing position in the criminal money flow. Criminal liability does not require ICANN action as a prerequisite.
| Agency | Jurisdictional Basis |
|---|---|
| ๐ช๐ช Politsei- ja Piirivalveamet | Primary registration jurisdiction ยท EU AML Directive |
| ๐ช๐ช CERT-EE / RIA | National CERT ยท cybercrime reporting authority |
| ๐ช๐บ Europol EC3 | Cross-border cybercrime coordination ยท iForce referrals |
| ๐บ๐ธ FBI IC3 | Wire fraud (18 U.S.C. ยง1343), CFAA โ US victims |
| ๐บ๐ธ FinCEN | Money-services business violations ยท USD flow tracing |
๐ Repository Structure
trustname-evidence/
โโโ ๐ docs/ GitHub Pages site
โ โโโ index.html Executive report โ metrics, charts, gallery
โ โโโ domains.html Searchable per-domain table (7,641)
โ โโโ data.json Slim dataset for the live report
โ โโโ build_datajson.py Generator: enriched.csv โ data.json
โ โโโ sitemap.xml / robots.txt / .nojekyll
โ โโโ screenshots/ Local mirror; ignored by git, publish via S3/Git LFS
โโโ ๐ data/ Source datasets
โ โโโ enriched.csv Full per-domain dataset
โ โโโ high_severity.csv HIGH-only filtered subset
โ โโโ dead_domains.csv Dead / parked enumeration
โโโ ๐ซ ioc/ Indicators of Compromise
โ โโโ domains_high.txt 1,114 HIGH blocklist
โ โโโ domains_all_malicious.txt 2,221 HIGH + MEDIUM blocklist
โ โโโ indicators.csv SIEM-ready
โโโ ๐ evidence/
โ โโโ screenshots/ Local screenshot archive; ignored by git
โ โโโ HASHES.txt SHA-256 manifest
โโโ ๐ case/ Narrative reports
โ โโโ INVESTIGATION.md
โ โโโ HIGH_SEVERITY.md
โ โโโ CLUSTERS.md
โโโ ๐ฆ pkg/raw_data/ Compressed raw scan output
โ โโโ enriched.csv.gz
โ โโโ lambda_results.jsonl.gz
โ โโโ deep_results.jsonl.gz
โ โโโ threat_intel.jsonl.gz
โโโ ๐ง .github/workflows/pages.yml Auto-build & deploy
โโโ ๐ PROVENANCE.md Chain of custody
โโโ ๐ VERIFY.md Hash verification and release signing
โโโ ๐ NOTICE.md TLP:CLEAR and evidence-use notice
โโโ ๐ CITATION.cff Citation metadata
โโโ ๐ SHA256SUMS.txt Repository SHA-256 manifest
โโโ ๐ LICENSE MIT
โโโ ๐ README.md
๐ PhishDestroy
PhishDestroy is an independent anti-phishing and anti-fraud research project. Our work includes:
- Domain abuse detection at scale โ complete-zone scans of accused-bulletproof registrars, real-time IOC feed publication, infrastructure clustering
- Operator attribution โ corporate-registry forensics, payment-rail tracing, fake-review forensics, infrastructure mapping
- Public evidence packages โ TLP:CLEAR, MIT-licensed, formatted for ICANN compliance, law-enforcement intake, and academic citation
๐ Main site & research index: phishdestroy.io ๐ Investigation archive: phishdestroy.io/articles ๐ Code & datasets: github.com/phishdestroy
๐ Mirrors and Long-Term Access
| Channel | Identifier |
|---|---|
| ๐ GitHub | phishdestroy/trustname-evidence |
| ๐ GitHub Pages | phishdestroy.github.io/trustname-evidence |
| ๐ฐ PhishDestroy publication | phishdestroy.io/trustname-bulletproof-exposed |
| ๐ PhishDestroy main site | phishdestroy.io |
| โณ Wayback Machine | snapshot pinned on publication |
๐ Citation
@misc{phishdestroy_trustname_2026,
author = {PhishDestroy Research},
title = {Fewmoretaps O\"U / Trustname.com --- Registrar Zone Evidence
(Phase II of the Trustname Investigation)},
year = 2026,
month = jun,
howpublished = {GitHub},
url = {https://github.com/phishdestroy/trustname-evidence}
}
Plain text:
PhishDestroy. (2026). Fewmoretaps Oร / Trustname.com โ Registrar Zone Evidence
(Phase II of the Trustname investigation). GitHub.
https://github.com/phishdestroy/trustname-evidence
โ๏ธ Legal Notice & Responsible Disclosure
All data in this repository was collected exclusively from publicly accessible sources:
| Source | Method |
|---|---|
| Zone file | ICANN CZDS โ accredited access, permissible use |
| WHOIS | Public WHOIS protocol (RFC 3912) |
| HTTP responses | Passive crawl of publicly reachable URLs |
| DNS records | Passive DNS / authoritative queries |
| Screenshots | Rendered pages accessible to any browser |
No non-public systems were accessed. No credentials were tested. No authentication was bypassed. No victim data was processed.
This publication is conducted under:
- ICANN Registrar Accreditation Agreement ยง3.18 (abuse response obligations)
- CISA Coordinated Vulnerability Disclosure guidelines
- FIRST.org TLP:CLEAR definition โ unlimited public sharing permitted
Regarding Reputational Impact
This research documents objectively verifiable facts: domain registration patterns, HTTP response content, and registrar abuse-response latency. Trustname.com / Fewmoretaps Oร is an ICANN-accredited registrar bound by public accountability obligations.
Publication of factual evidence of contractual non-compliance with ICANN's abuse-response requirements is not defamation โ it is the function those requirements were designed to enable. Registrars that maintain functional abuse response pipelines have nothing to fear from this disclosure.
If Trustname disputes any finding: submit documented evidence via phishdestroy.io. Findings supported by evidence will be corrected in a timestamped update.
| ๐ License | MIT โ see LICENSE |
| ๐ท TLP | CLEAR โ unlimited distribution, no restrictions |
| ๐ค Sharing | Researchers, journalists, law enforcement, brand protection teams โ use freely |
| ๐ Evidence notice | NOTICE.md |
| ๐ Verification | VERIFY.md |
| ๐ Contact | phishdestroy.io |
๐ธ๏ธ Network of Complicit Registrars
This investigation is part of a series documenting ICANN-accredited registrars that systematically obstruct anti-phishing enforcement or directly profit from fraud infrastructure.
| # | Registrar | IANA | Zone | Confirmed Malicious | Russian Connection | Investigation |
|---|---|---|---|---|---|---|
| 1 | NICENIC INTERNATIONAL GROUP | #3765 | 349,376 | 18,927 (50% of alive) | ๐ท๐บ #2 hosting country (8.5%) | nicenic-evidence ยท Live Report |
| 2 | Trustname.com / Fewmoretaps รร (this) | #4318 | 9,343 | 1,114 HIGH (86% alive) | ๐ท๐บ Russian-operated, Estonian shell | trustname-evidence ยท Live Report |
| 3 | NameSilo, LLC | #1479 | 5,251,494 | 183,419 | ๐ท๐บ Russian team members, suppression campaign | namesilo-evidence ยท Live Report |
๐ท๐บ Russian Connection & Complicity Record
The Operators โ Belarusian, Not Estonian
Fewmoretaps รร is registered in Estonia but operated entirely by Belarusian nationals with zero legitimate business activity:
Original Founder (2021โ2023):
| Field | Detail |
|---|---|
| Name | Vitali Tsyvinski |
| Nationality | Belarus |
| Personal ID | 39403090187 |
| Role | Sole board member & shareholder |
| Signed | 2022 annual report on 13.01.2023 |
Current Owner / CEO (since 23.05.2023):
| Field | Detail |
|---|---|
| Name | Kiryl Nestsiarovich ("Kir N.") |
| DOB | 09.09.1993 |
| Nationality | Belarus |
| Phone | +375 29 2964411 (MTS mobile, Belarusian carrier) |
| Shareholding | 100% |
| Status | Listed as CEO on trustname.com/about |
Estonia is used exclusively as a jurisdiction of convenience. The company has one employee (Nestsiarovich himself), โฌ120 declared revenue in 2024 against โฌ175,310 in long-term liabilities, and is currently under liquidation.
Financial Reality vs. Marketing Claims
What Trustname.com claims:
- "#1 fastest growing independent registrar in 2025"
- "Trusted by millions"
- Fortune 500 clients: McDonald's, Vodafone, Adidas, Yahoo, BCG
- "Team of over 35 people"
- Offices in London, Beverly Hills, Melbourne
- "Since 1997"
What Estonian tax filings show:
- โฌ120 total revenue (2024)
- 1 employee (Nestsiarovich)
- Incorporated 2021 โ not 1997
- Company under liquidation proceedings
- Virtual office address only
- 30 fake website testimonials โ only 11 unique first names ("Jack" ร5, "Lily" ร6)
The gap between the marketing front and the corporate reality is not a discrepancy โ it is the business model.
Crypto Wallets (Accept Monero โ Untraceable)
| Asset | Address |
|---|---|
| ETH | 0xdee6582dc53fa56180311393018121c6f1e8bd7c |
| LTC | MEREvHtzqAUTJ1XvEevmci8UqMnDvfe2ri |
| ZEC | t1d19KevpcXpesr9XA9UUyMW9XGYVDxkK9S |
| XMR | 8B5N29BocrTjkRCeGCARnkhKgBeHBhg4oH7ay4RfXfnL7RqBdyiuL4k6iN4GVUVxt1EQJvZRqLg8n4qgCNWmYHQQDZmfytM |
Accepting Monero (XMR) โ a cryptocurrency specifically designed to be untraceable โ while declaring โฌ120 annual revenue and holding an ICANN accreditation is not a compliance edge case. It is a structural violation of Estonian AML law and VASP licensing requirements.
Russian-Language Fraud Infrastructure
Active scam casino domains registered through IANA #4318 in April 2026, all shielded by registrar-owned privacy proxies:
| Domain | Registered | Notes |
|---|---|---|
| noawin.com | 04-12-2026 | Privacy: Perfect Privacy LLC (St Kitts & Nevis) |
| henofex.com | 04-09-2026 | "Elon Musk" Casino scheme |
| jopexplay.com | 04-10-2026 | Cloudflare-blocked |
| bezowin159.pro | 04-13-2026 | Privacy: WHOIS Privacy Protection LLC |
| noswin152.pro | 04-08-2026 | โ |
| bazowin781.pro | 04-08-2026 | โ |
Shared backend: gambler-partners.is โ Russian-language admin panel titled "Gambler | ะะปะฐะฒะฝะฐั"
Trustname operates two registrar-owned privacy proxy services to shield its fraud customers:
- harakiri.org โ Perfect Privacy LLC, Saint Kitts & Nevis โ accepts BTC, LTC, XMR, ZEC
- whoispps.com โ WHOIS Privacy Protection LLC, Orlando FL โ "Physical mail is discarded"
Documented Obstruction
- Domains with full evidence packages survive abuse reports without suspension.
- Registration revenue and crypto payments flow from operators running wire fraud, credential theft, and casino scams โ knowing position in criminal money flow.
- Company is under liquidation, yet ICANN accreditation remains active โ enforcement lag creates an operational window for ongoing abuse.
- As an EU-registered entity subject to Estonian AML/CFT law and the EU's VASP framework, Fewmoretaps is operating a de facto unlicensed crypto exchange.
- Direct abuse reports with evidence: ignored or met with form-letter non-responses.
- Criminal liability under Estonian law does not require prior ICANN action.
"โฌ120 revenue. โฌ175,310 liabilities. Monero accepted. One employee. ICANN-accredited. Under liquidation. This is not a registrar โ it is a fraud infrastructure service with a compliance veneer."
Full Phase I investigation: phishdestroy.io/trustname-bulletproof-exposed
๐ Related Investigations
PhishDestroy Research ยท Phase II ยท June 2026 ยท TLP:CLEAR