ACTIVE INVESTIGATION TLP:CLEAR IANA #1479 ICANN Filed · Mar 18, 2026

NameSilo, LLC
Registrar Abuse Investigation

5,281,415 domains scanned  ·  Complete zone file census  ·  PhishDestroy Research

5,281,415
Domains scanned
87.3%
Dead or parked
204,460
Malicious (PG-shielded)
$10–20M
Estimated victim losses
20+
Abuse reports — ignored

Investigation Reports

All reports are based on the complete NameSilo zone file — no sampling. Raw data available as gzip archives in pkg/raw_data/.

📋
Zone Scan Report
Full investigation: methodology, HTTP scan pipeline, IOC breakdown, server fingerprint cluster analysis, chain of custody. SHA-256 verified.
5,281,415 domains  ·  2-phase scanner
🔬
Favicon Cluster Analysis
12 operator clusters identified via MurmurHash3 favicon fingerprinting. Identical favicon = identical operator. 328,230-domain single-server network.
12 clusters  ·  MurmurHash3
🗂
IOC Domain List
107,252 confirmed criminal domains — fully searchable with country flags, favicons, and abuse categories. Filter by type, country, or keyword.
107,252 IOCs  ·  searchable
🛡
PrivacyGuardian Shield
204,460 malicious domains registered with NameSilo and shielded by PrivacyGuardian.org — NameSilo's own WHOIS privacy service. The registrar owns both.
204,460 malicious  ·  25+ feeds
Review Manipulation
129 Trustpilot reviews deleted in 4 months. Bot review network. Victim reports suppressed. NameSilo and xmrwallet both published on PR Newswire same day.
129 deleted  ·  Jan–May 2026
📁
GitHub Evidence Repository
SHA-256 verified screenshots, full investigation dossier, operator intelligence, case documents, raw scan data. MIT licensed for legal/regulatory use.
github.com/phishdestroy/namesilo-evidence

What Happened

xmrwallet[.]com is a Monero wallet drainer that has been running since approximately 2016. On every login, the site silently transmits the user's private view key to the operator's server via a base64-encoded session_key parameter. Eight PHP endpoints handle the exfiltration. raw_tx_and_hash.raw = 0 ensures all client-side transactions are discarded. The site has never been compromised — the theft code is the product. Estimated victim losses: $10–20M.

PhishDestroy submitted 20+ delivery-receipted abuse reports to NameSilo between 2023 and 2026. No action was taken. On March 13, 2026, NameSilo's official corporate account published a statement calling the operator "the victim," denying all reports ever arrived, and committing in writing to helping him remove his VirusTotal detections. Three other registrars — PDR, WebNic, NICENIC — reviewed the same evidence and suspended the domain within days.

When PhishDestroy published the operator's own emails proving every sentence false, NameSilo used X Gold Checkmark live-support access to lock the @Phish_Destroy research account. X's automated review cleared the account in writing on April 15, 2026. The lock remains in place. NameSilo's only documented response to this investigation: the scammer's domain was quietly transferred to Namecheap.

Exhibit A — NameSilo's official statement · March 13, 2026 · 11,300 views

NameSilo official corporate tweet March 13 2026 — defending xmrwallet operator, denying abuse reports, committing to VirusTotal delisting

Archived: ghostarchive.org/archive/CXXZ0  ·  SHA-256: ad29e1d3d4803ff37c88ef860bef6de9e62f6ce533657f2e5c5460eb2e0b8ebf

NameSilo's Four Claims vs. the Record

"Domain was compromised a few months ago."
Exfiltration code is the product — 8 PHP endpoints, session_key server-side capture, raw_tx_and_hash.raw=0. Operator's own email (Feb 16): no hack claimed, site defended as his work.
FALSE
"Prior to that, we had received no abuse reports."
20+ delivery-receipted reports submitted through NameSilo's own portal, 2023–2026. Public tweet the day before: "9 reports is no joke anymore."
FALSE
"After an extensive review… not involving the registrant."
Operator contacted PhishDestroy Feb 16, defending the site as his own. NameSilo adopted a "compromise" narrative the operator himself never used.
FALSE
"Working with registrant to remove website from VT reports."
Written, published, on their verified corporate account. A registrar actively assisting a confirmed fraud operator in erasing consumer-protection security alerts.
DOCUMENTED — DAMNING

Key Evidence

All screenshots SHA-256 verified. Full index: EVIDENCE_INDEX.md

Operator email Feb 16 2026 — no phishing claim, no hack
Feb 16, 2026 — Operator email: "There is no phishing." No hack claim. Sent 25 days before NameSilo's "compromise" narrative.
PhishDestroy technical reply Feb 16
Feb 16, 2026 — PhishDestroy reply: 8 PHP endpoints documented, escalation notice issued.
X Support email Apr 15 2026 — no violation, restored
Apr 15, 2026 — X Support: "No violation. Restored to full functionality." Account still locked.
Tweet: who is this operator to you?
Mar 16, 2026 — "Who is this operator to you?" 7,900 views. Never answered. Account locked shortly after.
GhostArchive — original confrontation tweet
GhostArchive — archived before suppression. NameSilo's full reply thread, permanent record.
Tweet: NameSilo acting as press secretary for Monero theft operation
Mar 16, 2026 — "NameSilo is acting as press secretary for a Monero theft operation." Tweets now invisible.

Timeline

2016
xmrwallet.com goes live. session_key silently exfiltrates private view key on every login.
2023–2026
PhishDestroy: 20+ delivery-receipted abuse reports → [email protected]. Zero action.
Feb 16, 2026
Operator emails PhishDestroy: "There is no phishing." No hack claim. Site defended as own work.
Mar 12, 2026
PhishDestroy public tweet: "9 reports is no joke anymore."
Mar 13, 2026
NameSilo official tweet (11,300 views): four false claims, offer to scrub VirusTotal. PDR, WebNic, NICENIC: suspended same domain within days.
Mar 16, 2026
PhishDestroy publishes operator emails. @Phish_Destroy account locked via X Gold Checkmark support.
Mar 18, 2026
Full case submitted to ICANN Contractual Compliance.
Apr 15, 2026
X automation: "no violation, restored to full functionality." Lock not lifted.
May 11, 2026
NameSilo legal threat tweet. Zero factual rebuttal. Documented →
May 2026
DMCA filed against this investigation. Keyword/geo suppression detected. xmrwallet domain transferred to Namecheap.
Jun 2026
Zone scan complete: 5,281,415 domains, 87.3% dead/parked. Site remains live. Investigation continues.

For Victims of xmrwallet[.]com

This evidence package is ready to attach to any legal or regulatory filing. MIT licensed — no further authorization needed.

[email protected]

For Regulators & Press

Full case submitted to ICANN March 18, 2026. Raw materials available on request: email headers, PHP endpoint captures, abuse report receipts.

Evidence manifest with SHA-256 hashes: evidence_manifest.json

[email protected]

Mirrors

This investigation is distributed across multiple platforms and protocols. No single point of failure.

● Live site
phishdestroy.eth.limo
IPFS via ENS · censorship-resistant
Arweave (blockchain)
arweave.net/LUuditolJS…
Permanent · on-chain
GhostArchive
ghostarchive.org/archive/CXXZ0
NameSilo's Mar 13 tweet · permanent
IPFS CID
bafybei…65xlq
PhishDestroy Research  ·  phishdestroy.eth.limo  ·  TLP:CLEAR  ·  MIT License

📊 Registration Activity

Daily and monthly new domain registrations. Click any bar to download that day’s list.

📡 Daily New Registrations

New domains registered daily — auto-fetched from registrar zone data every 6h. Download any day as a plain-text blocklist.

Loading…

⏱️ Registration Period Distribution

How long operators register domains for. Longer registration = greater investment = more serious/organised campaign.

🌐 Top TLD Zones

Domain zone distribution with average registration period per TLD. Cheap short-reg TLDs signal bulk throwaway infrastructure.

📡 Deployment Status at Registration

Whether domains had an IP at time of fetch. No IP = registered but not yet deployed (parked, pre-staged, or bulk spam).

💰 Estimated Registrar Revenue

⚠️ Estimates use average public TLD prices. Actual revenue will differ.

🌍 Hosting Geography

IP country at time of domain registration. No IP means domain was not yet deployed when fetched.

🖧 Top Shared IPs

IP addresses hosting the most phishing domains. High-count IPs indicate bulletproof hosting infrastructure shared across campaigns.

💹 Revenue by TLD Zone

Estimated registration revenue split by TLD. Shows which zones generate most income for the registrar from phishing operators.

⚡ Domain Freshness

How old were domains at time of first fetch. Same-day and within-week catches indicate early warning capability.

📈 Registration Burst Days

Days with abnormally high registration volume — likely campaign start dates. Multiple-of-average spikes indicate coordinated bulk registration events.

🕵 Registrant Fingerprinting

Email addresses and phone numbers used to register phishing domains. Repeated contacts across hundreds of domains identify serial abuse operators — direct IOCs for attribution.

Top Registrant Emails
Top Registrant Phones

🎯 Brand & Keyword Heatmap

Brand names and phishing keywords found in domain labels. Shows which ecosystems are most targeted: crypto wallets, exchanges, DeFi protocols, and support scams.

🚨 Serial Registrant IOCs

Registrant emails appearing across multiple phishing domains — direct operator fingerprints. High repeat count = organised, sustained campaign. Import into SIEM/EDR for attribution.

✅ Blocklist Correlation

Cross-reference with the main Destroylist blocklist. Confirmed phishing domains validated by independent verification pipeline. Unranked % = new infrastructure with no prior web presence.

PhishDestroy / Statement

While someone is still looking for the right regulator —
right now, someone is losing their savings.

This is not a complaint to ICANN. ICANN is a technical body — it standardises DNS resolution and allocates IP space. It was not designed to stop wire fraud. The RAA §3.18 acknowledgement requirement exists on paper. In practice, enforcement is a multi-year process of letters and reviews, measured in months while victims are measured in dollars lost per hour. That is the wrong regulator for this problem.

This is about money flows. Every domain in this dataset generated a registration fee. Every renewal generated another. Every day an abuse report sat unanswered, the registrar collected revenue from an active fraud operation. That is not a compliance gap — that is a business model.

Registrars are not passive infrastructure. They are the first and only chokepoint that can kill a fraud domain in 24 hours — no court order required. Their choice not to act is a decision with a revenue motive attached. The "not our jurisdiction" defence does not survive contact with one question: then why are you cashing the check?

The Deliberate Choice

Exclude the newcomers — the inexperienced operator who found a registrar via a Google ad or picked the cheapest option. Organised scam teams don't pick registrars by price. They pick by track record: which registrar ignores abuse reports, which privacy shield survives a takedown attempt, which reseller delivers domains fast with no questions asked.

In CIS-language fraud forums and Telegram channels, registrar recommendations circulate as operational intelligence. There are black-market resellers — "bulletproof domain" brokers — who specifically source from NICENIC, NameSilo, and similar registrars and sell to scam teams pre-configured. These resellers exist because these registrars reliably do not act on abuse reports. That is the product being sold.

When the same operator fingerprints — email clusters, favicon hashes, server stacks — appear across hundreds of domains registered at the same registrar over months: that is not coincidence. That registrar's non-enforcement is documented institutional knowledge in the criminal ecosystem. The question is not why scammers keep buying from NICENIC or NameSilo. The question is why NICENIC and NameSilo keep selling to them.

"We Never Received Any Reports"

PhishDestroy is not the only source. Every major registrar receives abuse reports from APWG, PhishTank, national CERTs, ISACs, brand protection teams, and individual researchers — continuously, in volume. There is no global centralised body that audits whether those reports are actually processed, no mandatory disclosure requirement, no independent verification. A registrar can claim to have received nothing, and there is currently no mechanism to prove otherwise at speed.

NameSilo received documented abuse reports from PhishDestroy alone — more than 20, with full evidence packages, timestamped, on record. Their public position was that they had received nothing. That is not a miscommunication. That is a lie.

The same pattern is predictable across Russian-connected registrars: when confronted, the default response will be "we never received any reports." It is the only legally useful position — because receiving a report and ignoring it is not the same as never receiving one.

Receiving an abuse report and ignoring it is not negligence. Negligence is an accident. Receiving documented evidence of an active fraud domain, taking no action, and collecting the renewal fee is a choice. That choice has a name: complicity.

When NameSilo responded to documented abuse of xmrwallet[.]com — a Monero drainer with $10–20M in confirmed victim losses — by offering to clear its VirusTotal detections rather than suspending the domain: that was not a mistake. That was a choice.

Real audience for this data
FBI IC3 FinCEN Europol EC3 CISA / NCSC Interpol IGCI Journalists Legislators Threat Intel Teams
One Domain Suspended Is Not Enforcement

There is a measurable difference between registrars that treat abuse as a compliance checkbox and those that treat it as a business policy. Responsible registrars — the ones that do not want fraud operators as clients — respond to a confirmed abuse report by suspending the entire account: every domain registered by that operator, in one action. They have seen the account. They know what it is.

The registrars documented in this investigation respond differently. A complaint arrives. One domain — the reported one — may eventually be suspended. The other 200, 500, or 1,000 domains on the same account continue operating. The operator registers new ones the same day. The registrar has seen the pattern. They have chosen to look away.

KYC and reseller vetting requirements exist on paper. In practice they are either absent or trivially bypassed — a formality that provides legal cover without creating any actual barrier to a fraud operator opening an account and registering domains at scale. Our non-public investigation into registrar intake processes, conducted prior to this report, found no meaningful friction at the account-creation stage for the registrars examined here.

Responsible registrar
  • Abuse report received
  • Account reviewed — pattern identified
  • Entire account suspended
  • All domains on account killed
  • Operator loses infrastructure
Complicit registrar
  • Abuse report received (maybe)
  • Account reviewed — pattern ignored
  • One domain suspended
  • 499 domains continue operating
  • Operator registers replacements

Every domain in this dataset is a receipt.

The receipt exists whether the registrar acknowledges the transaction or not.

The Abuse-Ignore Loop
📋
Register domain
Registrar collects fee
📭
Abuse report filed
Ignored / auto-closed
🔴
Domain stays live
Phishing continues
💸
Victim loses money
Real person, real losses
💰
Operator renews domain
Registrar collects again
Ignore = profit.
Not a bug. A feature.