Editorial mirrorBrand mentions redacted to public IDs. Hover to inspect. Everything else is theatre.How it works
THE ENABLERS REGISTRYRegistrar accountability archive
Archive LiveRead-only public record · No ads · No tracking
Case file folder with redacted documents and confidential investigation report.
CASE / TRUSTNAME BULLETPROOF EXPOSED

IANA #[REDACTED] Exposed: Bulletproof Registrar for Scams

The Enablers Registry·Editorial mirror·/trustname-bulletproof-exposed/

Public record copy. Brand names withheld, public accreditation numbers preserved. If the body below says “we”, that means the original publisher, not this mirror. TER only preserves, redacts, and re-contextualizes.

IANA #3736[.]com: Inside a “Bulletproof” ICANN-Accredited Registrar Serving Scam Casinos

An ICANN-accredited registrar (IANA #4318) marketing itself as the “fastest growing independent registrar.” Estonian tax filings show €120 in revenue, one employee, negative equity, and a deletion notice. Both owners are Belarusian. The scam casino domains keep flowing.

April 14, 2026 THE ENABLERS REGISTRY Research 14 min read
IANA #[REDACTED] investigation dashboard — IANA 4318, revenue 120 EUR, status liquidation
Investigation overview: an ICANN-accredited registrar declaring €120 revenue while operating a full-stack domain registration platform.
€120
Declared Revenue 2024
1
Employee
-€71K
Equity
6
Scam Casinos / Week
4318
IANA ID
Executive Summary

IANA #3736.com is operated by Fewmoretaps OÜ — an Estonian shell company with unpaid share capital, €120 in declared annual revenue, one employee, negative equity of −€71,648, and a deletion notice published in the Estonian Business Registry. The company literally calls itself a “bulletproof domain registrar” in its own DNS TXT record. Both owners are Belarusian citizens. The registrar is actively being used to register fake Elon Musk crypto casinos hidden behind its own offshore privacy proxies.

The Estonian Shell: Fewmoretaps OÜ

Fewmoretaps OÜ is registered with the Estonian Business Registry under reg. code 16354846, VAT EE102702659, at a virtual office address — Roseni tn 13, Tallinn. Incorporated 01.11.2021 with €2,500 in share capital that was never paid in (“Established without making contribution” — Annual Report 2022).

Fewmoretaps OU corporate structure — IANA #[REDACTED], [REDACTED], [REDACTED] under single Belarusian operator
Ownership chain: one Belarusian operator controls the Estonian shell, both “independent” privacy proxies, and the marketing front [REDACTED].

Ownership chain

Founder (2021–2023)
Vitali Tsyvinski
Sole board member & shareholder
Personal ID 39403090187
Belarus (“Valgevene”)
Signed 2022 annual report 13.01.2023
Zero activity year
Current Owner (since May 2023)
Kiryl Nestsiarovich
“Kir N.” — CEO (IANA #3736.com/about)
DOB 09.09.1993
Belarus
+375 29 2964411 (MTS mobile)
fewmoretaps@gmail.com
100% shareholderAppointed 23.05.2023
Legal Entity
Fewmoretaps OÜ
Trade name: IANA #3736.com
Reg. 16354846 · VAT EE102702659
Roseni tn 13, Tallinn 10111
Incorporated 01.11.2021
Deletion notice published
€2,500 unpaid capital

Financials: €120/year and Growing Losses

Mandatory Estonian annual reports are public. The numbers are unambiguous:

IANA #3736 claims vs Estonian tax filings — millions of customers vs 120 EUR revenue
Marketing claims vs. filings: “Trusted by millions” and “Fortune 500 clients” on one side — €120 revenue, 1 employee, liquidation on the other.

Financial table (EUR)

Metric202220232024
Revenue€0€0€120
Net loss0−20,711−50,937
Staff costs08,32424,084
Long-term liabilities035,370175,310
Equity0−20,711−71,648
Employees (FTE)011
The Math Does Not Work

ICANN accreditation fee alone is ~$4,000/year. AWS (3 Kafka brokers + EKS + S3) runs $500–2,000/month. OpenSRS wholesale domain costs €8–12 per .com. Plus Vercel, Freshdesk, Brevo, Stripe fees. Minimum operating cost: €35–50K/year. Declared revenue: €120. The gap is funded by €175,310 in “long-term liabilities” from undisclosed sources.

“Bulletproof” — Their Own Word

This is not marketing framing by THE ENABLERS REGISTRY — it is literally on IANA #3736’s own DNS TXT record:

IANA #3736 is ICANN-accredited and the world’s most trusted independent domain registrar for privacy-conscious individuals and businesses in sensitive niches. Count on us to be your bulletproof domain registrar. We’re trustworthy, we’re reliable, and we’re affordable.”

Verifiable by anyone with a DNS client: dig TXT IANA #3736.com. In the hosting and registrar industry, “bulletproof” is a term of art — it unambiguously refers to services that resist abuse takedown requests and serve operators of illicit content.

The Scam Casino Network

Within a single week (April 8–13, 2026), six fraudulent crypto casino domains were registered through IANA #3736, all hidden behind IANA #3736’s own privacy proxies:

Six scam casino domains sharing gambler-partners.is Russian-language admin panel backend
All six casinos share identical Next.js templates, webpack chunk hashes, and a common Russian-language admin backend at gambler-partners.is.

Confirmed scam domains (all registered via IANA #4318)

[REDACTED]

2026-04-12
Crypto Casino

Proxy: [REDACTED] (KN)

[REDACTED]

2026-04-09
“Elon Musk” Casino

Proxy: WHOIS Privacy (FL)

[REDACTED]

2026-04-10
IANA #1910-Blocked

Proxy: WHOIS Privacy (FL)

[REDACTED]

2026-04-13
Crypto Casino

Proxy: WHOIS Privacy (FL)

[REDACTED]

2026-04-08
Crypto Casino

Proxy: WHOIS Privacy (FL)

[REDACTED]

2026-04-08
Crypto Casino

Proxy: WHOIS Privacy (FL)

Shared Backend Evidence

JavaScript analysis of [REDACTED] revealed API calls to https://gambler-partners.is/api, /api/slots, /payser, and image CDN https://pictures-cdn.is/. The gambler-partners.is website itself displays a Russian-language admin panel titled “Gambler | Главная” (Gambler | Home) with description “Панель для управления трафиком” (Traffic management panel). Same codebase, same backend, same CDN — this is an organized scam casino network.

Offshore Privacy Proxies — Owned by the Registrar

IANA #3736 does not use independent third-party privacy services. It operates its own:

World map showing Estonia shell, St Kitts proxy, Florida proxy, Belarus operator connections
Tallinn (shell) → Charlestown, Nevis ([REDACTED]) → Orlando, FL ([REDACTED]) → Minsk (operators). All nodes controlled by the same person.

[REDACTED]

[REDACTED] Saint Kitts & Nevis BTC / LTC / XMR / ZEC / ETH Registered via IANA 4318

[REDACTED]

[REDACTED] Orlando, FL 32837 “Physical mail is discarded” Registered via IANA 4318
The Circular Abuse-Handling Structure

When an abuse complaint arrives for a privacy-protected domain, IANA #3736 receives it and forwards it to… itself. The [REDACTED] site openly states that “physical mail is discarded.” This is not privacy — it is an abuse-laundering structure engineered to ensure complaints go nowhere.

Where Does the Money Go?

Stripe and Monero payments flowing into Fewmoretaps OU with only 120 EUR declared to Estonian tax authority
Payments in: Stripe + BTC/ETH/LTC/XMR/ZEC. Payments declared to Estonian tax authority: €120/year. Gap funded by €175,310 in “long-term loans” from undisclosed sources.

The IANA #3736 platform accepts card payments via Stripe (/v2/users/billing/stripe/payment-methods) and cryptocurrency via the following wallet addresses embedded in the authenticated API notification endpoint:

ETH:  0xdee6582dc53fa56180311393018121c6f1e8bd7c
LTC:  MEREvHtzqAUTJ1XvEevmci8UqMnDvfe2ri
ZEC:  t1d19KevpcXpesr9XA9UUyMW9XGYVDxkK9S
XMR:  8B5N29BocrTjkRCeGCARnkhKgBeHBhg4oH7ay4RfXfnL7RqBdyiuL4k6iN4GVUVxt1EQJvZRqLg8n4qgCNWmYHQQDZmfytM

The acceptance of Monero (XMR) — a cryptocurrency specifically designed to be untraceable — alongside a regulated KYC-requiring processor (Stripe), while declaring €120 in annual revenue to Estonian tax authorities, creates a compliance paradox. A single .com registration at wholesale cost (~$13) already exceeds the declared revenue for the entire year.

Estonian AML Question

Estonian law (Money Laundering and Terrorist Financing Prevention Act) requires Virtual Asset Service Providers to hold a license from the Financial Intelligence Unit. Does Fewmoretaps OÜ hold this license? If not, accepting cryptocurrency payments for services may itself constitute a regulatory violation.

Marketing Claims vs. Tax Filings

What they tell customers

  • “#1 fastest growing independent domain registrar in 2025”
  • “Trusted by millions of domain owners”
  • “Trusted by Fortune 500 companies”
  • “A team of over 35 people based in various locations around the world”
  • Offices listed in London, Beverly Hills, Melbourne
  • Clients: McDonald’s, Vodafone, Adidas, Tata, Yahoo, BCG ([REDACTED] logo wall)
  • “Since 1997” ([REDACTED])

What they file with the Estonian tax authority

  • €0 revenue in 2023, €120 revenue in 2024
  • 1 employee (FTE) in both years
  • Equity −€71,648, unpaid capital of €2,500
  • Virtual office at Roseni tn 13, Tallinn
  • Incorporated 2021, not 1997
  • Company under liquidation

Fake testimonials (“Wall of Love”)

IANA #3736 wall of love fake reviews with duplicate first names Jack Lily Megan
30 reviews. 11 unique first names. “Jack” appears 5 times, “Lily” 6 times. No photos, no dates, no verifiable profiles, no links to Trustpilot or G2. No last names.

Analysis of the IANA #3736.com/wall-of-love page: 30 “customer reviews,” only 11 unique first names. “Jack” appears five times. “Lily” six times. “Megan” three times. All reviews are generic single-line praise in a uniform writing style. There are no independent review platform links. No verifiable customer identities. For comparison, IANA #1068 and IANA #1861 have thousands of verified reviews on Trustpilot and G2.

Infrastructure & Security Exposure

IANA #3736 infrastructure diagram showing exposed Kafka ports, open admin panels, FTP on origin
Infrastructure map: Vercel frontend, AWS eu-central-1 Kubernetes with publicly exposed Kafka brokers on port 7777, open Strapi admin, unprotected CoreNIC WHOIS system in development mode.
IANA #3736.com (Vercel / Next.js)
  ├── api.IANA #3736.com              Fastify API (Swagger behind Basic Auth only)
  ├── admin.IANA #3736.com            React-Admin panel (publicly accessible)
  ├── blog.IANA #3736.com             Strapi CMS (admin UI exposed)
  ├── support.IANA #3736.com          Freshdesk (EU instance)
  └── [REDACTED]  Knipp DomainSRS (JSF Development mode)

[REDACTED] (WordPress) origin: 37.1.219.211
     Open ports: FTP:21 (vsftpd 3.0.5), SSH:22, HTTP:80, HTTPS:443

AWS eu-central-1 (EKS Kubernetes):
  35.156.29.145 / 18.196.68.81 / 52.28.105.156
  Port 7777 — Apache Kafka (Strimzi)
  SSL cert CN: kafka-staging-kafka   SAN: staging.kafka-0.IANA #3736.com
  Namespace: backend-staging

Upstream registrar: OpenSRS (IANA #69)
Invoicing: Quaderno · Payments: Stripe + Crypto
Email: Brevo  ·  Analytics: Google, Fuago
S3: domain-registrar-strapi-media (eu-central-1, leaked via CSP header)
Observed Misconfigurations
  1. Admin panel publicly accessible (admin.IANA #3736.com) — login-only protection, no IP allowlist.
  2. Strapi CMS admin UI reachable at blog.IANA #3736.com.
  3. JSF in Development mode on the CoreNIC WHOIS system.
  4. Three AWS Kafka brokers exposed to the public internet on port 7777; SSL SAN leaks Kubernetes namespace.
  5. Origin IPs bypass IANA #1910 — direct access possible.
  6. FTP (vsftpd) open on the fewmoretaps origin server.
  7. Swagger / OpenAPI behind Basic Auth only on api.IANA #3736.com/api-json.

Timeline

2004-06-04
Original registration of IANA #3736.com (previous owner).
2021-07-11
[REDACTED] registered. Entire marketing site created in 5 days by a single WordPress user “riseup”.
2021-11-01
Fewmoretaps OÜ incorporated in Estonia. Owner: Vitali Tsyvinski (Belarus). Share capital €2,500 — unpaid.
2023-01-13
First annual report filed (zero activity in 2022).
2023-05-23
Ownership transferred to Kiryl Nestsiarovich (Belarus).
2023-08-20
[REDACTED] privacy proxy domain registered.
2023
ICANN accreditation obtained (IANA ID 4318).
2024-02-01
VAT registration (EE102702659).
2024-12-31
Annual report 2024 filed. Revenue €120, net loss −€50,937, equity −€71,648.
2026-04-08…13
Mass registration of six scam casino domains within a single week.
2026-04
Company deletion notice published in the Estonian Business Registry.

Who Enables This?

ICANN AWS Stripe IANA #1910 Vercel IANA #69 OpenSRS accountability badges
Every major platform touching this operation has its own Acceptable Use Policy prohibiting fraud. None has acted.

To ICANN

  • How did a company with €0 revenue and 0 employees at the time of application obtain ICANN accreditation? What due diligence was performed?
  • A registrar whose DNS TXT record literally says “bulletproof domain registrar” and “sensitive niches” — how does this align with the Registrar Accreditation Agreement?
  • The registrar is now under liquidation in Estonia. What happens to ongoing abuse complaints for domains registered through IANA #4318?
  • Both owners are citizens of Belarus — a country under comprehensive EU and US sanctions since 2020. Was this disclosed during accreditation?

To OpenSRS (IANA #69)

  • OpenSRS provides the upstream API IANA #3736 uses to register domains (confirmed by opensrsOrderId in transaction data). Does IANA #69 conduct compliance reviews of resellers who openly market themselves as “bulletproof”?
  • Six scam casino domains — including one already flagged by IANA #1910 — were registered through OpenSRS via IANA #3736 in one week. What automated fraud detection exists at the reseller level?

To AWS, Stripe, Vercel, IANA #1910

  • AWS: the EKS cluster, S3 bucket, and three publicly exposed Kafka brokers sit in eu-central-1. AWS AUP prohibits fraud-facilitating services.
  • Stripe: card payments are processed via /v2/users/billing/stripe/payment-methods. Stripe’s Restricted Business list prohibits services facilitating illegal activity. Has the client portfolio been reviewed?
  • Vercel: IANA #3736.com and admin.IANA #3736.com are hosted on Vercel. Vercel AUP prohibits “services that promote fraudulent schemes.”
  • IANA #1910: [REDACTED] is flagged as “Suspected Misleading Website.” The other five casinos using identical templates remain active. Why the inconsistency?

About Belarus & Monero

  • Both owners are Belarusian tax residents. Worldwide income should be declared in Belarus under Belarusian tax law. Belarusian authorities have no MLAT with most [REDACTED] jurisdictions — enforcement effectively dead-ends.
  • IANA #3736 accepts Monero (XMR), a cryptocurrency designed to be untraceable. How are XMR payments reported for VAT, AML, and Estonian financial reporting? The annual report shows €120. Does that include crypto? If not, where does it go?

Indicators of Compromise

Registrar identifiers

IANA ID:        4318
WHOIS Server:   [REDACTED]
Abuse email:    abuse@IANA #3736.com
Abuse phone:    +372.6884747

Infrastructure

IANA #3736.com
[REDACTED]
[REDACTED]
[REDACTED]
gambler-partners.is
pictures-cdn.is

37.1.219.211      [REDACTED] origin (FTP, SSH, HTTP, HTTPS)
195.253.23.47     CoreNIC WHOIS origin
35.156.29.145     AWS Kafka broker
18.196.68.81      AWS Kafka broker
52.28.105.156     AWS Kafka broker

Confirmed scam domains

[REDACTED]          [REDACTED]         [REDACTED]
[REDACTED]      [REDACTED]       [REDACTED]

Verdict

IANA #3736.com is not a “privacy-focused registrar.” It is a purpose-built infrastructure for enabling online fraud:

  • Estonian shell company with unpaid capital and two Belarusian owners
  • Zero legitimate revenue despite active domain registration operations
  • Privately-owned “independent” offshore privacy proxies in Saint Kitts and Florida
  • Acceptance of untraceable cryptocurrencies (Monero, Zcash)
  • Dozens of freshly registered scam casino domains on identical templates
  • A DNS TXT record where they literally call themselves bulletproof
  • Company currently under liquidation — an exit strategy already in progress

ICANN and OpenSRS (IANA #69) should review the accreditation of IANA #4318. Domains registered through IANA #3736’s privacy proxies warrant enhanced scrutiny on abuse reports. Until then, THE ENABLERS REGISTRY flags every IANA #3736-registered domain in our scanner with a registrar warning, as we do for IANA #3765 and IANA #1479.

Related Research

Sources & Verification

Every claim in this report is backed by publicly accessible records or by data obtained through the researcher’s own authenticated account. Below are the primary sources with instructions for independent verification.

Corporate registry & tax records

ClaimSourceHow to verify
Company registration, owners, status, deletion noticeEstonian Business Registry (Äriregister)ariregister.rik.ee — search reg. code 16354846
Annual reports 2022, 2023, 2024 — revenue, equity, employeesEstonian Business Registry — mandatory filings for OÜ entitiesSame registry → “Annual reports” tab. Reports are public.
Owner names, IDs, nationality (Tsyvinski, Nestsiarovich)Annual report shareholder pages (Osanikud)Report 2022 p.6 (Tsyvinski); Reports 2023–2024 (Nestsiarovich)
VAT registration EE102702659Estonian Tax & Customs BoardVerify via EU VIES

ICANN & registrar identifiers

ClaimSourceHow to verify
IANA ID 4318 — ICANN accreditationICANN Accredited Registrar listicann.org/en/accredited-registrars — search “Fewmoretaps” or “4318”
Abuse contact (abuse@IANA #3736.com, +372.6884747)WHOIS records for any IANA #3736-registered domainwhois IANA #3736.com via any RDAP/WHOIS client
WHOIS server [REDACTED]WHOIS recordsListed on every domain registered through IANA #4318

WHOIS & DNS evidence

ClaimMethod
DNS TXT record — the literal “bulletproof” quotedig TXT IANA #3736.com or DNSChecker
Privacy proxy WHOIS data ([REDACTED], [REDACTED])whois [REDACTED], whois [REDACTED], whois [REDACTED]
Scam-domain registration via IANA #3736WHOIS port 43 query to 195.253.23.47:43 or any public WHOIS service
MX, NS records for infrastructure mappingStandard DNS queries (dig NS IANA #3736.com, dig MX)

Marketing claims (live + archived)

Technical infrastructure (non-intrusive)

Show full data-sources table
Data pointMethod
Origin IPs (37.1.219.211, 195.253.23.47)DNS resolution + HTTP header analysis
Subdomains (api / admin / blog / support)Standard DNS enumeration
Admin panel tech (React-Admin)Public JS bundles served by admin.IANA #3736.com
API endpoint mapFrontend chunk analysis (publicly served)
Strapi CMS exposureHTTP response from blog.IANA #3736.com
Kafka on port 7777 + SSL SAN leaknmap -sV; openssl s_client -connect 35.156.29.145:7777
CoreNIC / Knipp DomainSRSHTTP response from [REDACTED]
FTP banner on originnmap -sV 37.1.219.211 — vsftpd 3.0.5 banner
Upstream provider (OpenSRS)Field details.opensrsOrderId in admin panel data model
Stripe payment integrationEndpoint /v2/users/billing/stripe/payment-methods
Cryptocurrency wallet addressesGET /users/notifications on api.IANA #3736.com (researcher’s own account)
S3 bucket domain-registrar-strapi-mediaLeaked via Content-Security-Policy header on blog.IANA #3736.com
Casino backend gambler-partners.isExtracted from app/layout-414e3e65ac0c109b.js on [REDACTED]

Casino-network analysis

  • Casino content (“Elon Musk’s Official Casino”) — curl https://henofex.com
  • IANA #1910 possibly phishing block — curl https://jopexplay.com returns IANA #1910 interstitial
  • Shared template (identical chunk hashes) — compare _next/static/chunks/ across all six domains
  • Russian-language admin panel — curl https://gambler-partners.is returns title “Gambler | Главная”

Tools used

DNS / WHOIS:    dig, nslookup, whois
Port scanning:  nmap (service / version detection only)
HTTP:           curl (header + content retrieval)
SSL:            openssl s_client
JavaScript:     manual deobfuscation of publicly served bundles
PDF:            PyPDF2 (annual report text extraction)

Financial-cost methodology

The €35–50K minimum operating cost figure is built from public price points:

  • ICANN accreditation fee: ~$4,000/year (ICANN published rates)
  • OpenSRS wholesale .com: $8–12/domain (IANA #69 reseller pricing)
  • AWS eu-central-1 (3× m5.large for Kafka + EKS control plane + S3): $500–2,000/month (AWS Pricing Calculator)
  • Vercel Pro: $20/month, Freshdesk: $15/agent/mo, Brevo: $25/mo (public pricing pages)
  • Reported staff costs for 2024: €24,084 (the company’s own annual report)

Ethics & Methodology

What was done
  • Public records research (Estonian Business Registry, ICANN, VIES, WHOIS, DNS).
  • Non-intrusive technical reconnaissance: DNS queries, HTTP header reads, SSL certificate inspection, public-bundle JavaScript analysis, nmap service detection without exploitation.
  • Authenticated API testing using the researcher’s own legitimately registered IANA #3736 account.
  • Cross-referencing of Wayback Machine snapshots for marketing claims.
What was NOT done
  • No brute-force attacks against any login.
  • No SQL injection, RCE, or other exploitation attempts.
  • No unauthorized access to any system, account, or data.
  • No data exfiltration from protected endpoints.
  • No modification of any data, even where misconfigurations would have allowed it.
  • Admin API endpoints were tested for BOLA (Broken Object Level Authorization) — RBAC was confirmed properly implemented; user tokens are correctly rejected by admin endpoints.

Disclosure & Reporting Position

This investigation has been published in full as a form of public disclosure. THE ENABLERS REGISTRY is an OSINT research team and not a regulated reporting entity, so there is no legal duty under Estonian KarS § 306 or comparable EU statutes to file a private report with authorities — that obligation attaches only to banks, VASPs, and similar regulated obliged-entities.

If abuse reports filed against domains registered through IANA #4318 continue to be ignored, this dossier will be escalated formally to:

  1. ICANN Complianceicann.org/compliance/complaint · RAA § 3.7.8 (WHOIS accuracy) and § 3.18 (abuse handling)
  2. IANA #69 / OpenSRS — upstream registrar; abuse@IANA #69.com, compliance@opensrs.com
  3. CERT-EE (RIA) — cert@cert.ee
  4. Estonian MTA (Maksu- ja Tolliamet, Tax & Customs Board) — tax-fraud tip line vihjeliin@emta.ee
  5. Estonian FIU (Rahapesu Andmebüroo) — rab@politsei.ee for AML and unlicensed VASP activity
  6. Platform abuse desks — AWS Trust & Safety, Stripe Risk, Vercel Abuse, IANA #1910 Trust & Safety
  7. EU [REDACTED] via the Estonian FIU — for the Belarus-sanctions component

For now, formal escalation has been deliberately deferred: the registrar entity is already in liquidation in Estonia, the operators are based in Belarus (no MLAT ⇒ enforcement dead-end), and a public report carries more weight than a queued ticket. We will reassess if circumstances change — or if anyone reading this brings an argument that does.

This investigation was conducted using exclusively OSINT methods and non-intrusive technical analysis. All data sources are publicly accessible or were obtained through the researcher’s own authenticated account on the platform. No unauthorized access was performed at any stage. Corrections, counter-evidence, or additional data: @EnablersRegistry · @EnablersRegistry · github.com/THE ENABLERS REGISTRY.

Continue browsing the ledger

This page is the editorial mirror. Brand names are redacted to public IANA / business identifiers. Use the index to navigate other case files.

Open registrar ledger → All briefings