Many of the domains maintained by EstDomains are used in illegal operations

Nov 22, 2008 11:56 GMT  ·  By

Following their decision to terminate the registrar accreditation agreement for EstDomains, ICANN (Internet Corporation for Assigned Names and Numbers) was looking for registrars interested in receiving a bulk transfer of all the domains maintained by the Estonian company. It looks like that registrar will be Directi-owned ResellerClub, which already started sending notification e-mails regarding the upcoming change to EstDomains customers.

EstDomains is a company that up to this point functioned as an ICANN-accredited domain name registrar. Originally founded in Estonia, the company is also incorporated in Delaware, US, and managed to become the work subject of many security groups because it provided domain registration services to numerous cybercriminal gangs. The company was named in multiple reports from the anti-spam group KnujOn or in HostExploit's extensive Atrivo – Cyber Crime USA report.

On October 28, ICANN's Director of Contractual Compliance, Stacy Burnette, sent a letter to EstDomains informing them that ICANN had decided to terminate the company's accreditation agreement, because Mr. Vladimir Tsastsin, listed as EstDomains' President and CEO, was convicted earlier this year by an Estonian court to three years in prison for credit card fraud, document forgery, and money laundering.

ICANN later halted the termination process in light of new documents submitted by Konstantin Poltev, who claimed to be the new CEO of EstDomains since June 2008. Mr. Poltev also claimed that Tsastsin's conviction was not final, being ruled by a circuit court judge, and that an appeal was ongoing. After reviewing the new information, the Internet authority chose to go ahead with the de-accreditation procedure, Poltev and Tsastsin being informed of the final decision on November 7, 2008.

Even though ICANN has yet to announce the registrar that will take over the administration of the approximately 281,000 domain names maintained by EstDomains, ResellerClub, a Directi-owned company has already starting sending e-mails to the owners of those domains, informing them that “ResellerClub, will be taking over their existing Domain Names and SSL Certificate operations”.

“As you might be aware, EstDomains Inc will soon be de-accredited by ICANN and is awaiting its termination in lieu with the Registrar Accreditation Agreement (RAA). The termination will be effective from the 24th November, after which EstDomains will cease its Registrar operations,” reads the e-mail. ResellerClub also points out that since EstDomains was using the LogicBoxes’ OrderBox Technology, the transition will be “fairly smooth”. LogicBoxes is a hosting and domain registration automated solution owned by the Directi Group and implicitly also used by Reseller Club.

Directi, as well as their LogicBoxes service, were previously erroneously linked in several reports to the illegal operations sponsored by EstDomains and Atrivo. After clearing its name, the company has since been active in openly fighting abuse. A recent joint report revealed that the company's work with HostExploit resulted in 175,547 abusive domain names being suspended and an impressive number of 527,000 domains losing the right of using privacy protection (hidden registration details) through Directi's PrivacyProtect service.