That's incredible. That "[the domainname] matched the pattern of command and control (C2) domain names generated by a malware family named Nymaim" was enough to get it sinkholed is nuts. There should be a fair bit of manual checks here before applying this sort of death penalty.
Take my username. I actually got targeted by my bank some years ago for a similar reason: "crypto" surely means you're doing crypto-currencies, right?, so you must register as a money services business (MSB)! Uh, no, nothing of the sort, and thankfully I was able to disabuse them of the notion that I had anything to do with crypto-currencies. (Indeed, I'm vehemently opposed to proof-of-work currencies, and as for proof-of-stake, why not just do double-spend detection and leave it at that?)