# noircas.com — SUSPICIOUS > PhishDestroy identifies noircas.com as a crypto drainer impersonating a crypto service. VirusTotal flags 1/95 vendors. Avoid this domain immediately. ## Summary PhishDestroy identifies noircas.com as an active crypto drainer impersonating a cryptocurrency service. The domain leverages a generic name to deceive users into connecting wallets or entering seed phrases, enabling direct fund theft. No specific drainer kit details are publicly available, but the domain's recent creation and SSL certificate suggest opportunistic impersonation tactics. noircas.com was registered through Hello Internet Corp on February 01, 2026, resolving to IP 172.67.177.180. VirusTotal reports a detection score of 1/95 security vendors, while Google Safe Browsing (GSB) has not flagged the domain. The domain uses a Google Trust Services SSL certificate, which may be leveraged to appear legitimate. These technical indicators point to a newly established, low-profile threat with minimal current exposure. As of the latest assessment, noircas.com remains active with an elevated risk level. Users should block this domain at the network level and avoid any interaction. Remaining risk is moderate due to the domain's recency and low VT detection count, but the threat is evolving. Immediate action is required to prevent potential crypto fund theft. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2026-02-01 17:59:32 - Registrar: Hello Internet Corp - IP: 172.67.177.180 ## Detection Status - VirusTotal: 1 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/f149ef73-3cdf-45e6-9343-5116fd25bb7c - PhishDestroy: https://phishdestroy.io/domain/noircas.com/ - LLM endpoint: https://phishdestroy.io/domain/noircas.com/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/noircas.com/ Last updated: 2026-03-21