# PhishDestroy threat dossier — novadispatchservice.xyz ================================================================ Fetched: 2026-07-27 15:06:53 UTC Canonical: https://phishdestroy.io/domain/novadispatchservice.xyz/ ## VERDICT ---------------------------------------------------------------- HIGH THREAT — malicious activity confirmed Composite threat score: 62/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 2/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, Forcepoint ThreatSeeker AlienVault OTX: 4 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 162.245.237.212 (US, Tukwila) ASN: AS27323 Wowrack.com Hosting org: CENTRIOHOST-LLC Registrar: OwnRegistrar, Inc. Nameservers: dns1.webproserver.com, dns2.webproserver.com Registered: 2025-10-09 Expires: 2026-10-09 Page title: Nova Dispatch Service HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / R12 Expires: 2026-08-26 Status: INVALID chain Fingerprint: dd7b4ac974b65cfb63c35d07d00a054c4fab75adf3d82b237dd3b78401c969b5 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2025-10-09 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-27 09:48:19 UTC (by PhishDestroy tracker) First reported: 2026-07-27 11:58:08 UTC (abuse notice filed) Last verified: 2026-07-27 16:20:20 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fa320-25a2-7136-bdd1-cc80cd9c5f49/ URLQuery: https://urlquery.net/report/6e394959-6e89-41d5-964e-f5a758d7a068 Wayback Machine: https://web.archive.org/web/*/novadispatchservice.xyz crt.sh CT logs: https://crt.sh/?q=%25.novadispatchservice.xyz Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=novadispatchservice.xyz AlienVault OTX: https://otx.alienvault.com/indicator/domain/novadispatchservice.xyz URLhaus: https://urlhaus.abuse.ch/host/novadispatchservice.xyz/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 09:48:47 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] novadispatchservice.xyz Safety Check — Phishing Detected This domain was registered on 9 October 2025 through OwnRegistrar, Inc. The authoritative name servers are dns1.webproserver.com and dns2.webproserver.com, with an additional null entry that may indicate a placeholder configuration. DNS resolution points to the IPv4 address 162.245.237.212, which remains active as of the assessment date. The domain is listed on a public phishing blocklist; PhishDestroy has added it and actively blocks traffic to the host. VirusTotal scanning reports that 2 of 91 security vendors have flagged the domain, providing a low but non‑zero detection rate. No further data from Safe Browsing, OTX, or other reputation services is present in the current intelligence set. The recent creation date, combined with the presence on a blocklist and modest detection count, aligns with typical short‑lived phishing campaigns that aim to evade long‑term detection. Concrete details such as SSL certificate information, HTTP response codes, page titles, or evidence links have not been disclosed, leaving the exact content and lure employed by the site unknown. Defenders should proactively block DNS resolution to 162.245.237.212 at the network perimeter and add novadispatchservice.xyz to internal blocklists and email security policies. Continuous re‑query of multi‑engine scanners, including VirusTotal, is recommended to capture any emerging detections. Organizations should monitor outbound traffic for attempts to contact the domain, quarantine or reject emails containing links to it, and treat any credential submissions to the site as potentially compromised, prompting affected users to reset passwords and review account activity. [Updates since narrative was generated:] - WHOIS creation date: 2025-10-09 ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260727-F25AF1 Favicon MD5: fa3f3375cb692f4b3c1c002017b40591 TLS cert SHA-256: dd7b4ac974b65cfb63c35d07d00a054c4fab75adf3d82b237dd3b78401c969b5 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/novadispatchservice.xyz/ JSON API: https://api.destroy.tools/v1/check?domain=novadispatchservice.xyz Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 205,660 domains (80,832 alive under monitoring, 123,797 confirmed takedowns/dead). Site: https://phishdestroy.io