# PhishDestroy threat dossier — novaedge-innovations.com ================================================================ Fetched: 2026-07-30 12:01:56 UTC Canonical: https://phishdestroy.io/domain/novaedge-innovations.com/ ## VERDICT ---------------------------------------------------------------- CRITICAL THREAT — DO NOT VISIT Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Investment Scam ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 5/91 security vendors flagged this domain Flagging vendors: alphaMountain.ai, CRDF, Gridinsoft, Netcraft, SOCRadar AlienVault OTX: 2 pulses (threat-intel feed mentions) Public blocklists: listed on 1 independent blocklist ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 192.142.53.230 (NL, Amsterdam) ASN: AS214036 Ultahost, Inc. Hosting org: Ultahost Inc Registrar: Ultahost, Inc. Nameservers: ns3.mywebvps2.com, ns4.mywebvps2.com Registered: 2025-09-06 Expires: 2026-09-06 Page title: novaedge-innovations.com | Investment Platform with a Business Opportunity ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / YE2 Expires: 2026-10-08 Status: INVALID chain Fingerprint: e5c19118cca2e23c94a9a05bc524d579d4a5c816b02fd6ffc2d24d181cb6c3fd Subject Alternative Names (related infrastructure — often same operator): - www.novaedge-innovations.com ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2025-09-06 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-07-27 06:51:46 UTC (by PhishDestroy tracker) First reported: 2026-07-27 08:21:07 UTC (abuse notice filed) Last verified: 2026-07-30 12:30:22 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019fa2c1-e6a7-76ba-8ffc-d6906001c8e0/ URLQuery: https://urlquery.net/report/1f32d615-ed5b-40cc-8a85-d1d15ad442b0 Wayback Machine: https://web.archive.org/web/*/novaedge-innovations.com crt.sh CT logs: https://crt.sh/?q=%25.novaedge-innovations.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=novaedge-innovations.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/novaedge-innovations.com URLhaus: https://urlhaus.abuse.ch/host/novaedge-innovations.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-07-27 06:54:43 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] novaedge-innovations.com - Generic Phishing Investigation The domain novaedge-innovations.com was registered through Ultahost, Inc. on 06 September 2025 and remains active as of the 27 July 2026 report date. Infrastructure analysis shows the domain resolves to the IPv4 address 192.142.53.230 and is served by the authoritative name servers ns3.mywebvps2.com and ns4.mywebvps2.com. The IP address is not linked to any publicly disclosed corporate network and appears to be hosted on a generic VPS platform, which is a common pattern for short‑lived phishing infrastructure. VirusTotal has recorded a single positive detection out of 91 scanned security vendors, indicating that at least one AV engine has identified malicious behavior associated with the domain. The domain is also listed on one external security blocklist and has been actively blocked by the PhishDestroy mitigation service, confirming that threat‑intelligence feeds consider it malicious. The threat type is cataloged as generic phishing, and the risk rating is high, reflecting the combination of active hosting, a recent creation date, and confirmed detections. No public evidence of SSL certificate details, HTTP response codes, page title, or landing‑page content has been disclosed, so the specific lure or credential‑harvesting mechanism cannot be described at this time. Defenders should add novaedge-innovations.com to URL filtering and DNS sink‑hole rules, monitor outbound traffic for connections to 192.142.53.230, and ensure that any corporate email gateways block messages that reference the domain. Because the domain is already present on at least one blocklist, integrating that list into existing security appliances will provide immediate coverage. Continuous re‑scanning of the domain via multi‑engine services is advised to capture any new detections that may arise as the campaign evolves. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260727-25DB76 Favicon MD5: f9975b80c6aef147c48d36a2c9d6447d TLS cert SHA-256: e5c19118cca2e23c94a9a05bc524d579d4a5c816b02fd6ffc2d24d181cb6c3fd ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (operator takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/novaedge-innovations.com/ JSON API: https://api.destroy.tools/v1/check?domain=novaedge-innovations.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: independent open-source threat-intelligence platform. Tracked: 195,633 domains (83,358 alive under monitoring, 110,015 confirmed takedowns/dead). Site: https://phishdestroy.io