nowa.finance
“NOWA – AI-Powered Crypto Price Prediction Platform | Predict & Earn with $NOW Token”
Evidence Summary
The domain nowa.finance, impersonating Binance, has a high threat score of 70/100 and is currently down. It has been detected as malicious by 1 out of 95 security vendors, with Seclookup being the only vendor to flag it. The domain is listed on one public blocklist, but it is not flagged by Google Safe Browsing, indicating limited visibility in mainstream threat detection systems. It is associated with Wallet Connect Abuse, suggesting a targeted crypto scam.
Registered with Cloudflare, Inc. in the US, the domain's first-seen date is November 16, 2025. The hosting IP is 104.21.46.136. The lack of additional detection from other vendors and the current site status reinforces the need for vigilance in monitoring this domain's potential reactivation. Block the domain at the perimeter and submit a report to the registrar's abuse desk for further investigation.
Forensic History & Detection Timeline
-
VirusTotal Detections Update Mar 10, 2026 · 03:17 UTCVirusTotal scanner detections updated from 1 to 2. Added scanner alerts: SOCRadar.
Threat Response Pipeline
Public Blocklist Status
Evasion analysis
Cloaking suspected: scanner and victim titles differ
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
- Stored cloaking flag
- Not observed
- Cloaking score
- 0/6
- Last cloaking scan
- Server header seen by scanner
cloudflare
Scanner note: alive_content: raw=ok; http=200; via=https_proxy; server=cloudflare
Stored Capture · 2 sources
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies · 3 identified
VirusTotal Analysis
Archived Evidence
Lookalike domains
187 stored lookalike domains
Show all (88)
Showing 100 of 187
Community reports
Reported by 1 community member, first seen Nov 16, 2025
- Stored reports
- 1
- Unique reported URLs
- 1
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive