# ws.notvian.com — SUSPICIOUS > Caution! ws.notvian.com is a crypto drainer phishing site impersonating Notvian with 0/95 detections. Verify safety on PhishDestroy immediately to protect your. ## Summary PhishDestroy identifies ws.notvian.com as a crypto drainer phishing domain actively targeting cryptocurrency users. This domain employs deceptive tactics to mimic legitimate services, specifically impersonating Notvian, a known platform in the crypto space. The site likely incorporates a drainer kit designed to siphon funds from victims' wallets upon interaction. Technical analysis suggests this is a high-priority threat due to its active status and potential for financial harm. Domain forensic analysis reveals critical technical indicators: VirusTotal detects this domain with 0/95 detections, indicating it remains under the radar of most security vendors. Registered through Arsys Internet via NICLINE.COM, the domain resolves to IP 5.56.62.150 and was created on June 01, 2022. It utilizes a Let's Encrypt SSL certificate for a false sense of legitimacy. Google Safe Browsing (GSB) has not yet flagged this domain, and no current blocklist entries were found. These indicators suggest a newly emerging or carefully crafted threat designed to evade detection. Current status of ws.notvian.com is classified as active, with an under-investigation risk level. PhishDestroy has flagged this domain as a crypto drainer phishing site, and immediate verification is recommended for users who may have encountered it. Response actions include continued monitoring and potential takedown requests to hosting providers. Despite these efforts, the remaining risk is moderate due to the domain's recent creation, low detection rate, and active operation. Users are advised to avoid interacting with this domain and verify its safety status on PhishDestroy before proceeding with any transactions or data input. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2022-06-01 07:09:42 - Registrar: Arsys Internet, S.L. dba NICLINE.COM - IP: 5.56.62.150 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/570f7126-436c-435b-961a-3035dde43532 - PhishDestroy: https://phishdestroy.io/domain/ws.notvian.com/ - LLM endpoint: https://phishdestroy.io/domain/ws.notvian.com/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/ws.notvian.com/ Last updated: 2026-03-28