thenovelo.app
“Novelo”
The domain thenovelo.app is currently active and has been classified as a generic phishing site with an elevated risk rating.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Resumen de las pruebas
The domain thenovelo.app is currently active and has been classified as a generic phishing site with an elevated risk rating. Infrastructure analysis shows that the domain resolves to the IPv4 address 216.150.16.129, which is the sole hosting endpoint observed in public scans. The domain is listed on one external blocklist and is actively blocked by the PhishDestroy filtering service.
VirusTotal reports that four of ninety‑one scanned security vendors have flagged the domain, indicating a modest but non‑trivial detection rate across the ecosystem. No additional intelligence such as registrar details, ASN, or SSL certificate metadata is available in the supplied data set, and the page title or any brand‑specific impersonation cues have not been disclosed. Consequently, while the presence of multiple detections and blocklist entries confirms malicious intent, the precise target brand or credential‑harvesting technique remains indeterminate.
Defenders should prioritize adding thenovelo.app to domain‑allow‑lists for web proxy and DNS filtering solutions, enforce blocklisting in email security gateways, and monitor outbound traffic for connections to 216.150.16.129. Continuous re‑scanning with multi‑engine services is advised to capture any evolution in the payload or hosting infrastructure. Organizations that employ strict outbound filtering should consider immediate denial of any HTTP or HTTPS requests to the domain until further forensic analysis clarifies the scope of the campaign.
Forensic History & Detection Timeline
-
Threat First Observed Aug 2, 2026 · 07:21 UTCDomain ingestion complete. Initial state is marked as unknown pointing to IP
216.150.16.129.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Evasion analysis
Cloaking & traffic-distribution check
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
- Stored cloaking flag
- Not yet scanned
- Last cloaking scan
- Server header seen by scanner
Vercel
Scanner note: redirect: raw=redirect_307; http=307; via=https_proxy; location=https://www.thenovelo.app/; server=Vercel
Captura guardada · 3 sources
Inteligencia de dominios
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologías · 9 identified
Análisis de VirusTotal
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.