Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 17 days has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
norvost[.]org
“Norvost | Decentralized Web3 Gambling Site with Provable Trust”
संग्रहीत अवलोकन
देखा गया शीर्षक अंतर
साक्ष्य सारांश
The domain norvost.org is currently flagged as an active brand impersonation threat targeting crypto casino and gambling platforms. Analysis indicates this site mimics decentralized Web3 gambling services, presenting itself under the title 'Norvost | Decentralized Web3 Gambling Site with Provable Trust.' The domain operates as a high-risk impersonation vector, likely designed to deceive users into engaging with fraudulent gambling activities or disclosing sensitive credentials. Infrastructure analysis reveals the domain was registered through NAMECHEAP INC on June 30, 2026, an anomalous creation date suggesting potential domain spoofing or incorrect registry data. It resolves to the IP address 188.114.96.3, a Cloudflare-associated endpoint commonly used to obfuscate hosting origins. The SSL certificate is issued by Google Trust Services, providing a veneer of legitimacy. Detection metrics indicate that 2 of 95 security vendors on VirusTotal have flagged this domain as malicious, a relatively low detection rate that may reflect evasion techniques or recent activation. No blocklist entries or trust scores from additional threat intelligence platforms were identified at the time of assessment. Current status confirms norvost.org remains operational, serving content designed to impersonate legitimate crypto gambling platforms. Users and network administrators are advised to treat this domain as a confirmed threat vector. Immediate mitigation steps include blocking the domain and its resolving IP (188.114.96.3) at firewall and DNS levels, implementing browser-based warnings for internal users, and monitoring for related phishing campaigns leveraging similar naming conventions. Organizations in the gambling or cryptocurrency sectors should issue alerts to customers regarding this impersonation attempt and reinforce multi-factor authentication for account access.
भेजे गए प्रमाण का स्नैपशॉट
- भेजा गया
- लेज़र रिकॉर्ड
- 1
- केस आईडी
PD-1784892546-norvost.org- PDF दस्तावेज़
- PDF प्रमाण
रिपोर्ट इतिहास 1
- रिपोर्ट 1 ⚠️ ESCALATION #1 (0h active): Phishing - norvost[.]org
Data Coverage
धमकी प्रतिक्रिया पाइपलाइन
ब्लॉकलिस्ट कवरेज
10 निगरानी वाले बाहरी स्रोत · संग्रहीत स्नैपशॉट 11/08/2026
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणDNS, TLS नाम और समय-मुद्राएँ
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
तकनीकें
4 उच्च-विश्वसनीयता वाली तकनीकें पहचानी गईं
वायरसटोटल विश्लेषण
साइट प्रदर्शन विश्लेषण
Google PageSpeed Insights — mobile performance audit of norvost.org · checked Jul 6, 2026
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।