noawin[.]com
Pemeriksaan phishing dan keamanan noawin.com
“Noawin: Most Popular Online Crypto Casino Based on Blockchain”
noawin.com — Terselubung · dapat dijangkau (HTTP 666). Peniruan identitas merek: Genericcrypto; Jenis penipuan: Brand Impersonation. Ringkasan bukti: VirusTotal 5/94 (CRDF, G-Data, Gridinsoft, SOCRadar, Sophos); URLQuery 2 alerts; URLScan malicious verdict; Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); cloaking observed; PhishDestroy score 79/100. Registrar: Fewmoretaps OU d/b/a T….
Analisis terperinci PhishDestroy AI di bawah tetap berbahasa Inggris untuk menjaga catatan forensik asli.
PhishDestroy identifies noawin.com as a recently activated domain engaging in credential-harvesting operations disguised as a Microsoft 365 login portal. The infrastructure exhibits hallmarks of a generic phishing campaign, including a newly registered domain, rapid SSL provisioning, and hosting on a bulletproof IP space associated with prior malicious activity. While no specific brand impersonation was confirmed in the initial analysis, the domain’s recent creation and low detection profile suggest it is part of a fast-moving campaign targeting enterprise users under the guise of a legitimate Microsoft authentication flow. The drainer kit appears to be a basic HTML-based credential collector with client-side validation, likely distributed via spear-phishing emails leveraging urgency or executive impersonation tactics. This domain was flagged by 3 out of 95 security vendors on VirusTotal, indicating a low initial detection rate that may allow the campaign to slip past perimeter defenses. The domain was registered on April 12, 2026, through Fewmoretaps OU d/b/a Trustname.com, a registrar known to offer privacy protection services that can obscure true ownership and hinder takedown efforts. It resolves to IP address 188.114.97.3, a segment historically linked to bulletproof hosting providers and previously flagged in relation to malware distribution and C2 infrastructure. The domain is protected by a Let's Encrypt SSL certificate, which adds legitimacy to phishing pages and may enable bypass of browser-based security controls. Google Safe Browsing (GSB) has not yet blacklisted this domain, and it remains absent from major threat intelligence feeds beyond the limited VT detection. With only four confirmed detections across public sandboxes and security platforms, noawin.com represents a high-evasion threat with elevated risk to organizations lacking advanced email and web filtering. As of this advisory, noawin.com remains active and unblocked across most threat intelligence platforms, including GSB. Immediate response actions include adding the domain and resolving IP to organizational blacklists, inspecting DNS resolution logs for internal queries, and scanning email gateways for messages referencing Microsoft 365 login pages. Given the domain’s recent registration (within 7 days), proactive hunting for Indicators of Compromise (IoCs) such as the SSL thumbprint, page hash, or email sender domains is strongly recommended. While the current risk is elevated due to low detection coverage, rapid response and containment could mitigate successful credential theft. Users should be warned not to enter credentials on any unexpected Microsoft login prompts and to verify URLs via official channels.
Intelijen Keamanan Jaringan Registrar context
Alur Tanggapan Ancaman Pipeline
Status Daftar Blokir Publik
Tangkapan tersimpan
Intelijen Domain
Rincian teknisDNS, SAN SSL, cap waktu
ICANN OVERSIGHT
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Riwayat Laporan Penyalahgunaan · 3 stored reports over 15 days · click to expand
-
Report #2 ICANN CC 163h still active Apr 20, 2026 · 14:45 UTCESCALATION #2 (163h active): Phishing - noawin[.]comabuse@trustname.com abuse@verisign-grs.com compliance@icann.org
-
Report #3 ICANN CC 365h still active Apr 29, 2026 · 00:47 UTCESCALATION #3 (365h active): Phishing - noawin[.]comabuse@trustname.com abuse@verisign-grs.com compliance@icann.org
-
Report #4 ICANN CC 515h still active May 5, 2026 · 07:25 UTCESCALATION #4 (515h active): Phishing - noawin[.]comabuse@trustname.com abuse@verisign-grs.com compliance@icann.org
Casino / Gambling License Verification
Analisis VirusTotal
Bukti Terarsip
Analisis Performa Situs
Google PageSpeed Insights — mobile performance audit of noawin.com · checked Apr 13, 2026
Bukti & Laporan Eksternal
PD-20260413-0C31FE Recipient: abuse@trustname.com Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive