novyra-kelthar[.]com
“Novyra Kelthar - Offizielle Plattform | KI-Trading 2025 | Über 10.000 Bewertungen”
Riepilogo delle prove
Analysis of the domain novyra-kelthar.com indicates it was actively used for brand impersonation targeting Argent, a financial or trading platform. The domain, registered on February 21, 2026, through Gransy, s.r.o., was taken offline following detection by security vendors. Infrastructure analysis reveals the domain resolved to 172.67.191.104, a Cloudflare IP (AS13335) located in the US, and used Cloudflare nameservers (ashley.ns.cloudflare.com and christian.ns.cloudflare.com). No SSL certificate was present, increasing the risk of unencrypted data transmission.
The page title, 'Novyra Kelthar - Offizielle Plattform | KI-Trading 2025 | Über 10.000 Bewertungen,' suggests an attempt to impersonate a legitimate trading platform, leveraging claims of AI-driven trading and fabricated user reviews to appear credible. At the time of reporting, 13 of 93 security vendors on VirusTotal flagged the domain, and it appeared on one security blocklist. AlienVault OTX also listed the domain in a threat intelligence pulse, confirming its malicious classification. Defenders should treat this domain as part of a broader phishing campaign targeting Argent users.
The absence of SSL, use of Cloudflare infrastructure, and rapid takedown align with common phishing tactics. While the exact content of the site remains unanalyzed, the available evidence—including the page title, brand impersonation classification, and detection by multiple security sources—supports its designation as a scam. Organizations are advised to block the domain at the DNS level and monitor for related infrastructure, such as similarly named domains or shared IP addresses.
Istantanea delle prove inviate
- Inviato
- Voci del registro
- 1
- ID del caso
PD-20260107-34286D- Titolo della pagina acquisita
- Novyra Kelthar - Offizielle Plattform | KI-Trading 2025 | Über 10.000 Bewertungen
- Artefatto PDF
- Prova in PDF
Base giuridica
Testo completo delle prove
Acceptable Use Policy (AUP): The domain novyra-kelthar.com is engaged in phishing activities, which directly contravenes the AUP prohibiting illegal activities, fraud, and deception.
Terms of Service (TOS): The registrar reserves the right to suspend or terminate services for violations, and the ongoing use of this domain for malicious purposes constitutes a clear breach of these terms.
Applicable Laws (Unknown):
Computer Fraud and Abuse Act (CFAA): This U.S. federal law prohibits unauthorized access to computers and the distribution of fraudulent communications, applicable to phishing schemes.
Wire Fraud Statute (18 U.S.C. § 1343): This law criminalizes schemes to defraud individuals or entities through electronic communications, which is relevant to the activities associated with this domain.
Anti-Phishing Consumer Protection Act: This legislation aims to combat phishing and protect consumers from deceptive online practices, applicable to the operations of novyra-kelthar.com.
Regulatory Note: Failure to take prompt action against this domain may expose your organization to legal liabilities and regulatory scrutiny. Immediate suspension is advised to mitigate risks associated with non-compliance.
Data Coverage
Informazioni sulla sicurezza di rete
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | novyra-kelthar.com |
malicious | Sinkholed |
Pipeline di risposta alle minacce
Copertura delle blocklist
10 fonti esterne monitorate · snapshot del 12/08/2026
10 fonti esterne monitorate Nessuna corrispondenza
Cronologia del rilevamento
-
Cloudflare Radar
Scansione Cloudflare Radar archiviata · Apri scansione
Acquisizione salvata
Analisi dei domini
Dettagli tecniciDNS, nomi TLS e date
ICANN OVERSIGHT
Accreditamento e contesto RAA
Accreditamento e contesto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analisi di VirusTotal
Questo sito ti ha influenzato in qualche modo?
Se hai inserito credenziali dell'account, informazioni personali o di pagamento oppure hai scaricato un file da questo dominio, agisci immediatamente. Di seguito sono riportate le risorse per aiutarti a segnalare l'incidente e proteggerti.
Segnalalo alle autorità locali
Seleziona il tuo Paese per ottenere contatti ufficiali del crimine informatico o creare una bozza di reclamo →.
Verifica qualsiasi dominio
Analisi delle minacce utilizzando blocklist archiviate, WHOIS, DNS e prove di scansione pubblica
Scansiona oraSegnala un tentativo di phishing
Segnala i domini sospetti al nostro database delle minacce — proteggi la comunità
SegnalaFeed in tempo reale sulle minacce
Segnalazioni recenti di phishing e modifiche osservate della disponibilità
MonitoraRimani informato, rimani al sicuro
Controlla le minacce in tempo reale oppure contesta questa segnalazione se ritieni che si tratti di un falso positivo