novalink[.]to
“NovaLink — One hub. Every connection”
novalink.to — Não verificado. Representação da marca: Across; Tipo de golpe: Brand Impersonation. Resumo das evidências: VirusTotal 4/91 (alphaMountain.ai, CRDF, Gridinsoft, Webroot); PhishDestroy score 65/100. Registrador: NameCheap.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Analysis of novalink.to shows multiple indicators of malicious activity related to brand impersonation. The domain was created on September 24, 2025 and is registered through NameCheap, Inc. It resolves to IP address 188.114.96.3, which belongs to Cloudflare, Inc. (AS13335) and is geolocated in the United States. The authoritative nameservers are kianchau.ns.cloudflare.com and leia.ns.cloudflare.com, confirming the use of Cloudflare’s DNS infrastructure. No SSL certificate is presented, meaning the site would be served over plain HTTP if it were reachable.
The page title retrieved during a brief scan reads "NovaLink — One hub. Every connection," suggesting an attempt to appear as an official service hub for a brand named NovaLink. The intelligence indicates the domain impersonates "across" and is classified as a brand‑impersonation scam. Security‑vendor data from VirusTotal shows that 2 of 95 scanned vendors flagged the domain, and it appears on one external security blocklist.
PhishDestroy has also added the domain to its blocklist, and Gridinsoft assigns a trust score of 0 out of 100, indicating a high confidence of malicious intent. The site is currently taken offline, limiting immediate interaction, but the combination of low trust scoring, vendor detections, blocklist listings, and the absence of TLS suggests a deliberate attempt to deceive users. Defenders should continue to block the domain at perimeter controls, monitor DNS queries for the associated IP and nameservers, and add the domain to internal threat‑intel feeds. Since the content of the site has not been publicly examined, further investigation is warranted if the domain reappears online to confirm the exact phishing payload or credential‑capture mechanisms.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo