Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 1 month has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
novarmint[.]com
“Novar Mint | Homepage”
Зведення доказів
This domain, novarmint.com, is identified as a crypto drainer phishing site designed to illicitly extract cryptocurrency assets from victims' wallets. Analysis indicates the domain operates without impersonating a specific brand, instead deploying generic but highly effective drainer scripts to bypass user authentication and initiate unauthorized transactions. The infrastructure appears to leverage automated kits, common in large-scale crypto theft operations, to maximize exploitation efficiency. Infrastructure analysis reveals the following technical indicators: the domain was registered on June 11, 2026, through NameCheap, Inc., and resolves to the IP address 63.250.38.225. It holds a VirusTotal detection score of 4/95, indicating limited but confirmed malicious activity recognition. The SSL certificate is issued by Sectigo Limited, a common certificate authority often exploited by threat actors to lend false legitimacy. The domain appears on two security blocklists and is actively blocked by PhishDestroy and OISD, further corroborating its malicious intent. As of the latest assessment, novarmint.com has been taken offline, likely due to registrar intervention or hosting provider action. However, the elevated risk persists due to the potential for rapid re-deployment under a new domain or IP address. Users who interacted with this domain are advised to immediately revoke any connected wallet permissions, transfer remaining assets to a secure wallet, and monitor transaction histories for unauthorized activity. Organizations should update blocklists to include this domain and its associated IP to prevent future access attempts. Continuous monitoring of newly registered domains with similar patterns is recommended to mitigate recurring threats.
Знімок надісланих доказів
- Надіслано
- Записи журналу
- 1
- ID справи
PD-20260611-2755BE- Заголовок збереженої сторінки
- Novar Mint | Homepage
- PDF-файл
- PDF із доказами
Правова підстава
Повний текст доказів
Policy Violations: Domain Registration Agreement prohibits hacking, misuse of domain to conduct attacks, scam and fraudulent activities; AUP allows immediate suspension
Applicable Laws: CFAA 18 U.S.C. §1030, Wire Fraud 18 U.S.C. §1343, CAN-SPAM Act
Data Coverage
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | novarmint.com |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Перевірка за блок-листами
10 зовнішніх джерел під наглядом · знімок від 10.08.2026
Хронологія виявлення
-
VirusTotal
3 → 4
Збережений знімок
Аналітика доменів
Технічні подробиціDNS, імена TLS і часові мітки
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології
Виявлено 7 технологій із високою впевненістю
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of novarmint.com · checked Jun 25, 2026
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога