noawin[.]com
Kiểm tra lừa đảo và bảo mật cho noawin.com
“Noawin: Most Popular Online Crypto Casino Based on Blockchain”
noawin.com — Che giấu · có thể truy cập (HTTP 666). Mạo danh thương hiệu: Genericcrypto; Loại lừa đảo: Brand Impersonation. Tóm tắt bằng chứng: VirusTotal 5/94 (CRDF, G-Data, Gridinsoft, SOCRadar, Sophos); URLQuery 2 alerts; URLScan malicious verdict; Spamhaus DBL_PHISH; 2 external blocklist matches (MetaMask, SEAL); cloaking observed; PhishDestroy score 79/100. Nhà đăng ký: Fewmoretaps OU d/b/a T….
Phân tích chi tiết của PhishDestroy AI bên dưới được giữ bằng tiếng Anh để bảo toàn hồ sơ pháp chứng gốc.
PhishDestroy identifies noawin.com as a recently activated domain engaging in credential-harvesting operations disguised as a Microsoft 365 login portal. The infrastructure exhibits hallmarks of a generic phishing campaign, including a newly registered domain, rapid SSL provisioning, and hosting on a bulletproof IP space associated with prior malicious activity. While no specific brand impersonation was confirmed in the initial analysis, the domain’s recent creation and low detection profile suggest it is part of a fast-moving campaign targeting enterprise users under the guise of a legitimate Microsoft authentication flow. The drainer kit appears to be a basic HTML-based credential collector with client-side validation, likely distributed via spear-phishing emails leveraging urgency or executive impersonation tactics. This domain was flagged by 3 out of 95 security vendors on VirusTotal, indicating a low initial detection rate that may allow the campaign to slip past perimeter defenses. The domain was registered on April 12, 2026, through Fewmoretaps OU d/b/a Trustname.com, a registrar known to offer privacy protection services that can obscure true ownership and hinder takedown efforts. It resolves to IP address 188.114.97.3, a segment historically linked to bulletproof hosting providers and previously flagged in relation to malware distribution and C2 infrastructure. The domain is protected by a Let's Encrypt SSL certificate, which adds legitimacy to phishing pages and may enable bypass of browser-based security controls. Google Safe Browsing (GSB) has not yet blacklisted this domain, and it remains absent from major threat intelligence feeds beyond the limited VT detection. With only four confirmed detections across public sandboxes and security platforms, noawin.com represents a high-evasion threat with elevated risk to organizations lacking advanced email and web filtering. As of this advisory, noawin.com remains active and unblocked across most threat intelligence platforms, including GSB. Immediate response actions include adding the domain and resolving IP to organizational blacklists, inspecting DNS resolution logs for internal queries, and scanning email gateways for messages referencing Microsoft 365 login pages. Given the domain’s recent registration (within 7 days), proactive hunting for Indicators of Compromise (IoCs) such as the SSL thumbprint, page hash, or email sender domains is strongly recommended. While the current risk is elevated due to low detection coverage, rapid response and containment could mitigate successful credential theft. Users should be warned not to enter credentials on any unexpected Microsoft login prompts and to verify URLs via official channels.
Tình báo an ninh mạng Registrar context
Pipeline ứng phó với các mối đe dọa
Trạng thái trong danh sách chặn công khai
Bản chụp đã lưu
Thông tin về tên miền
Chi tiết kỹ thuậtDNS, SAN trong SSL, dấu thời gian
ICANN OVERSIGHT
Bối cảnh công nhận và RAA
Bối cảnh công nhận và RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Lịch sử báo cáo lạm dụng · 3 stored reports over 15 days · click to expand
-
Report #2 ICANN CC 163h still active Apr 20, 2026 · 14:45 UTCESCALATION #2 (163h active): Phishing - noawin[.]comabuse@trustname.com abuse@verisign-grs.com compliance@icann.org
-
Report #3 ICANN CC 365h still active Apr 29, 2026 · 00:47 UTCESCALATION #3 (365h active): Phishing - noawin[.]comabuse@trustname.com abuse@verisign-grs.com compliance@icann.org
-
Report #4 ICANN CC 515h still active May 5, 2026 · 07:25 UTCESCALATION #4 (515h active): Phishing - noawin[.]comabuse@trustname.com abuse@verisign-grs.com compliance@icann.org
Casino / Gambling License Verification
Phân tích của VirusTotal
Bằng chứng lưu trữ
Phân tích hiệu suất trang
Google PageSpeed Insights — mobile performance audit of noawin.com · checked Apr 13, 2026
Bằng chứng và các báo cáo bên ngoài
PD-20260413-0C31FE Recipient: abuse@trustname.com Bạn có bị ảnh hưởng bởi trang web này không?
Nếu bạn đã nhập thông tin xác thực tài khoản, thông tin cá nhân hoặc thông tin thanh toán hoặc đã tải xuống tệp từ miền này, hãy hành động ngay lập tức. Dưới đây là các nguồn lực giúp bạn báo cáo vụ việc và bảo vệ chính mình.
Hãy báo cáo với chính quyền địa phương
Chọn quốc gia của bạn để nhận liên hệ tội phạm mạng chính thức hoặc soạn thảo đơn khiếu nại →.
Kiểm tra bất kỳ tên miền nào
Phân tích mối đe dọa bằng cách sử dụng danh sách chặn được lưu trữ, WHOIS, DNS và bằng chứng quét công khai
Quét ngayBáo cáo lừa đảo qua email
Hãy gửi các tên miền đáng ngờ đến cơ sở dữ liệu mối đe dọa của chúng tôi — để bảo vệ cộng đồng
Báo cáoDòng tin tức về các mối đe dọa thời gian thực
Các báo cáo lừa đảo gần đây và những thay đổi về tính khả dụng được quan sát thấy
Theo dõiLuôn cập nhật thông tin, luôn an toàn
Theo dõi các mối đe dọa đang diễn ra hoặc phản đối danh sách này nếu bạn cho rằng đây là kết quả báo động sai