app-ocra[.]so
“Orca | Pools”
ملخص الأدلة
Analysis of the domain app-ocra.so indicates that it was registered on 25 February 2026 through NameCheap, Inc. The authoritative nameservers are dns1.registrar-servers.com and dns2.registrar-servers.com, and the domain resolves to the IPv4 address 82.25.63.187, which is advertised by AS207043 DEDIK SERVICES LIMITED and geolocated to France. No TLS certificate is presented for the host, confirming the absence of HTTPS support. The site’s HTML title, as captured before the domain was taken offline, reads “Orca | Pools”, and the domain is explicitly listed as impersonating the Orca brand. VirusTotal reports a single positive detection out of 93 scanning engines, indicating at least one vendor identified malicious behavior.
Independent blocklist aggregators have added the domain to four separate security blocklists, and it is currently blocked by PhishDestroy, MetaMask, ScamSniffer, and SEAL. The overall risk assessment is elevated, and the operational status is recorded as offline. While the available data confirms the domain’s use for brand‑impersonation, the specific phishing kit, payload, or victim interaction flow has not been publicly disclosed.
The lack of an SSL certificate and the offline status limit real‑time observation of malicious content, leaving the exact lure and credential‑harvesting mechanisms uncertain. Defenders should continue to monitor the IP address 82.25.63.187 for any re‑activation, enforce outbound filtering to block connections to the domain and its hosting ASN, and ensure that any corporate or user‑initiated requests to app‑ocra.so are denied by web‑filtering solutions. Adding the domain to internal blocklists and sharing the indicator with threat‑sharing communities will reduce exposure to the identified Orca impersonation campaign.
لقطة الأدلة المرسلة
- أُرسل
- سجلات الدفتر
- 1
- معرّف القضية
PD-20260225-B39B6C- عنوان الصفحة الملتقطة
- Orca | Pools
- ملف PDF
- دليل PDF
الأساس القانوني
النص الكامل للدليل
Policy Violations: Domain Registration Agreement prohibits hacking, misuse of domain to conduct attacks, scam and fraudulent activities; AUP allows immediate suspension
Applicable Laws: CFAA 18 U.S.C. §1030, Wire Fraud 18 U.S.C. §1343, CAN-SPAM Act
Data Coverage
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | widget.metacrm.inc/static/js/widget-3-4-1.js |
audit | Hunting_JS_WebAssembly |
| Hagezi Threat Feed | app-ocra.so |
malicious | Sinkholed |
| DNS4EU | calm-spiffy.fontmaxplugin.cc |
malicious | Sinkholed |
| DigiCert UltraDNS | ipfs.io |
malicious | Sinkholed |
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 11/08/2026
٧ مصادر خارجية مراقبة لا تطابق
المخطط الزمني للاكتشاف
-
حالة النطاق
يمكن الوصول إليه ← يتعذر الوصول إليه
-
VirusTotal
1 ← 3
-
Cloudflare Radar
تم حفظ فحص Cloudflare Radar · فتح الفحص
تحليل VirusTotal
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب