orangex-korea[.]at
“OrangeX 로그인 - 최고의 암호화폐 거래소 | OrangeX Login Exchange”
orangex-korea.at — المحتوى غير متوفر (HTTP 502). انتحال العلامة التجارية: Facebook; نوع الاحتيال: Fake Exchange. ملخص الأدلة: VirusTotal 5/93 (ADMINUSLabs, G-Data, SOCRadar, Sophos, alphaMountain.ai); Spamhaus DBL_PHISH; PhishDestroy score 65/100. مسجّل النطاق: Iqweb.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
The domain orangex-korea.at was registered on 27 February 2026 through the registrar Iqweb and is currently taken offline. DNS resolution points to the IP address 186.2.175.29, which belongs to AS59692 IQWeb FZ-LLC and is geolocated to a BZ address block. The domain is served by four CloudNS nameservers (pns71.cloudns.net, pns72.cloudns.com, pns73.cloudns.net, pns74.cloudns.uk) and presents a TLS certificate issued by Let’s Encrypt (R13). The site’s page title, "OrangeX 로그인 - 최고의 암호화폐 거래소 | OrangeX Login Exchange," indicates an attempt to impersonate a cryptocurrency exchange, matching the classified scam type of a fake exchange.
Technical fingerprinting shows the presence of jQuery, Hammer.js, and DDoS‑Guard scripts, suggesting a typical phishing hosting stack. Reputation checks reveal a Gridinsoft trust score of 0 / 100 and inclusion on a single security blocklist. VirusTotal analysis recorded five detections out of ninety‑three scanning engines, confirming malicious activity, and the domain is listed by PhishDestroy as blocked.
While the offline status prevents real‑time content verification, the convergence of registrar information, IP ownership, SSL details, page title, and detection counts provides strong evidence that orangex-korea.at was used for credential‑harvesting targeting cryptocurrency users. Defenders should continue to block the domain at network perimeter devices, monitor for any resurgence of the host infrastructure, and update URL filtering and endpoint protection rules to reflect the observed indicators. Further investigation is needed to determine whether additional sub‑domains or related IP assets are being leveraged for the same campaign.
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
التقنيات · 3 identified
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
تحليل VirusTotal
الأدلة المؤرشفة
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of orangex-korea.at · checked Mar 2, 2026
الأدلة والتقارير الخارجية
PD-20260227-0439DA Recipient: abuse@iqweb.io هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب