MALICIOUS — CRITICAL
ochamchyra[.]com
Analysis of ochamchyra.com indicates an active phishing domain registered on January 8, 2025, through REG.RU LLC.
- VirusTotal
- 3/91
- Blocklists
- No stored match
- Verfügbarkeit
- Letzter bekanntermaßen aktiv · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@reg.ru.
The latest stored availability evidence still shows the domain reachable; 13 days has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
ochamchyra.com — Letzter bekanntermaßen aktiv (HTTP 200). Zusammenfassung der Beweislage: VirusTotal 3/91 (CRDF, Gridinsoft, SOCRadar); PhishDestroy score 76/100. Registrar: Registrar of Domain Na….
Die ausführliche Analyse von PhishDestroy AI bleibt auf Englisch, damit der ursprüngliche forensische Bericht unverändert bleibt.
Evidence Analysis
Analysis of ochamchyra.com indicates an active phishing domain registered on January 8, 2025, through REG.RU LLC. As of July 27, 2026, the domain remains operational and is currently flagged by one security blocklist, PhishDestroy. Infrastructure review shows the domain resolves to IP address 78.24.222.223 and uses nameservers ns1.reg.ru and ns2.reg.ru, consistent with hosting via REG.RU. No specific brand impersonation or scam category has been confirmed in available data, and the exact content of the site is not yet analyzed.
VirusTotal scans conducted by 91 vendors returned no detections; however, the absence of flags does not confirm safety and may reflect delayed detection or evasion techniques. The domain's creation date suggests it has been active for over 18 months, a duration often associated with persistent phishing operations. Defenders are advised to treat this domain as high-risk until further analysis is completed.
Network-level blocking at 78.24.222.223 and monitoring of associated REG.RU nameservers may help mitigate exposure. Additional investigation is required to determine the specific threat vector, target audience, or potential credential harvesting activity.
Datenabdeckung12 recorded checks
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Status der öffentlichen Sperrliste
Gespeicherte Aufnahme
Domain-Intelligenz
Technische DetailsDNS, SSL-SANs, Zeitstempel
ICANN OVERSIGHT
Akkreditierung und RAA-Kontext
Akkreditierung und RAA-Kontext
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologien · 3 identified
Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 100 % KonfidenzHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100 % KonfidenzVirusTotal-Analyse
Archivierte Beweise
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of ochamchyra.com · checked Jul 27, 2026
Nachweise und externe BerichteIndependent lookups and source reports
“"I received my 105 USDT and decided to cash out 100 USDT through a bot (@SwapX_changebot) on Telegram. I did everything as stated in the bot's instructions, transferred them to the appropriate wallet (0xb41567F7fE9957514b0C5a8e51A9760934BD3EcC), but never received my money. I am requesting that my 100 USDT be returned to the same address."”
PD-20260727-CEB4BA Recipient: abuse@reg.ru Victim safety and official reportingImmediate actions and verified reporting channels
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.