# oracaquwant.digital — MALICIOUS > oracaquwant.digital is a high-risk phishing site now offline. Avoid visiting this domain to protect your personal data from fraud. ## Summary PhishDestroy identifies oracaquwant.digital as a high-risk generic phishing threat. The domain was designed to deceive users, with a suspicious page title promising high earnings, indicating its intent to lure victims into fraudulent schemes. Supporting intelligence shows the domain was created on September 30, 2025, and registered through PDR Ltd., a commonly used registrar in fraudulent activity. It resolves to IP 104.21.93.154 and appears on two security blocklists. AlienVault OTX detected this domain in two threat intelligence pulses, and VirusTotal flagged it as malicious by 23 out of 95 security vendors, confirming its malicious nature. Currently offline, oracaquwant.digital no longer serves phishing content, reducing immediate risk. Users should avoid interacting with this domain and ensure they have updated security measures to protect against similar threats. Monitoring for such domains and blocking access remain critical in mitigating phishing risks. ## Threat Details - Verdict: MALICIOUS - Site status: dead (HTTP 403) - Page title: Zarobte viac ako 950 eur denne ## Domain Intelligence - Registered: 2025-09-30 13:08:20 - Expires: 2026-09-30 00:00:00 - Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com - Country: IN - IP: 104.21.93.154 - IP Country: US - IP City: San Francisco - IP Org: AS13335 Cloudflare, Inc. - Nameservers: ["ns1.suspended-domain.com", "ns2.suspended-domain.com"] - SSL Issuer: none ## Detection Status - VirusTotal: 23 vendors flagged Vendors: ["ADMINUSLabs", "alphaMountain.ai", "BitDefender", "Certego", "Cluster25", "CRDF", "CyRadar", "DNS8", "ESET", "Emsisoft", "Forcepoint ThreatSeeker", "Fortinet", "G-Data", "Google Safebrowsing", "Gridinsoft", "Kaspersky", "Lionic", "PREBYTES", "Seclookup", "SOCRadar", "Sophos", "VIPRE", "Webroot"] - Google Safe Browsing: clean - Blocklists: 2 hits Lists: ["PhishDestroy", "MetaMask"] ## Evidence - Screenshot: https://urlscan.io/screenshots/019c17a8-32b8-733b-a003-8a9150d2caab.png - Cloudflare Radar: https://radar.cloudflare.com/scan/c20df6f0-1dd4-4f5f-a627-db2e083cf473 - PhishDestroy: https://phishdestroy.io/domain/oracaquwant.digital/ - LLM endpoint: https://phishdestroy.io/domain/oracaquwant.digital/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/oracaquwant.digital/ Last updated: 2026-03-19