# orxglobal.com — SUSPICIOUS > PhishDestroy examines the phishing risks linked to orxglobal.com. Stay informed and protect your network from potential threats. ## Summary PhishDestroy has identified orxglobal.com as a low-risk, generic phishing domain. The site was purposed around the theme of "On-chain Recovery eXperts," likely aiming to exploit trust in blockchain-related services. While the overall threat level remains low, the domain’s association with phishing tactics warrants caution, especially given its recent creation and limited operational history. The domain orxglobal.com was registered on March 11, 2026, via Dynadot LLC and resolved to the IP address 159.100.9.49. VirusTotal analysis flagged it by a single security vendor out of 95, suggesting minimal detection but not complete benign status. The domain also appears on one security blocklist, reinforcing the need for vigilance. These technical indicators indicate the domain was likely part of a broader phishing infrastructure designed to deceive users under the guise of blockchain recovery expertise. Currently, orxglobal.com is offline and no longer accessible, reducing immediate risk. However, given that such domains can be reactivated or replicated, it is recommended that organizations maintain updated blocklists and monitor similar domain registrations. Continuous awareness and proactive filtering remain essential to mitigate the potential resurgence of phishing attempts linked to this or related domains. ## Threat Details - Verdict: SUSPICIOUS - Site status: dead (HTTP 429) - Page title: On-chain Recovery eXperts | orxglobal.com ## Domain Intelligence - Registered: 2026-03-11 03:07:02 - Registrar: Dynadot LLC - Country: US - IP: 159.100.9.49 - IP Country: DE - IP City: Frankfurt am Main - IP Org: AS214036 Ultahost, Inc. - Nameservers: evelyn.ns.cloudflare.com quincy.ns.cloudflare.com - SSL Issuer: Let's Encrypt / R12 ## Detection Status - VirusTotal: 1 vendors flagged Vendors: ["SOCRadar"] - Google Safe Browsing: clean - Blocklists: 1 hits Lists: ["PhishDestroy"] ## Evidence - Screenshot: https://i.ibb.co/Cr5QwR5/db5a82cb5199.png - Cloudflare Radar: https://radar.cloudflare.com/scan/43d8669d-3e32-4340-a135-ce92c3371db9 - PhishDestroy: https://phishdestroy.io/domain/orxglobal.com/ - LLM endpoint: https://phishdestroy.io/domain/orxglobal.com/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/orxglobal.com/ Last updated: 2026-03-19