This phishing domain has been taken down
Confirmed dead — kept on record for forensic reference and similar-pattern matching.

rocket.originworld[.]io

Domain Security & Threat Intelligence Report
“Origin”
5/95 VT Taken Down 2 Blocklists Impersonation: Origin Taken Down
REF 85171D1E SCORE 100/100 ENGINE PD-4 Turbo Appeal listing
0 Risk Score
Data coverage VirusTotal 5 / 95 URLQuery no det. OTX no pulses CF Radar pending URLScan pending DNS blocks none SSL invalid WHOIS 2d old Screenshot not captured Redirect chain no redirect CDN bypass n/a
VirusTotal
5 det.
URLQuery
no det.
OTX
no pulses
CF Radar
pending
URLScan
DNS Security
no dets
Gridinsoft
SSL
Age
2d
Status
Dead
DestroyList
Listed
Reports Sent
0
02

Forensic brief

auto-generated · PhishDestroy AI
PhishDestroy AI
probe: —
score: 100/100
vendors5/95
blocklists2
Analyst brief · auto-generated

Threat Overview The domain rocket[.]originworld[.]io has been flagged as a phishing threat. PhishDestroy's automated scanning systems detected multiple risk indicators associated with this domain. Detection Details This domain was identified through a combination of automated analysis, community reports, and cross-referencing with global threat intelligence feeds including VirusTotal, Google Safe Browsing, and 50+ specialized blocklists. Risk Indicators - Domain registered on io TLD - Domain length: 21 characters Stay Safe Always verify URLs before entering credentials. Use a password manager to avoid typing passwords on fake sites. Enable two-factor authentication wherever possible.

Brand Impersonation unknown brand: Origin
03

Threat response pipeline

0 reports submitted
Discovery
Submission
Legal
Takedown
9/19
30+ Proprietary Parsers
Distributed scanning of Google Ads, SEO-manipulated results, Twitter/X, YouTube & Telegram campaigns.
Infrastructure Analysis
dnstwist & typosquatting detection against Origin.
Community Intelligence
Real-time ingestion via Telegram Bot & partner intelligence feeds.
Threat Ingested
rocket.originworld.io detected and queued for full analysis.
56+ Vendor Submissions
Threat data submitted to 56+ security vendors & threat-intel platforms. 5 flagged this domain.
VirusTotal
5 / 95 vendors flagged on VirusTotal.
Blocklist Detection
Found in 2 blocklists: ScamSniffer, PhishDestroy.
Open Threat Database
Real-time commits to GitHub repository & live monitoring at phishdestroy.io/live.
Social Broadcasting
Automated alerts on X, Telegram & Mastodon.
Confirmed dead
Domain confirmed taken down.
May 17, 2026
08

Public blocklist status

cross-vendor confirmation
2
Listed in 2 public blocklists — confirmed by independent sources
Sources with no listing are omitted.
10

VirusTotal consensus

95 vendors · 3-col matrix
5/95
vendors flagging
Partial detection

Aggregated detection across 95 security vendors.

Per-vendor breakdown not available — view raw report on VirusTotal ↗
12

Evidence & external reports

cross-reference this domain
14

Were you affected by this site?

immediate response · authorities

Were You Affected?

You are not alone and there is nothing to be ashamed of. Reporting is the most powerful weapon against fraud — your report can prevent others from becoming victims.
Beware of recovery scammers! No legitimate service will ask for upfront payment to recover stolen crypto. Learn more about recovery fraud →

Recommendations & Advice for Victims

  1. Do not pay anything else. Recovery agents demanding upfront fees are a second-stage scam.
  2. Disconnect compromised wallets. Move remaining funds to a fresh seed phrase generated offline.
  3. Preserve evidence. Screenshot transactions, save URLs, archive emails — chain-of-custody matters for prosecution.
  4. Report to authorities (see section 15 below) — even small reports help build case patterns.
  5. Notify your bank/exchange. Some chargebacks may still be possible within 24-72h.
ICANN RAA §3.18 DMCA §512 GDPR Art.17 FBI guidelines SEAL-ISAC
15

Report to your local authorities

geo-aware · authorities · AI complaint
Your country (auto-detected)
International / Other

  Email template — registrar abuse

To: abuse@ Case: PD-
Open in mail client Appeal (if false-positive)
16

Embed this report

iframe · sizer · CC-BY

Embed this report

Drop a live, self-updating risk widget anywhere — blog, DAO forum, Discord webhook, X post. Free, no API key, CC-BY.

rocket[.]originworld[.]io 100/100 TAKEN DOWN · 5/95 VT · 0h View full report ↗
Live preview at 100% width
Canonical: https://phishdestroy.io/domain/rocket.originworld.io/ JSON API llm.txt
17

About this report

methodology · appeals · API

About this report: rocket.originworld.io

This domain security report is maintained by PhishDestroy's automated threat-intelligence pipeline. Our system continuously monitors this domain across 95 security vendors on VirusTotal and 2 public blocklists.

The site displays a page titled “Origin”.

rocket.originworld.io has been flagged by 5 security vendors as of today.

If you believe this listing is inaccurate, you can submit an appeal. For more information about our methodology, visit our FAQ page.