id[.]orijin[.]plus
“Product Info Page”
Resumen de las pruebas
This domain, id.orijin.plus, is identified as a generic phishing site designed to impersonate a legitimate product information portal. Analysis confirms the domain is currently offline, though prior activity involved luring users into disclosing sensitive data under the guise of product verification or updates. The threat type aligns with credential harvesting and potential malware distribution, targeting individuals seeking product-related services. Infrastructure analysis reveals the domain was registered on February 21, 2026, through Amazon Registrar, Inc., and resolves to the IP address 13.226.244.115, hosted on Amazon.com, Inc. infrastructure (AS16509) in Germany. The SSL certificate is issued by Amazon RSA 2048 M02, a common practice among legitimate services that threat actors exploit to appear trustworthy. The domain is flagged by 11 of 95 security vendors on VirusTotal, and it appears on one security blocklist, further corroborating its malicious intent. The page title, 'Product Info Page,' suggests an attempt to mimic a corporate or e-commerce portal, increasing the likelihood of successful social engineering. As of the latest assessment, id.orijin.plus has been taken offline, reducing immediate risk to end users. However, organizations and individuals should remain vigilant, as domains of this nature often reappear under similar names or infrastructure. Recommended actions include blocking the domain and its associated IP (13.226.244.115) at the network level, monitoring for related subdomains or typosquatting variants, and educating users on recognizing phishing attempts. Security teams should also review logs for prior connections to this domain and investigate any potential data exposure or unauthorized access attempts linked to its activity.
Data Coverage
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 11/08/2026
10 fuentes externas supervisadas Sin coincidencias
Cronología de detección
-
VirusTotal
11 → 12
-
VirusTotal
12 → 13
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, nombres TLS y marcas de tiempo
ICANN OVERSIGHT
Registration: orijin.plus
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For the registrable domain orijin.plus behind this subdomain, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análisis de VirusTotal
Análisis del rendimiento del sitio
Google PageSpeed Insights — mobile performance audit of id.orijin.plus · checked Mar 6, 2026
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.