Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 6 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
ordexiabot[.]net
“OrdexiaBot - Piattaforma Ufficiale Italia | Trading IA 2025”
Resumen de las pruebas
Analysis of ordexiabot.net indicates a deliberately crafted brand impersonation campaign targeting the base brand. The domain was registered through PDR Ltd. d/b/a PublicDomainRegistry.com and was created on February 21, 2026. DNS resolution points to IP address 188.114.97.3, which is associated with Cloudflare, Inc. (AS13335) and geolocated to the United States. The domain is served behind Cloudflare's edge network, employing HSTS and HTTP/3, and presents a TLS certificate issued by Google Trust Services under the WE1 intermediate, confirming the use of a valid public‑trusted certificate chain.
Reputation data shows the site is flagged by eight of ninety‑three VirusTotal scanners, and it appears on three external blocklists, including PhishDestroy, MetaMask, and SEAL. Independent trust scoring from Gridinsoft assigns a zero out of one hundred rating, reinforcing the malicious assessment. The page title captured from the live site reads "OrdexiaBot - Piattaforma Ufficiale Italia | Trading IA 2025," which aligns with the declared scam type of brand impersonation.
Current operational status is offline, but the infrastructure components (registrar, hosting, certificate) remain observable and could be reused. Defenders should add ordexiabot.net to internal block and URL filtering policies, monitor for any re‑activation or related domains using the same registrar or Cloudflare nameservers (cameron.ns.cloudflare.com, liz.ns.cloudflare.com), and consider sharing the indicator set with threat‑intel partners. Continuous observation of the IP 188.114.97.3 for new hostnames is advised, as the same Cloudflare edge may be leveraged for future campaigns.
Instantánea de evidencia enviada
- Enviado
- Registros del libro
- 1
- ID del caso
PD-20260207-728256- Artefacto PDF
- Evidencia en PDF
Texto completo de la evidencia
Section 3.1 of AUP: The domain ordexiabot.net is engaged in phishing activities, which is a direct violation of your Acceptable Use Policy prohibiting illegal activities and deception.
Section 5.2 of TOS: The continued operation of this domain constitutes a breach of your Terms of Service, which reserves the right to suspend or terminate services for violations related to fraud and phishing.
Applicable Laws (PL):
Act of 18 July 2002 on the Provision of Services by Electronic Means: This law prohibits the use of electronic means for fraudulent purposes, including phishing.
Criminal Code of Poland (Ustawa z dnia 6 czerwca 1997 r. - Kodeks karny), Article 287: This article addresses computer fraud, making it illegal to unlawfully access data or systems for fraudulent purposes.
Act of 29 August 1997 on Personal Data Protection: This law protects personal data and prohibits its unlawful processing, which is relevant in the context of phishing schemes.
Regulatory Note: Failure to act on this report may expose your organization to legal liability under Polish law, as well as potential regulatory actions from relevant authorities. Immediate action is recommended to mitigate risks associated with hosting this phishing domain.
Data Coverage
Inteligencia de seguridad de red
Proceso de respuesta ante amenazas Pipeline
Cobertura de listas de bloqueo
10 fuentes externas supervisadas · instantánea del 13/08/2026
8 fuentes externas supervisadas Sin coincidencias
Cronología de detección
-
Estado del dominio
Accesible → Inaccesible
-
Estado del dominio
Accesible → Inaccesible
-
Cloudflare Radar
Análisis de Cloudflare Radar almacenado · Abrir análisis
-
Estado del dominio
Inaccesible → Accesible
Captura guardada
Inteligencia de dominios
Detalles técnicosDNS, nombres TLS y marcas de tiempo
ICANN OVERSIGHT
Acreditación y contexto RAA
Acreditación y contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologías
3 tecnologías identificadas con alta confianza
Análisis de VirusTotal
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.