stains[.]oridash[.]fr
“Connectez-vous pour continuer – Oridash”
stains.oridash.fr — No verificado. Tipo de estafa: Impersonation. Resumen de las pruebas: VirusTotal 15/91 (ADMINUSLabs, AILabs (MONITORAPP), BitDefender, Chong Lua Dao, CRDF); PhishDestroy score 95/100. Registrador: OVH.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
Analysis indicates that stains.oridash.fr is an active phishing infrastructure targeting users of the Oridash service. The domain was registered through OVH on November 07, 2020 and continues to resolve to the IPv4 address 145.239.37.162, which is hosted in France under ASN16276 (OVH SAS). DNS resolution is served by the OVH nameservers dns113.ovh.net and ns113.ovh.net. The site presents a HTTP 302 redirect and serves a TLS certificate issued by Let’s Encrypt (certificate identifier E7), confirming the use of a legitimate certificate authority to appear trustworthy.
The page title returned from the web server is "Connectez-vous pour continuer – Oridash", matching the expected login prompt for the legitimate service and reinforcing the impersonation attempt. Multiple security tools have flagged the domain: thirteen of ninety‑five VirusTotal scanners reported malicious activity, and the domain appears on one public blocklist. Independent reputation services have assigned a Gridinsoft trust score of 0 out of 100, effectively marking the site as completely untrusted. Additionally, the anti‑phishing platform PhishDestroy has listed the domain as blocked, providing further confirmation of its malicious nature.
Given the observed indicators—active status, OVH hosting, Let’s Encrypt TLS, HTTP 302 redirection, low trust score, and multiple vendor detections—defenders should treat stains.oridash.fr as a high‑risk phishing host. Recommended mitigation steps include adding the domain and its resolving IP address to network‑level blocklists, updating email and web filtering rules to deny connections, and monitoring for any related C2 activity originating from the OVH infrastructure. Continuous re‑evaluation is advised, as the current evidence does not reveal the full scope of the credential‑stealing campaign, but the existing data strongly supports immediate containment.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Análisis de VirusTotal
Evidencias archivadas
Análisis del rendimiento del sitio
Google PageSpeed Insights — mobile performance audit of stains.oridash.fr · checked Mar 2, 2026
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.