ordexia-bot[.]com
“OrdexiaBot - Plataforma Oficial | Trading IA 2025 | Más de 10.000 Reseñas”
Résumé des preuves
Analysis of the domain ordexia-bot.com, registered February 21, 2026, indicates active brand impersonation targeting the Base platform. The domain was taken offline by July 24, 2026, following detection by PhishDestroy. Infrastructure analysis reveals Cloudflare hosting (AS13335) on IP 188.114.96.3, with nameservers chad.ns.cloudflare.com and shubhi.ns.cloudflare.com. No SSL certificate was observed.
The page title, 'OrdexiaBot - Plataforma Oficial | Trading IA 2025 | Más de 10.000 Reseñas,' explicitly references an official trading platform, aligning with the brand impersonation classification. Detection data is limited: one of 93 security vendors on VirusTotal flagged the domain, and it appears on a single security blocklist. Gridinsoft assigned a trust score of 0/100, reinforcing its malicious classification. The domain was registered through Metaregistrar BV, though no additional registrar abuse contacts or historical patterns are documented.
While the exact content of the site remains unanalyzed, the page title and scam type suggest an attempt to deceive users into engaging with a fraudulent trading service under the guise of Base's branding. Defenders should treat this domain as confirmed malicious, block it at the DNS and proxy levels, and monitor for related infrastructure (e.g., Cloudflare IPs or similar naming conventions). Given its offline status, no active payloads are expected, but retrospective log analysis may identify prior victim interactions. Further investigation into the hosting provider and registrar could uncover additional linked domains or campaigns.
Instantané des preuves transmises
- Envoyé
- Entrées du registre
- 1
- ID du dossier
PD-20260107-DDA67D- Titre de la page capturée
- OrdexiaBot - Plataforma Oficial | Trading IA 2025 | Más de 10.000 Reseñas
- Artefact PDF
- Preuve PDF
Fondement juridique
Texte intégral des preuves
Acceptable Use Policy (AUP): The domain ordexia-bot.com is engaged in phishing activities, which directly contravenes the AUP by facilitating fraud and deception.
Terms of Service (TOS): The registrar reserves the right to suspend or terminate services for violations, and the ongoing use of this domain for illegal activities warrants immediate action.
Applicable Laws (Unknown):
Computer Fraud and Abuse Act (CFAA): This U.S. law prohibits unauthorized access to computers and networks, which is applicable as phishing schemes often involve unauthorized data access.
Wire Fraud Statute (18 U.S.C. § 1343): This law criminalizes schemes to defraud individuals or entities via electronic communications, which is relevant to the phishing activities associated with this domain.
CAN-SPAM Act (15 U.S.C. § 7701): This legislation regulates commercial email and prohibits deceptive practices, which are inherent in phishing operations.
Regulatory Note: Failure to take prompt action against this domain may expose your organization to legal liability and regulatory scrutiny. Immediate suspension is recommended to mitigate risks associated with non-compliance.
Data Coverage
Processus de réponse aux menaces Pipeline
Couverture des listes de blocage
10 sources externes surveillées · instantané du 12/08/2026
10 sources externes surveillées Aucune correspondance
Chronologie de détection
-
Cloudflare Radar
Analyse Cloudflare Radar enregistrée · Ouvrir l’analyse
Capture enregistrée
Informations sur les domaines
Détails techniquesDNS, noms TLS et horodatages
ICANN OVERSIGHT
Contexte de l’accréditation et du RAA
Contexte de l’accréditation et du RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Analyse VirusTotal
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif