oryvian[.]de
Analyse phishing et sécurité de oryvian.de
“Oryvian - Offizielle Plattform | KI-Trading 2025 | Über 10.000 Bewertungen”
oryvian.de — Contenu indisponible (HTTP 502). Usurpation de l'identité de la marque : Argent. Résumé des preuves: VirusTotal 2/93 (Fortinet, SOCRadar); PhishDestroy score 56/100.
L’analyse détaillée de PhishDestroy AI reste en anglais afin de préserver le relevé forensique original.
Analysis of the domain oryvian.de, registered on 21 February 2026, indicates that it was operated as a phishing site targeting users interested in AI‑driven trading. The site was hosted behind Cloudflare’s network (ASN 13335) and resolved to the IP address 172.67.147.130, which is geolocated in the United States. Cloudflare’s authoritative nameservers kira.ns.cloudflare.com and lynn.ns.cloudflare.com were observed during DNS resolution, confirming the use of a commercial CDN for traffic obfuscation. No TLS certificate was present at the time of collection, and the HTTP service responded without HTTPS, which is atypical for a site attempting to convey legitimacy. The page title returned by the web server read “Oryvian – Offizielle Plattform | KI‑Trading 2025 | Über 10.000 Bewertungen”, suggesting the adversary attempted to present the domain as an official platform for a 2025 AI‑trading service.
No further content was captured because the site was taken offline before a full scrape could be performed. VirusTotal scanned the domain and recorded detections from two of ninety‑three AV engines, indicating partial consensus among security vendors. The domain appears on a single external blocklist and has been actively blocked by the PhishDestroy service, demonstrating that at least one dedicated anti‑phishing platform recognized the threat. No Safe Browsing or Open Threat Exchange entries were reported in the available intelligence.
Overall confidence in the malicious classification is elevated due to the combination of recent creation, use of a reputable CDN for anonymity, observed phishing‑related blocklist entries, and the presence of a deceptive page title. Uncertainty remains regarding the exact phishing workflow, credential‑stealing mechanisms, or any associated command‑and‑control infrastructure because the site was taken offline before deeper forensic capture. Defenders should add oryvian.
Processus de réponse aux menaces Pipeline
Statut de la liste de blocage publique
Analyse VirusTotal
Preuves archivées
Données factuelles et rapports externes
Ce site vous a-t-il affecté ?
Si vous avez saisi des informations d'identification de compte, des informations personnelles ou de paiement, ou téléchargé un fichier à partir de ce domaine, agissez immédiatement. Vous trouverez ci-dessous des ressources pour vous aider à signaler l'incident et à vous protéger.
Signalez-le à vos autorités locales
Sélectionnez votre pays pour obtenir contacts officiels en matière de cybercriminalité ou créer un projet de plainte →.
Vérifier n'importe quel domaine
Analyse des menaces à l'aide de listes de blocage stockées, de WHOIS, de DNS et de preuves d'analyse publique
Scanner maintenantSignaler une tentative d'hameçonnage
Signalez les domaines suspects à notre base de données des menaces — protégez la communauté
SignalerFlux d'alertes en temps réel
Rapports de phishing récents et changements de disponibilité observés
SurveillerRestez informés, restez en sécurité
Surveillez les menaces en temps réel ou signalez cette alerte si vous pensez qu'il s'agit d'un faux positif