orangex-korea[.]at
“OrangeX 로그인 - 최고의 암호화폐 거래소 | OrangeX Login Exchange”
orangex-korea.at — सामग्री अनुपलब्ध. ब्रांड प्रतिरूपण: Facebook; घोटाले का प्रकार: Fake Exchange. साक्ष्य सारांश: VirusTotal 5/93 (ADMINUSLabs, G-Data, SOCRadar, Sophos, alphaMountain.ai); Spamhaus DBL_PHISH; PhishDestroy score 65/100. रजिस्ट्रार: Iqweb.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
The domain orangex-korea.at was registered on 27 February 2026 through the registrar Iqweb and is currently taken offline. DNS resolution points to the IP address 186.2.175.29, which belongs to AS59692 IQWeb FZ-LLC and is geolocated to a BZ address block. The domain is served by four CloudNS nameservers (pns71.cloudns.net, pns72.cloudns.com, pns73.cloudns.net, pns74.cloudns.uk) and presents a TLS certificate issued by Let’s Encrypt (R13). The site’s page title, "OrangeX 로그인 - 최고의 암호화폐 거래소 | OrangeX Login Exchange," indicates an attempt to impersonate a cryptocurrency exchange, matching the classified scam type of a fake exchange.
Technical fingerprinting shows the presence of jQuery, Hammer.js, and DDoS‑Guard scripts, suggesting a typical phishing hosting stack. Reputation checks reveal a Gridinsoft trust score of 0 / 100 and inclusion on a single security blocklist. VirusTotal analysis recorded five detections out of ninety‑three scanning engines, confirming malicious activity, and the domain is listed by PhishDestroy as blocked.
While the offline status prevents real‑time content verification, the convergence of registrar information, IP ownership, SSL details, page title, and detection counts provides strong evidence that orangex-korea.at was used for credential‑harvesting targeting cryptocurrency users. Defenders should continue to block the domain at network perimeter devices, monitor for any resurgence of the host infrastructure, and update URL filtering and endpoint protection rules to reflect the observed indicators. Further investigation is needed to determine whether additional sub‑domains or related IP assets are being leveraged for the same campaign.
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
तकनीकें · 3 identified
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
वायरसटोटल विश्लेषण
संग्रहीत साक्ष्य
साइट प्रदर्शन विश्लेषण
Google PageSpeed Insights — mobile performance audit of orangex-korea.at · checked Mar 2, 2026
साक्ष्य और बाहरी रिपोर्टें
PD-20260227-0439DA Recipient: abuse@iqweb.io क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।