MALICIOUS — CRITICAL
ogaudit[.]com
4 of 91 security engines flagged the domain; URLQuery recorded 2 threat-system alerts; the latest stored check returned HTTP 200.
- VirusTotal
- 4/91
- Blocklists
- No stored match
- 可用性
- 最後に確認されたアクティブな状態 · HTTP 200
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse-complaints@squarespace.com.
The latest stored availability evidence still shows the domain reachable; 3 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
Jump to section
ogaudit.com — 最後に確認されたアクティブな状態 (HTTP 200). 詐欺タイプ: Credential Phishing. 証拠の概要: VirusTotal 4/91 (alphaMountain.ai, CRDF, Gridinsoft, SOCRadar); URLQuery 2 alerts; PhishDestroy score 78/100. レジストラ: Squarespace Domains II.
元のフォレンジック記録を保持するため、下の PhishDestroy AI 詳細分析は英語のままです。
Evidence Digest
ogaudit.com has a stored critical classification with an evidence score of 78/100. 4 of 91 security engines flagged the domain. Registered 22 Aug 2023 via Squarespace Domains II LLC, hosted on 188.114.96.3 (Cloudflare, Inc., CA). The latest stored check on 9 Aug 2026 returned HTTP 200 and includes a capture. 1 outgoing abuse report is recorded, most recently on 30 Apr 2026.
Stored generated summary (templated)mistral · 2026年4月30日
Retained for the record. This text repeats stored detection facts and is not presented as authored analysis.
The domain ogaudit.com has been identified as a phishing site hosting a fake login page, posing an immediate risk to users' credentials and sensitive data. This domain is actively engaged in malicious activities designed to deceive visitors into entering personal information under false pretenses. The threat is classified as elevated due to its current operational status and confirmed malicious intent. PhishDestroy identifies that ogaudit.com is flagged by 3 of 95 VirusTotal security vendors, indicating a low but notable detection rate among industry-standard tools. The domain is registered through Squarespace Domains II LLC and resolves to IP address 188.114.96.3. This IP is associated with hosting infrastructure known for malicious activity. Additionally, ogaudit.com has appeared on 2 security blocklists, further validating its malicious reputation. The domain was created on August 22, 2023, and currently holds a valid SSL certificate issued by Google Trust Services, which may contribute to a false sense of legitimacy. Despite these measures, the domain remains blocked by MetaMask and SEAL, highlighting its confirmed malicious nature. The domain ogaudit.com is currently active and poses an ongoing threat to users who may encounter it. Users are strongly advised to avoid accessing this domain and to verify any suspicious links using PhishDestroy's tools before interacting with them. It is crucial to rely on trusted sources and security platforms to confirm the legitimacy of websites, especially those requesting login credentials or sensitive information. If this domain has been encountered in emails, messages, or other digital communications, users should report it to their security teams or relevant authorities immediately to prevent further exploitation.
データの網羅性13 recorded checks
ネットワークセキュリティインテリジェンス
脅威対応 Pipeline
公開ブロックリスト登録状況
保存済みキャプチャ
ドメイン・インテリジェンス
技術的な詳細DNS、SSL SAN、タイムスタンプ
ICANN OVERSIGHT
認定と RAA の背景
認定と RAA の背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
使用技術 · 13 identified
Bootstrap is a free and open-source CSS framework directed at responsive, mobile-first front-end web development. It contains CSS and JavaScript-based design templates for typography, forms, buttons, navigation, and other interface components.
getbootstrap.com 信頼度 100%SweetAlert2 is a JavaScript library that provides customisable, visually appealing, and responsive alert and modal dialog boxes for web applications.
sweetalert2.github.io 信頼度 100%Select2 is a jQuery based replacement for select boxes. It supports searching, remote data sets, and infinite scrolling of results.
select2.org 信頼度 100%OWL Carousel is an enabled jQuery plugin that lets you create responsive carousel sliders.
owlcarousel2.github.io 信頼度 100%JSDelivr is a free public CDN for open-source projects. It can serve web files directly from the npm registry and GitHub repositories without any configuration.
www.jsdelivr.com 信頼度 100%jQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
jquery.com 信頼度 100%HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 信頼度 100%Google Analytics is a free web analytics service that tracks and reports website traffic.
google.com 信頼度 100%DataTables is a plug-in for the jQuery Javascript library adding advanced features like pagination, instant search, themes, and more to any HTML table.
datatables.net 信頼度 100%Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 信頼度 100%Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 信頼度 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 信頼度 100%VirusTotalによる分析
証拠および外部報告書Independent lookups and source reports
“URGENT – Phishing / Crypto Wallet Drainer This domain (https://ogaudit.com/) is conducting phishing attacks and draining user wallets via malicious signature requests (EIP-7702 delegation). This constitutes financial fraud and user fund theft. Please investigate and suspend the domain immediately. Evidence: - Users report wallet draining after connection - Malicious wallet interactions (phishing signature prompts) Evidence Tx: Arbitrum One Transaction Hash: 0x05a2ea69b4... | Arbitrum One”
PD-20260430-ED5C84 Recipient: abuse-complaints@squarespace.com Victim safety and official reportingImmediate actions and verified reporting channels
このドメインを操作したり、個人情報を入力したり、暗号通貨ウォレットに接続したりした場合は、直ちに行動を起こしてください。インシデントを報告し、自分自身を守るのに役立つリソースを以下に示します。
お住まいの地域の当局へ報告してください
サイバー犯罪の公式連絡先 または 苦情草稿を作成する → を取得するには、国を選択してください。
Wallet incident responseActions, evidence preservation, and official reporting
Use this section only if you connected a wallet, signed a transaction, disclosed a seed phrase, or transferred funds through ogaudit.com.
今すぐ何をすべきでしょうか?
至急
- トークンの承認を取り消す — use revoke.cash 悪意のあるスマートコントラクトに付与されたアクセス権を取り消す
- 残りの資金を移動する まったく新しいウォレットへ。セキュリティが侵害されたウォレットは、もはや安全ではありません
- すべてのパスワードを変更する — メール、Exchangeアカウントなど、同じパスワードを使用しているものすべて
- 2段階認証を有効にする 認証アプリ(SMSではない)を使用する。SMSによる復旧機能を無効にする
- カードの凍結 フィッシングサイトに銀行口座情報を入力してしまった場合
レポート作成のために、どのような情報を収集すべきでしょうか?
FBIのガイドライン
によると、 FBI、最も重要な詳細はトランザクションデータです:
- 仮想通貨アドレス — 詐欺師の財布(例:
0x5856...35985) - 金額および仮想通貨の種類 — 正確な金額(例:1.02345 ETH、0.5 BTC、500 USDT)
- トランザクションID(ハッシュ) — ブロックチェーン上の取引を識別するための固有の識別子
- 正確な日時 — 各取引および詐欺師との最初の接触について
- スクリーンショット — 詐欺サイト、チャットメッセージ、メール、ウォレットでの取引、ソーシャルメディア
- すべてのURLおよびドメイン 詐欺師が使用した(以下を含む)
ogaudit.com) - コミュニケーション — 詐欺師が使用したメール、テキストメッセージ、電話番号、ユーザー名
たとえすべての詳細がわかっていなくても―― とにかく報告を提出する. 不完全な情報であっても、捜査には役立つ。
この詐欺はどこに通報すればいいですか?
- FBI IC3 — インターネット犯罪通報センター(米国連邦政府の通報窓口)
- ユーロポール — 欧州におけるサイバー犯罪の報告(EU)
- Chainabuse — 取引所やプラットフォーム間で詐欺ウォレットを特定する
- あなたの仮想通貨取引所 — notify its fraud team immediately; it may be able to preserve records or restrict funds held on its platform
- 地元の警察 — たとえ直ちに行動を起こせなくても、公式な記録が残される
A report is not a guarantee of recovery or investigation, but prompt, accurate transaction data can help authorities and service providers trace the incident.
仮想通貨詐欺は通常、どのような手口で行われるのでしょうか?
- 偽のウェブサイト — 正規サイトのドメインをわずかに変更した、ピクセル単位で完璧に再現されたクローンサイト
- 悪意のある承認 — 「connect wallet」というプロンプトが表示されると、攻撃者にトークンの無制限な使用権限が与えられてしまう
- pig butchering — TelegramやWhatsApp、出会い系アプリを通じて数週間にわたって信頼関係を築き、その後、金銭をだまし取られる
- 詐欺による金銭の返還を装った詐欺 — fraudsters pose as recovery agents and demand upfront fees. Never share a seed phrase or pay before independently verifying the provider
- 偽の広告とエアドロップ — Googleやソーシャルメディアの広告、および「無料トークン」のオファーが、財布を空にするようなアプリへと誘導している
- AIを利用した詐欺 — ディープフェイク、自動化されたフィッシング、AI生成サイトにより、詐欺の発見が難しくなっている
今後、どうすれば身を守ることができるでしょうか?
- ハードウェアウォレットを使用する (Ledger、Trezor)。ブラウザウォレットには決して多額の資産を保管しないでください
- 公式サイトをブックマークする — メール、DM、広告に含まれるリンクは絶対にクリックしないでください
- すべての承認内容を確認する — 署名する前に権限を確認してください。無制限の承認は拒否してください
- ドメインの確認 — 確認する PhishDestroy 操作を行う前に、HTTPS、スペル、ドメインの登録期間を確認してください。
- 「良すぎて怪しい」=詐欺 — 確実なリターン、有名人の推薦、差し迫った締め切り