app-ocra[.]so
“Orca | Pools”
app-ocra.so — Conteúdo indisponível. Representação da marca: Orca; Tipo de golpe: Brand Impersonation. Resumo das evidências: VirusTotal 1/93 (Fortinet); URLQuery 4 alerts; Spamhaus DBL_SPAM; 3 external blocklist matches (MetaMask, ScamSniffer, SEAL); PhishDestroy score 74/100. Registrador: NameCheap.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Analysis of the domain app-ocra.so indicates that it was registered on 25 February 2026 through NameCheap, Inc. The authoritative nameservers are dns1.registrar-servers.com and dns2.registrar-servers.com, and the domain resolves to the IPv4 address 82.25.63.187, which is advertised by AS207043 DEDIK SERVICES LIMITED and geolocated to France. No TLS certificate is presented for the host, confirming the absence of HTTPS support. The site’s HTML title, as captured before the domain was taken offline, reads “Orca | Pools”, and the domain is explicitly listed as impersonating the Orca brand. VirusTotal reports a single positive detection out of 93 scanning engines, indicating at least one vendor identified malicious behavior.
Independent blocklist aggregators have added the domain to four separate security blocklists, and it is currently blocked by PhishDestroy, MetaMask, ScamSniffer, and SEAL. The overall risk assessment is elevated, and the operational status is recorded as offline. While the available data confirms the domain’s use for brand‑impersonation, the specific phishing kit, payload, or victim interaction flow has not been publicly disclosed.
The lack of an SSL certificate and the offline status limit real‑time observation of malicious content, leaving the exact lure and credential‑harvesting mechanisms uncertain. Defenders should continue to monitor the IP address 82.25.63.187 for any re‑activation, enforce outbound filtering to block connections to the domain and its hosting ASN, and ensure that any corporate or user‑initiated requests to app‑ocra.so are denied by web‑filtering solutions. Adding the domain to internal blocklists and sharing the indicator with threat‑sharing communities will reduce exposure to the identified Orca impersonation campaign.
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | widget.metacrm.inc/static/js/widget-3-4-1.js |
audit | Hunting_JS_WebAssembly |
| Hagezi Threat Feed | app-ocra.so |
malicious | Sinkholed |
| DNS4EU | calm-spiffy.fontmaxplugin.cc |
malicious | Sinkholed |
| DigiCert UltraDNS | ipfs.io |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências e relatórios externos
PD-20260225-B39B6C Recipient: abuse@namecheap.com Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo