MALICIOUS — CRITICAL
Verificação de phishing e segurança de oreprotocol-research.com
oreprotocol-research[.]
The domain oreprotocol-research.com has been identified as a high-risk cryptocurrency phishing resource.
- VirusTotal
- 5/91
- Blocklists
- 2 · MetaMask, SEAL
- Disponibilidade
- Conteúdo indisponível · HTTP 503
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
oreprotocol-research.com — Conteúdo indisponível (HTTP 503). Resumo das evidências: VirusTotal 5/91 (ADMINUSLabs, alphaMountain.ai, CRDF, Forcepoint ThreatSeeker, Kaspersky); URLQuery 2 alerts; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 90/100. Registrador: Hostinger.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Evidence Analysis
The domain oreprotocol-research.com has been identified as a high-risk cryptocurrency phishing resource. Analysis indicates it is designed to impersonate legitimate blockchain research or protocol platforms, likely targeting users with credential harvesting schemes for digital wallets or decentralized applications. As of the latest assessment, the domain is currently offline, though prior activity suggests it may resurface under similar infrastructure. Infrastructure analysis reveals the domain was registered on June 1, 2026, through HOSTINGER operations, UAB, a registrar frequently associated with newly created phishing domains. It resolves to the IP address 187.77.24.2, which has been linked to other malicious campaigns in recent threat intelligence reports. Detection metrics show the domain was flagged by 13 of 95 security vendors on VirusTotal, with additional listings on three independent security blocklists. AlienVault OTX records further confirm its presence in two distinct threat intelligence pulses, underscoring its active use in phishing operations. The domain’s rapid inclusion in multiple blocklists and its association with known malicious infrastructure contribute to its high-risk classification. Current status indicates the domain has been taken offline, though historical patterns suggest threat actors may re-deploy similar domains using comparable naming conventions or infrastructure. Organizations and individual users are advised to monitor for domains mimicking legitimate cryptocurrency protocols, particularly those registered through bulk registrars or resolving to IPs with prior malicious associations. Network-level blocking of the IP 187.77.24.2 is recommended as a preventive measure. Security teams should also review logs for connections to this IP or domain, particularly in environments where cryptocurrency-related activities occur. Proactive threat hunting for related indicators of compromise, such as similar domain registrations or SSL certificate patterns, is strongly encouraged to mitigate future risks.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
Cobertura dos dados12 recorded checks
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | oreprotocol-research.com |
malicious | Sinkholed |
| DNS4EU | oreprotocol-research.com |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análise do VirusTotal
Evidências e relatórios externosIndependent lookups and source reports
PD-20260606-8AE635 Recipient: abuse@hostinger.com Victim safety and official reportingImmediate actions and verified reporting channels
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.