picorechain[.]ru
“Home”
picorechain.ru — Conteúdo indisponível (HTTP 502). Resumo das evidências: VirusTotal 13/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); PhishDestroy score 89/100. Registrador: R01-RU.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Analysis of picorechain.ru conducted on 23 July 2026 confirms that the domain is currently offline but retains several indicators of malicious infrastructure. The domain was registered on 22 November 2024 through the R01‑RU registrar and uses the expired‑r01.ru nameserver pair ns1.expired.r01.ru and ns2.expired.r01.ru, a configuration commonly observed in abuse cases. DNS resolution points to the IPv4 address 194.36.191.196, which belongs to AS60117 (Host Sailor Ltd) in the Netherlands. No TLS certificate is presented for the host, indicating that any communication would occur over plain HTTP. The sole HTML title returned from the site is the generic string “Home”, and no additional page content has been captured, leaving the exact phishing payload undefined. Reputation services have flagged the domain.
PhishDestroy lists it as blocked, and it appears on one additional security blocklist. Gridinsoft assigns a trust score of 0 out of 100, the lowest possible rating. VirusTotal reports that 13 out of 95 scanned engines label the domain as malicious, reinforcing the suspicion of phishing intent. The limited detection count suggests that the site may have been short‑lived or hosted on a shared infrastructure that evaded broader scanning. Because the site is offline, direct observation of malicious pages, credential‑harvesting forms, or redirect chains is not possible. The lack of an SSL certificate and the generic page title prevent verification of the specific brand or campaign being impersonated.
No Safe Browsing, OTX, or additional vendor feeds are referenced in the supplied intelligence, so the broader threat landscape surrounding picorechain.ru remains unclear. Defenders should continue to block network traffic to 194.36.191.196 and to the domain itself at DNS and proxy layers. Monitoring of the hosting ASN (AS60117) for new domains that resolve to the same IP range is advised, as attackers frequently recycle infrastructure.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo