soracas[.]com
“Soracas: Most Popular Online Crypto Casino Based on Blockchain”
soracas.com — Conteúdo indisponível (HTTP 502). Representação da marca: Genericcrypto; Tipo de golpe: Crypto Scam. Resumo das evidências: VirusTotal 12/95 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, Forcepoint ThreatSeeker); URLQuery 100 det.; URLScan malicious verdict; PhishDestroy score 100/100. Registrador: Dominet (HK).
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Analysis as of July 23 2026 indicates that soracas.com was registered on November 5 2025 via Dominet (HK) Limited and resolved to Cloudflare IP 104.21.48.150, belonging to AS13335 Cloudflare, Inc., United States. The domain used the authoritative nameservers jeremy.ns.cloudflare.com and margaret.ns.cloudflare.com, consistent with the Cloudflare hosting. No TLS certificate was observed, suggesting the site operated over plain HTTP or presented an invalid certificate. The page title returned by the live check was “Soracas: Most Popular Online Crypto Casino Based on Blockchain,” aligning with the listed scam type of a crypto scam and the identified Gambler Scam phishing kit.
The infrastructure has been taken offline, but it was previously listed on a single security blocklist and is currently blocked by PhishDestroy. Independent scanning on VirusTotal recorded 12 detections out of 95 security vendors, reinforcing the malicious classification. Gridinsoft assigned a trust score of 1 out of 100, indicating an extremely low reputation. The combination of a recent registration date, use of a reputable CDN for anonymity, lack of proper TLS, and presence on blocklists points to a purposeful campaign targeting cryptocurrency enthusiasts through a fabricated online casino front.
Uncertainties remain regarding the exact content served before takedown, the extent of victim interaction, and whether any payloads were delivered. Defenders should add soracas.com and its associated IP 104.21.48.150 to internal block and monitoring lists, enforce TLS inspection to detect any future re‑hosting attempts, and correlate any alerts from the 12 VirusTotal‑identified signatures with endpoint telemetry. Continuous watch of the registrar Dominet (HK) Limited for potential batch registrations is also advised.
Sinais de segurança
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Análise do VirusTotal
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo