What Gridinsoft observed on Omg10.com
A Gridinsoft threat analyst reviewed the site directly and documented the evidence behind this decision.
- Reviewed
- by Gridinsoft Threat Analyst
- Analyst finding
- Suspicious Website
- Evidence basis
- First-party site analysis External vendor intelligence: Context only โ not used for this decision
The independent first-party review confirmed that the supplied omg10.com path is an active advertising redirect endpoint whose destination changes between repeated browser executions. Four runs reached Stake twice, Rainbet once, and a CyberGhost VPN affiliate landing page once. The route also used tracking identifiers, browser-history manipulation, client-dependent code, environment profiling, cookie synchronization, and obfuscated dynamic routing. These directly observed behaviors are incompatible with a high-confidence Safe verdict and support the narrower Suspicious Website classification. No specific malware payload or automatic executable download was identified.
Analyst findings
One URL rotates users across unrelated affiliate destinations
Repeated browser executions of the same omg10.com path produced unrelated gambling, crypto-casino, and VPN affiliate destinations. The destination was therefore not stable or predictable from the source URL.
Client-dependent and obfuscated traffic routing
The route changed its delivered program according to client characteristics and used browser profiling, cookie synchronization, tracking, and online filtering as part of the navigation process. This behavior limits transparency and makes a clean root-page assessment insufficient.
The root information page does not represent the redirect namespace
The root page is a static description of advertising infrastructure, while the supplied /4/ path performs security-relevant third-party routing. Domain age, TLS, and root-page content do not neutralize the directly observed redirect risk.
No specific malware payload identified
The reviewed evidence demonstrates deceptive, rotating, and privacy-relevant advertising navigation. It does not establish that omg10.com delivered a specific malware payload, so the supported category is Suspicious Website rather than a malware-distribution label.
Review 5 documented observations View evidence
The public root page described omg10.com as advertising infrastructure used for ad delivery, tracking, attribution, campaign optimization, and traffic routing rather than as a normal user-facing website.
-
HTTP status
200 -
Final URL
https://omg10.com/ -
Page element
The page stated that advertising materials may originate from third-party advertisers and that the operator does not guarantee third-party content or destinations. -
Page element
The privacy page disclosed processing of IP addresses, device and browser information, referral URLs, cookies, mobile advertising IDs, and similar online identifiers.
The supplied path returned a no-cache redirect document that changed browser history, created a cross-site advertising identifier, sent a tracking beacon, and initiated client-side navigation away from omg10.com.
-
HTTP status
200 -
Page element
The response set OAID and oaidts cookies with a one-year lifetime and SameSite=None. -
Page element
The delivered script called history.pushState three times, sent a beacon to my.rtmark.net, and assigned window.location.href to an external destination. -
Redirect destination
https://s.click.aliexpress.com/
Four independent browser navigations to the same supplied path did not produce a stable destination. The route sent the browser to two gambling or crypto-casino registration destinations and to an unrelated VPN affiliate landing page.
-
Redirect destination
https://stake.com/ -
Redirect destination
https://rainbet.com/ -
Redirect destination
https://safe.cyberghostvpn.com/ -
Analyst observation
stake.com was reached twice; rainbet.com was reached once; safe.cyberghostvpn.com was reached once after an additional advertising redirect.
The same path delivered materially different client code according to the requesting profile. One variant contained an obfuscated advertising-routing program with browser and environment profiling, cookie synchronization, dynamic ad-exchange routing, and online filtration controls.
-
Page element
The larger script included browser and environment capability collection, cookie-sync controls, a dynamic redirect handler, and an onlineFiltrationEnabled option. -
Analyst observation
A mobile browser profile received a short fixed redirect document while another client profile received the larger obfuscated routing program.
The reviewed navigations confirmed deceptive and rotating advertising redirects, but did not identify a specific malware file, executable payload, credential-exfiltration endpoint, malicious file hash, or automatic executable download.
-
Analyst observation
The evidence supports a Suspicious Website classification based on redirect behavior, not a malware-distribution claim.
Scope and limitations
- The review covered the public root and policy pages plus the supplied /4/6912070 redirect object; the domain's complete set of advertising zone identifiers could not be enumerated.
- Redirect destinations are dynamic and may vary by time, location, browser profile, cookies, or advertising inventory; the recorded destinations are representative observations rather than a permanent destination list.
- The destination sites were reviewed only far enough to identify their presented service and the navigation outcome. No account, credential, payment, age-verification, or download flow was completed.
- The result applies to the public behavior reviewed at the recorded time and does not predict future destinations or content.
Help protect others by sharing this page on social media! The more people who know about omg10.com, the fewer chances they have to deceive someone else. Help others evaluate omg10.com by sharing this page on social media!