MALICIOUS — CRITICAL
chuyi[.]pro
The domain chuyi.pro was found to be a brand impersonation crypto drainer specifically targeting users of the OKX cryptocurrency exchange.
- VirusTotal
- 12/91
- Blocklists
- No stored match
- التوفر
- آخر نشاط معروف · HTTP 302
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
chuyi.pro — آخر نشاط معروف (HTTP 302). انتحال العلامة التجارية: OKX; نوع الاحتيال: Fake Exchange. ملخص الأدلة: VirusTotal 12/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CRDF, CyRadar); PhishDestroy score 96/100. مسجّل النطاق: Dynadot.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Evidence Analysis
The domain chuyi.pro was found to be a brand impersonation crypto drainer specifically targeting users of the OKX cryptocurrency exchange. This threat type involves creating fake login pages or reward portals to steal credentials and digital assets. The domain's page title, "Earn rewards when you get started on OKX | My referral code: 4475707881 | OKX Europe," further confirms its deceptive intent, luring victims with promises of referral bonuses.
Technical indicators reveal that chuyi.pro has a VirusTotal detection ratio of 1 out of 95 security vendors, indicating it is flagged by at least one engine. The domain was registered through Dynadot Inc and resolves to IP address 54.215.31.113. It was created on April 2, 2026, and its SSL certificate is issued by Let's Encrypt (R13). The domain appears on one security blocklist and is found in 8 AlienVault OTX threat intelligence pulses, but Google Safe Browsing status is not explicitly provided.
Currently, chuyi.pro is offline and has been taken down. However, the risk remains as similar domains may emerge. Users should avoid entering credentials or cryptocurrency wallet information on any site that requests such data through unsolicited links. Always verify URLs directly with the official OKX website and enable two-factor authentication. PhishDestroy continues to monitor for related threats.
نطاق تغطية البيانات12 recorded checks
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
تحليل VirusTotal
الأدلة والتقارير الخارجيةIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.