cybelshoke[.]com
“CYBERSHOKE – CS2 Servers (CSGO)”
PhishDestroy identifies cybelshoke.com as an active OKX brand impersonation domain hosting a cryptocurrency drainer kit. The site leverages visual assets and terminology indistinguishable from legitimate OKX support channels to dupe users into connecting wallets and approving malicious token transfers. Domain registration coincided with a recent uptick in fake exchange support campaigns, suggesting coordinated opportunistic fraud rather than a lone actor.
This domain was flagged by 6 of 95 VirusTotal security vendors and currently exhibits the following technical indicators: registration dated March 27, 2025, through NICENIC INTERNATIONAL GROUP CO., LIMITED, resolving to IP 188.114.97.3 and secured via a Google Trust Services SSL certificate. Six other reputable databases already list the domain, cumulative blocklist coverage now totals 6/8.
Authorities have not yet remediated the domain; it remains live and accessible. Users should immediately block 188.114.97.3 at the firewall and browser policy levels, cease any interaction with cybelshoke.com, and verify all future OKX support queries against the exchange’s official domain list. Persistent elevated risk warrants heightened monitoring for downstream wallet compromise and downstream fraud campaign propagation.
سجل البلاغ المرسل
لقطة الأدلة المرسلة
- أُرسل
- سجلات الدفتر
- 1
- معرّف القضية
PD-20260327-DFF668- عنوان الصفحة الملتقطة
- CYBERSHOKE – CS2 Servers (CSGO)
- ملف PDF
- دليل PDF
الأساس القانوني
النص الكامل للدليل
Policy Violations: “Services may be used only for lawful purposes… fraud, abuse and illegal activity prohibited. Violations may result in immediate suspension.” + dedicated abuse handling and takedown
Applicable Laws: Crimes Ordinance Cap.200 (Fraud), Theft Ordinance Cap.210 §16A (fraud by deception), Personal Data (Privacy) Ordinance Cap.486
استخبارات أمن الشبكات Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | cybelshoke.com |
malicious | Sinkholed |
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
10 مصادر · تمت المزامنة في 09/08/2026
أدلة النتيجة المحفوظة
النتيجة وإسناد الإزالة
- النتيجة
inactive- السبب
rdap_not_registered- الآلية
rdap_404- درجة الثقة
- 90%
وقت التعطل التقديري
نطاق عدم اليقين: ±1695.57 h دقة الوقت:very_low المخطط الزمني للاكتشاف
الملاحظات المحفوظة بترتيب زمني.
-
التوفر
التوفر: رُصد أول مرة بالحالة dns_inactive
f93a11f87e4d -
التوفر
التوفر: dns_inactive ← unknown
5914c6d4ecd7 -
التوفر
التوفر: unknown ← dns_inactive
284ba883afb2 -
التوفر
التوفر: dns_inactive ← inactive
3b8e28f44e47 -
التوفر
التوفر: inactive ← dns_inactive
f52d526b76a1 -
التوفر
التوفر: dns_inactive ← unknown
7bc9ccc36f5c -
التوفر
التوفر: unknown ← inactive
f4d9ba39fc22 -
التوفر
التوفر: inactive ← unknown
cfc7c1249392 -
التوفر
التوفر: unknown ← dns_inactive
6dfe9145995c -
التوفر
التوفر: dns_inactive ← inactive
a15b2dbdf29b
عرض الكل (6)
-
التوفر
التوفر: inactive ← dns_inactive
641ed81dc4d5 -
التوفر
التوفر: dns_inactive ← unknown
3bdb9dd691e9 -
التوفر
التوفر: unknown ← inactive
48b89ed7fae2 -
التوفر
التوفر: inactive ← unknown
d71a707d8d3c -
التوفر
التوفر: unknown ← dns_inactive
d0b7046e8c2f -
التوفر
التوفر: dns_inactive ← inactive
bce616beea5e
لقطة محفوظة
معلومات النطاق
التفاصيل التقنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of cybelshoke.com · checked Mar 27, 2026
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب