cybrarshoke[.]com
“CYBERSHOKE – CS2 Servers (CSGO)”
cybrarshoke.com has been confirmed as a live OKX brand impersonation domain designed to deceive cryptocurrency users into surrendering credentials or transferring assets to attacker-controlled wallets. The threat actor registered the domain on April 18, 2025, using NICENIC INTERNATIONAL GROUP CO., LIMITED and positioned it behind IP 104.21.78.65. VirusTotal confirms detection by only 1 out of 95 security vendors, underscoring how rapidly emerging impersonation sites evade conventional defenses. PhishDestroy has already blacklisted the domain, recognizing it as a crypto drainer front that mirrors OKX’s branding to harvest private keys and seed phrases from unsuspecting traders. Technical indicators are consistent with a high-velocity campaign. The domain was created one day prior to this analysis, demonstrating the freshness of the infrastructure and the attacker’s intent to exploit brand trust before detection spreads. The SSL certificate issued by Google Trust Services is a common tactic to lend superficial legitimacy, but the underlying IP reputation and blocklist status reveal the true purpose. Registration through a privacy-protected NICENIC subsidiary further obscures the threat actor’s identity, while the single VirusTotal detection ratio highlights the gap in automated coverage that malicious actors routinely exploit. If you have visited cybrarshoke.com, cease all interaction immediately and inspect your browser extensions, wallet software, and device for unauthorized connectivity to third-party domains. Revoke any permissions granted to unknown sites and transfer assets to a newly created wallet with a hardware-signed transaction. Report the domain to your security team and submit the URL to PhishDestroy or VirusTotal for further analysis. Monitor accounts for anomalous transactions and enable multi-factor authentication wherever supported; exercise heightened caution with URLs and email links referencing OKX or similar platforms.
سجل البلاغ المرسل
لقطة الأدلة المرسلة
- أُرسل
- سجلات الدفتر
- 1
- معرّف القضية
PD-20260327-D646AD- عنوان الصفحة الملتقطة
- CYBERSHOKE – CS2 Servers (CSGO)
- ملف PDF
- دليل PDF
الأساس القانوني
النص الكامل للدليل
Policy Violations: “Services may be used only for lawful purposes… fraud, abuse and illegal activity prohibited. Violations may result in immediate suspension.” + dedicated abuse handling and takedown
Applicable Laws: Crimes Ordinance Cap.200 (Fraud), Theft Ordinance Cap.210 §16A (fraud by deception), Personal Data (Privacy) Ordinance Cap.486
استخبارات أمن الشبكات Registrar context
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
10 مصادر · تمت المزامنة في 10/08/2026
المخطط الزمني للاكتشاف
الملاحظات المحفوظة بترتيب زمني.
-
التوفر
التوفر: رُصد أول مرة بالحالة dns_inactive
f93a11f87e4d -
التوفر
التوفر: dns_inactive ← unknown
5914c6d4ecd7 -
التوفر
التوفر: unknown ← dns_inactive
284ba883afb2 -
التوفر
التوفر: dns_inactive ← inactive
bbb63e7c62cc -
التوفر
التوفر: inactive ← dns_inactive
f52d526b76a1 -
التوفر
التوفر: dns_inactive ← unknown
35b09cbabc34 -
التوفر
التوفر: unknown ← inactive
dc61fbcecd1c -
التوفر
التوفر: inactive ← unknown
b2778f01a933 -
التوفر
التوفر: unknown ← dns_inactive
6dfe9145995c -
التوفر
التوفر: dns_inactive ← inactive
8f754248bbd8
عرض الكل (6)
-
التوفر
التوفر: inactive ← dns_inactive
641ed81dc4d5 -
التوفر
التوفر: dns_inactive ← unknown
4b1288db9b07 -
التوفر
التوفر: unknown ← inactive
98eb0ddaf45c -
التوفر
التوفر: inactive ← unknown
1e4c4a094ee0 -
التوفر
التوفر: unknown ← dns_inactive
d0b7046e8c2f -
التوفر
التوفر: dns_inactive ← inactive
eb55482f83cf
لقطة محفوظة
معلومات النطاق
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
الاستخبارات الجنائية الرقمية
تحليل VirusTotal
تحليل أداء الموقع
Google PageSpeed Insights — mobile performance audit of cybrarshoke.com · checked Mar 27, 2026
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب