pay-for-okx-usdt-0000000006[.]pages[.]dev
“OKX”
pay-for-okx-usdt-0000000006.pages.dev — لم يتم التحقق منها. انتحال العلامة التجارية: OKX; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VirusTotal 14/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar, ESET); URLQuery 1 alert; PhishDestroy score 97/100. مسجّل النطاق: Cloudflare.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Analysis of the domain pay-for-okx-usdt-0000000006.pages.dev indicates active brand impersonation targeting OKX, a cryptocurrency exchange. The domain, registered on April 27, 2026, resolves to IP 172.66.47.12 and is hosted on Cloudflare infrastructure, as evidenced by nameservers jim.ns.cloudflare.com and serenity.ns.cloudflare.com. The SSL certificate is issued by Google Trust Services (WE1), and the site returns an HTTP 200 status, confirming operational status as of July 12, 2026. Detected technologies include jQuery, HSTS, and HTTP/3, consistent with modern web applications. The page title explicitly displays 'OKX,' aligning with the reported scam type of brand impersonation. Security vendors have flagged this domain, with 14 of 91 engines on VirusTotal identifying it as malicious. It appears on one security blocklist and is currently blocked by PhishDestroy. The domain's trust score is 0/100, further supporting its classification as high-risk. Defenders should treat this domain as an active threat. Indicators such as the Cloudflare-hosted infrastructure, recent registration date, and alignment with known OKX impersonation tactics warrant immediate blocking at the DNS or proxy level. The exact content of the site remains unanalyzed, but the combination of technical indicators and brand targeting confirms its malicious intent. No legitimate association with OKX is known, and the domain should be considered hostile until further analysis disproves its fraudulent nature.
استخبارات أمن الشبكات
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | pay-for-okx-usdt-0000000006.pages.dev |
malicious | Sinkholed |
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
التقنيات · 4 identified
jQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
jquery.com ثقة 100٪HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org ثقة 100٪Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com ثقة 100٪HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org ثقة 100٪تحليل VirusTotal
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب