trojantoken[.]live
ملخص الأدلة
This domain, trojantoken.live, poses a high-risk threat as a brand impersonation phishing site targeting users of the cryptocurrency exchange OKX. The site is designed to mimic legitimate OKX login or transaction pages, tricking victims into entering sensitive credentials, private keys, or two-factor authentication codes. Once obtained, these details are used to drain digital wallets or gain unauthorized access to user accounts. The domain employs social engineering tactics, often promoted through malicious ads, compromised social media accounts, or phishing emails, to lure victims into interacting with it. Analysis indicates trojantoken.live was registered on February 21, 2026, through PDR Ltd. d/b/a PublicDomainRegistry.com, a registrar frequently associated with malicious domain registrations. The domain resolves to the IP address 188.114.96.3, hosted on Cloudflare’s infrastructure (AS13335), which is commonly used to obfuscate the true origin of phishing sites. Notably, the domain lacks an SSL certificate, a red flag for users accustomed to secure connections. It is flagged by 11 out of 95 security vendors on VirusTotal and appears on three independent security blocklists, including those maintained by cryptocurrency-focused threat intelligence sources. The domain’s current status is offline, but similar sites often reappear under different names or IP addresses. Users who visited trojantoken.live should assume their credentials or private keys may have been compromised. Immediate actions include revoking access to any connected wallets or accounts, enabling new two-factor authentication methods, and monitoring for unauthorized transactions. If financial assets were transferred, report the incident to the targeted platform (OKX) and relevant law enforcement or cybercrime units. Additionally, scan local devices for malware, as phishing sites often deploy malicious scripts or payloads. Future vigilance is critical: verify domain authenticity by cross-checking URLs with official sources, avoid clicking on unsolicited links, and use browser-based or hardware security tools to block known malicious domains.
Data Coverage
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 11/08/2026
المخطط الزمني للاكتشاف
-
Cloudflare Radar
تم حفظ فحص Cloudflare Radar · فتح الفحص
لقطة محفوظة
معلومات النطاق
التفاصيل التقنيةDNS وأسماء TLS والطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
تحليل VirusTotal
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب