x-token-eligibility-check[.]pages[.]dev
“Xaman | Airdrop”
ملخص الأدلة
PhishDestroy identifies x-token-eligibility-check.pages.dev as an active brand impersonation threat impersonating OKX under investigation. The domain uses a deceptive page title, Xaman | Airdrop, to lure victims into a fraudulent airdrop scheme while mimicking OKX’s branding to appear legitimate. This tactic is consistent with drainer kit operations, where attackers exploit trust in established brands to steal cryptocurrency assets.
This domain was flagged with 0 detections out of 95 on VirusTotal, indicating it has evaded immediate detection by antivirus engines. It is registered through Cloudflare, Inc. and resolves to IP 188.114.96.3 via a Let’s Encrypt SSL certificate. The domain is part of the Cloudflare Pages platform, which has been increasingly abused by threat actors to host phishing and scam pages due to its legitimate infrastructure and ease of deployment. The creation date and Google Safe Browsing (GSB) status remain unverified in current threat intelligence feeds, but it remains unlisted on major blocklists at this time.
The domain is currently active and poses a significant risk to users seeking legitimate OKX services or airdrop opportunities. PhishDestroy recommends immediate blocking of the domain at the network and user level. Users should exercise caution when encountering unsolicited airdrop offers or links purporting to originate from OKX. The remaining risk is classified as active and under investigation, with potential for broader abuse as threat actors refine their tactics. Organizations and individuals are advised to monitor threat intelligence feeds for updates and implement proactive defenses against similar impersonation campaigns.
Data Coverage
استخبارات أمن الشبكات
مسار الاستجابة للتهديدات Pipeline
تغطية قوائم الحظر
١٠ مصادر خارجية مراقبة · لقطة محفوظة 13/08/2026
المخطط الزمني للاكتشاف
-
حالة النطاق
يمكن الوصول إليه ← يتعذر الوصول إليه
التقنيات
حُدّدت ٤ تقنيات عالية الثقة
تحليل VirusTotal
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب