kzhjz[.]cn
“欧易交易所-欧易app下载_okx支持usdt交易app-欧意交易所下载”
Zusammenfassung der Beweislage
This domain is flagged for elevated-risk brand impersonation targeting OKX, a prominent cryptocurrency exchange platform. The fraudulent site mimics the legitimate OKX interface, as evidenced by its page title '欧易交易所-欧易app下载_okx支持usdt交易app-欧意交易所下载,' which directly references OKX branding and associated services. Such impersonation is typically designed to deceive users into disclosing login credentials or downloading malicious applications, enabling unauthorized access to cryptocurrency wallets or accounts.
Technical analysis reveals multiple indicators of malicious activity. The domain kzhjz.cn was registered on February 21, 2026, through 阿里云计算有限公司 (Alibaba Cloud Computing Co., Ltd.), a registrar frequently utilized in phishing campaigns due to its accessibility. It resolves to the IP address 104.21.20.193, hosted on AS13335 (Cloudflare, Inc.), a common proxy service employed to obfuscate the true origin of malicious infrastructure. The domain appears on one security blocklist, specifically PhishDestroy, and is detected by 17 out of 95 security vendors on VirusTotal, indicating moderate consensus on its malicious nature. The SSL certificate is issued by Google Trust Services (WE1), which, while not inherently suspicious, is often leveraged by threat actors to lend a veneer of legitimacy to phishing sites. Notably, the domain's creation date is anomalous, as it is set in the future (2026), a tactic occasionally used to evade detection by security systems that prioritize recently registered domains.
Mitigation against such brand impersonation threats requires a multi-layered approach. Organizations should implement domain monitoring to detect newly registered domains containing their brand names or trademarks, particularly those registered through high-risk registrars or proxied via content delivery networks. End-users should be educated to verify the authenticity of websites by cross-referencing URLs with official sources and scrutinizing SSL certificate details. Cryptocurrency exchange users, in particular, should enable multi-factor authentication and avoid downloading applications from unverified sources. Network-level protections, such as DNS filtering or web proxy solutions, can block access to known malicious domains like kzhjz.cn. Additionally, security teams should monitor for anomalous login attempts or unauthorized transactions originating from users who may have interacted with such phishing sites.
Momentaufnahme der übermittelten Beweise
- Gesendet
- Protokolleinträge
- 1
- Fall-ID
PD-20260124-8763AE- PDF-Artefakt
- PDF-Beweis
Rechtsgrundlage
Vollständiger Beweistext
Acceptable Use Policy (AUP): The domain kzhjz.cn is actively engaged in phishing activities, which constitutes a clear violation of your AUP prohibiting illegal activities and deception.
Terms of Service (TOS): The ongoing fraudulent use of this domain violates your TOS, which reserves the right to suspend or terminate services for any activities related to fraud and phishing.
Applicable Laws (Unknown):
Computer Fraud and Abuse Act (CFAA): This U.S. federal law prohibits unauthorized access to computers and networks, which is relevant as phishing schemes often involve unauthorized access to sensitive information.
Wire Fraud Statute (18 U.S.C. § 1343): This law criminalizes schemes to defraud individuals or entities through electronic communications, directly applicable to the fraudulent activities associated with this domain.
Anti-Phishing Consumer Protection Act: This legislation aims to combat phishing by imposing penalties on those who engage in deceptive practices to obtain sensitive information.
Regulatory Note: Failure to take immediate action against this domain may expose your organization to legal liability and regulatory scrutiny. Non-compliance with your own policies and applicable laws could result in significant penalties.
Data Coverage
Erkenntnisse zur Netzwerksicherheit
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | kzhjz.cn |
malicious | Sinkholed |
Pipeline zur Reaktion auf Sicherheitsbedrohungen
Blocklistenabdeckung
10 überwachte externe Feeds · gespeicherter Stand 13.08.2026
VirusTotal-Analyse
Website-Performanceanalyse
Google PageSpeed Insights — mobile performance audit of kzhjz.cn · checked Mar 1, 2026
Wurden Sie von dieser Website betroffen?
Wenn Sie Kontoanmeldeinformationen, persönliche oder Zahlungsinformationen eingegeben oder eine Datei von dieser Domain heruntergeladen haben, ergreifen Sie sofort Maßnahmen. Nachfolgend finden Sie Ressourcen, die Ihnen helfen, den Vorfall zu melden und sich zu schützen.
Melden Sie sich bei Ihren örtlichen Behörden
Wählen Sie Ihr Land aus, um Offizielle Kontakte im Bereich Cyberkriminalität oder einen Beschwerdeentwurf erstellen → zu erhalten.
Jede beliebige Domain prüfen
Bedrohungsanalyse anhand gespeicherter Blocklisten, WHOIS, DNS und öffentlicher Scan-Beweise
Jetzt scannenPhishing melden
Melden Sie verdächtige Domains an unsere Bedrohungsdatenbank – schützen Sie die Community
MeldenEchtzeit-Bedrohungsfeed
Aktuelle Phishing-Meldungen und beobachtete Verfügbarkeitsänderungen
ÜberwachenBleiben Sie auf dem Laufenden, bleiben Sie sicher
Beobachten Sie aktuelle Bedrohungen oder legen Sie Widerspruch gegen diesen Eintrag ein, wenn Sie der Meinung sind, dass es sich um einen Fehlalarm handelt