# backpack-token.xyz — SUSPICIOUS > Discover key findings on backpack-token.xyz, a low-risk domain mimicking OKX. Learn about its activity and technical details here. ## Summary PhishDestroy identifies backpack-token.xyz as a brand impersonation threat targeting OKX. The domain is classified as low risk based on current intelligence and behavior. The domain was created on March 16, 2026, and resolves to IP 104.21.84.242. It is registered through PDR Ltd. d/b/a PublicDomainRegistry.com. VirusTotal flags it in 1 out of 95 security engines, indicating limited detection. These factors suggest a potentially deceptive intent linked to the OKX brand. Currently active, backpack-token.xyz remains under close monitoring by PhishDestroy. Due to its low risk and minor detection footprint, users are advised to exercise caution but no urgent mitigation is recommended at this time. ## Threat Details - Verdict: SUSPICIOUS - Site status: dead (HTTP ?) - Target brand: OKX ## Domain Intelligence - Registered: 2026-03-16 18:42:48 - Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com - Country: IN - IP: 104.21.84.242 - Nameservers: ali.ns.cloudflare.com lamar.ns.cloudflare.com ## Detection Status - VirusTotal: 3 vendors flagged Vendors: ["Forcepoint ThreatSeeker"] - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Screenshot: https://i.ibb.co/21mh6pyV/743a5eb578dd.png - Cloudflare Radar: https://radar.cloudflare.com/scan/4291f653-69ac-4cc4-bc86-56c6205071ef - PhishDestroy: https://phishdestroy.io/domain/backpack-token.xyz/ - LLM endpoint: https://phishdestroy.io/domain/backpack-token.xyz/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/backpack-token.xyz/ Last updated: 2026-03-19