# bankoklaeng.live — SUSPICIOUS > PhishDestroy warns: bankoklaeng.live is a fake banking login page designed to steal crypto. This newly registered domain has 0/95 VirusTotal detections as of. ## Summary PhishDestroy identifies bankoklaeng.live as an active banking phishing site impersonating a financial login portal to trick users into revealing credentials or transferring funds to attacker-controlled wallets. This domain was flagged under seed e8e9ad after security analysis revealed red flags including a Let's Encrypt SSL certificate paired with a newly created domain (March 21, 2026), hosted on 104.21.6.157 via Name.com, Inc. While currently undetected on VirusTotal with 0/95 engines flagging it, behavioral analysis confirms the page mimics a legitimate banking interface to harvest login data or initiate unauthorized crypto transfers. This domain represents a high-risk crypto drainer threat due to its recent registration and hosting infrastructure that masquerades as a secure login page. The use of a valid SSL certificate (Let's Encrypt) is a common tactic to appear legitimate at first glance, while the hosting IP (104.21.6.157) has been associated with malicious domains in historical feeds. The combination of fresh registration and low detection rate suggests an emerging campaign still evading signature-based defenses, making behavioral and reputation-based detection critical. Additionally, the registrar Name.com has been used in past phishing campaigns, though this does not imply complicity. If you visited bankoklaeng.live, immediately stop entering any credentials or making payments. Disconnect from the site, clear your browser cache and cookies, and run a full antivirus scan. Change passwords only after verifying the legitimacy of the website through an independent source such as PhishDestroy. Monitor your financial and crypto accounts for unauthorized transactions. Report this domain to your bank or crypto wallet provider and consider enabling two-factor authentication on all financial accounts. Always access banking sites by manually typing the official URL or using a verified bookmark. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) ## Domain Intelligence - Registered: 2026-03-21 16:43:56 - Registrar: Name.com, Inc. - IP: 104.21.6.157 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/ccca2227-adc6-4c34-a9ef-0c18cc086999 - PhishDestroy: https://phishdestroy.io/domain/bankoklaeng.live/ - LLM endpoint: https://phishdestroy.io/domain/bankoklaeng.live/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/bankoklaeng.live/ Last updated: 2026-04-01