# cabershoke.com — SUSPICIOUS > Beware: cabershoke.com is a crypto drainer impersonating OKX. This domain is not OKX — verify URLs on PhishDestroy. Flagged by 0 of 95 VirusTotal vendors. ## Summary PhishDestroy identifies cabershoke.com as an active crypto drainer impersonating the OKX brand. The domain is currently under investigation and remains accessible as of the latest assessment. This domain was flagged by 0 of 95 VirusTotal vendors, indicating it has not yet been widely detected by security engines despite its malicious intent. The domain is registered through NICENIC INTERNATIONAL GROUP CO., LIMITED, resolves to the IP address 172.67.142.237, and was created on April 05, 2025. It operates under an SSL certificate issued by Google Trust Services, which may contribute to a false sense of legitimacy. The domain is not listed on any public blocklists at this time, and its trust scores remain untested due to its recent creation. The current status of cabershoke.com is active, and it continues to pose a significant risk to users who may mistake it for the legitimate OKX platform. To mitigate this threat, users are strongly advised to verify any suspicious URLs using PhishDestroy before entering sensitive information or engaging in financial transactions. Additionally, bookmarking the official OKX website and cross-referencing domain names can prevent accidental visits to impersonation sites. Always ensure SSL certificates are issued to the correct brand and check for discrepancies in domain age and registrar details. If you encounter this domain, report it immediately to PhishDestroy to help protect others in the community. ## Threat Details - Verdict: SUSPICIOUS - Site status: unknown (HTTP ?) - Target brand: OKX ## Domain Intelligence - Registered: 2025-04-05 15:42:55 - Registrar: NICENIC INTERNATIONAL GROUP CO., LIMITED - IP: 172.67.142.237 ## Detection Status - VirusTotal: 0 vendors flagged - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Cloudflare Radar: https://radar.cloudflare.com/scan/af12a648-d420-49a3-9153-3166acd5537b - PhishDestroy: https://phishdestroy.io/domain/cabershoke.com/ - LLM endpoint: https://phishdestroy.io/domain/cabershoke.com/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/cabershoke.com/ Last updated: 2026-03-27