# dex-tokenclaim.pages.dev — SUSPICIOUS > Dex-tokenclaim.pages.dev is under investigation for impersonating OKX. Avoid interaction and verify legitimacy before sharing data or tokens. ## Summary PhishDestroy identifies dex-tokenclaim.pages.dev as an active threat related to brand impersonation targeting the OKX cryptocurrency platform. The domain uses deceptive content, including a misleading page titled "Benjamin Netanyahu AI | Airdrop," to lure users into potentially fraudulent airdrop schemes. Although the domain currently shows no detection on VirusTotal scans, its suspicious branding and context warrant caution. The domain dex-tokenclaim.pages.dev is registered through Cloudflare, Inc., a common registrar for proxy or shielding services, complicating attribution efforts. It resolves to the IP address 188.114.97.3. Despite the lack of immediate vendor flags on VirusTotal, the nature of the content and the exploit of a reputable brand like OKX indicate potential phishing or scam activity aiming to harvest user credentials or crypto assets. The use of a seemingly unrelated AI and airdrop theme appears intended to misdirect and entice victims. Currently, this campaign remains under investigation with an active status due to ongoing monitoring and risk evaluation. It is recommended users avoid interacting with the domain, refrain from submitting personal or financial information, and verify communications with official OKX channels. Security teams should block or monitor traffic to this domain and maintain vigilance for similar brand impersonation threats leveraging emerging tactics such as AI-themed scams. PhishDestroy will continue tracking dex-tokenclaim.pages.dev for updates on threat evolution and mitigation. ## Threat Details - Verdict: SUSPICIOUS - Site status: alive (HTTP 200) - Target brand: OKX - Page title: Benjamin Netanyahu AI | Airdrop ## Domain Intelligence - Registrar: Cloudflare, Inc. - Country: US - IP: 188.114.97.3 - Nameservers: faye.ns.cloudflare.com stan.ns.cloudflare.com - SSL Issuer: E7 ## Detection Status - VirusTotal: 0 vendors flagged Vendors: [] - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Screenshot: https://urlscan.io/screenshots/019cee40-acf0-776e-9f04-95c4d7417adb.png - Cloudflare Radar: https://radar.cloudflare.com/scan/a976960a-be76-488b-8478-292f16dcc3fc - PhishDestroy: https://phishdestroy.io/domain/dex-tokenclaim.pages.dev/ - LLM endpoint: https://phishdestroy.io/domain/dex-tokenclaim.pages.dev/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/dex-tokenclaim.pages.dev/ Last updated: 2026-03-19