# PhishDestroy threat dossier — tokenpocket.run ================================================================ Fetched: 2026-05-05 11:58:35 UTC Canonical: https://phishdestroy.io/domain/tokenpocket.run/ ## VERDICT ---------------------------------------------------------------- HIGH THREAT — malicious activity confirmed Composite threat score: 77/100 (PhishDestroy scoring — see methodology below) Scam classification: Impersonation Targeted brand: OKX ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 0/95 security vendors flagged this domain ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 188.114.96.3 (CA, Toronto) ASN: AS13335 Cloudflare, Inc. Hosting org: CloudFlare, Inc. Registrar: GoDaddy.com, LLC Nameservers: khalid.ns.cloudflare.com, raquel.ns.cloudflare.com Registered: 2026-03-25 Expires: 2027-03-25 Page title: TokenPocket - \u8ba9\u533a\u5757\u94fe\u968f\u5904\u53d1\u751f | TP\u94b1\u5305-ETH\u94b1\u5305-BTC\u94b1\u5305-BSC\u94b1\u5305-Aptos\u94b1\u5305-HECO\u94b1\u5305-OKExChain\u94b1\u5305-Polkadot\u94b1\ HTTP response: 200 ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / E7 Expires: 2026-07-09 Status: INVALID chain Fingerprint: 2b0e9a0c8a239c8321a7c52125e0b1553655c3bc8aa18802924fe2c74c60f5b7 ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: pending notification queue. No abuse reports filed yet — this domain is waiting for the next cycle of our automated abuse-reporter. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-03-25 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-05-05 05:05:14 UTC (by PhishDestroy tracker) First reported: 2026-05-05 02:06:36 UTC (abuse notice filed) Last verified: 2026-05-05 13:03:49 UTC Current status: ACTIVE / observable ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019df5df-a46f-70bb-9ff5-f54dc6be1cdd/ URLQuery: https://urlquery.net/report/43a0a11c-6a19-4f1c-a0bc-24573b71c2ea Wayback Machine: https://web.archive.org/web/*/tokenpocket.run crt.sh CT logs: https://crt.sh/?q=%25.tokenpocket.run Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=tokenpocket.run AlienVault OTX: https://otx.alienvault.com/indicator/domain/tokenpocket.run URLhaus: https://urlhaus.abuse.ch/host/tokenpocket.run/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-05-05 05:06:58 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies tokenpocket.run as an active brand impersonation domain masquerading as OKX, a major cryptocurrency exchange. The domain employs a deceptive naming strategy to lure users into divulging sensitive wallet credentials or transferring funds under false pretenses. Based on current telemetry, this threat is classified as 'under_investigation' with an elevated risk profile due to its direct association with a high-value target brand. Users interacting with this domain risk credential theft or crypto drainer activity, particularly given its recent registration and minimal detection coverage. This domain was flagged for its malicious intent, specifically impersonating OKX to deceive cryptocurrency users. key indicators include a VirusTotal detection rate of 0/95, indicative of its stealthy deployment, as well as its registration through GoDaddy.com, LLC on March 25, 2026. The domain resolves to IP address 188.114.96.3 and leverages a Let's Encrypt SSL certificate to appear legitimate. Crucially, the domain remains undetected on major threat intelligence platforms, highlighting its potential to evade traditional security measures. The absence of blocklist presence or trust scores further underscores its nascent but dangerous operational status. To mitigate exposure to this threat, users should immediately block the domain tokenpocket.run at the network and endpoint levels. Organizations are advised to update firewall rules to restrict outbound connections to 188.114.96.3. Additionally, cryptocurrency users should verify all wallet-related domains against official OKX communications and avoid interacting with unsolicited links purporting to offer wallet services. If credentials or private keys have been entered, users must revoke access via the legitimate OKX platform and transfer assets to a secure wallet. Continuous monitoring for IOCs associated with this domain is strongly recommended to prevent further exploitation. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260505-986E82 Favicon MD5: 8c6f6244dda1e0bdc39fb7852892bb4b TLS cert SHA-256: 2b0e9a0c8a239c8321a7c52125e0b1553655c3bc8aa18802924fe2c74c60f5b7 ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/tokenpocket.run/ JSON API: https://api.destroy.tools/v1/check?domain=tokenpocket.run Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 145,991 domains (61,895 alive under monitoring, 83,628 confirmed takedowns/dead). Site: https://phishdestroy.io