# trumptoken.lat — SUSPICIOUS > Avoid trumptoken.lat, a phishing domain mimicking OKX. This site is offline but posed medium risk. Stay vigilant against brand impersonation scams. ## Summary PhishDestroy identifies trumptoken.lat as a medium-risk phishing domain impersonating the OKX cryptocurrency platform. Such brand impersonation campaigns aim to deceive users into revealing sensitive information or credentials. The domain was registered on March 13, 2026, through PDR Ltd. d/b/a PublicDomainRegistry.com and resolved to IP 172.67.184.188. VirusTotal flagged it with 4 detections out of 95 scanners before the domain was taken offline, indicating some malicious activity. Users are advised to avoid interacting with trumptoken.lat or any suspicious sites claiming affiliation with OKX. Verify URLs carefully, use official channels, and report phishing attempts to protect personal data and assets. ## Threat Details - Verdict: SUSPICIOUS - Site status: dead (HTTP 404) - Target brand: OKX ## Domain Intelligence - Registered: 2026-03-13 12:28:11 - Registrar: PDR Ltd. d/b/a PublicDomainRegistry.com - Country: IN - IP: 172.67.184.188 - Nameservers: june.ns.cloudflare.com nikon.ns.cloudflare.com ## Detection Status - VirusTotal: 4 vendors flagged Vendors: ["Certego", "Forcepoint ThreatSeeker", "Gridinsoft", "SOCRadar"] - Google Safe Browsing: clean - Blocklists: 0 hits ## Evidence - Screenshot: https://i.ibb.co/7t7Kk9kD/f2a18f3127d2.png - Cloudflare Radar: https://radar.cloudflare.com/scan/08ba195e-6550-44b4-ba4b-15160df68f42 - PhishDestroy: https://phishdestroy.io/domain/trumptoken.lat/ - LLM endpoint: https://phishdestroy.io/domain/trumptoken.lat/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/trumptoken.lat/ Last updated: 2026-03-19