vote-okx[.]com
Phishing and security check for vote-okx.com
“Project not found”
This domain, vote-okx.com, is classified as an elevated-risk cryptocurrency wallet impersonation threat. Analysis indicates the infrastructure was specifically designed to deceive users into disclosing sensitive wallet credentials or private keys by mimicking a legitimate cryptocurrency exchange platform. The threat type falls under brand impersonation, with a clear focus on exploiting trust in the targeted brand's user base. Infrastructure analysis reveals the domain was registered on December 24, 2025, through PDR Ltd. d/b/a PublicDomainRegistry.com. It resolves to the IP address 185.158.133.1 and has been flagged by 9 out of 95 security vendors on VirusTotal. The domain appears on four independent security blocklists and is associated with one threat intelligence pulse in AlienVault OTX. Additional detection sources include MetaMask, ScamSniffer, SEAL, and PhishDestroy, while Gridinsoft assigns a trust score of 0 out of 100. The page title, 'Project not found,' suggests either a placeholder or a deliberate attempt to evade automated detection systems. To mitigate risks associated with cryptocurrency wallet impersonation, users should verify domain authenticity by cross-referencing official communication channels. Organizations should implement domain monitoring to detect lookalike registrations and enforce strict validation protocols for all wallet-related interactions. Endpoints resolving to the IP 185.158.133.1 should be blocked at the network level, and security teams should treat any domains registered through the identified registrar with heightened scrutiny. Users who may have interacted with this domain should immediately revoke any active sessions, rotate credentials, and monitor wallet activity for unauthorized transactions.
Network Security Intelligence
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analysis
Evidence & External Reports
Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive