enter-okx-listing[.]vercel[.]app
“Token Voting | Vote on Crypto Listings”
enter-okx-listing.vercel.app — Contenido no disponible. Suplantación de marca: OKX; Tipo de estafa: Crypto Scam. Resumen de las pruebas: VirusTotal 5/93 (alphaMountain.ai, Emsisoft, Fortinet, Netcraft, Webroot); PhishDestroy score 65/100. Registrador: Vercel.
El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.
The domain enter-okx-listing.vercel.app was observed as an offline site that impersonates the cryptocurrency exchange brand OKX. Technical analysis shows the domain resolves to the IP address 216.198.79.131, which is allocated to Amazon.com, Inc. (AS16509) and geolocated to the United States. The hosting platform is Vercel, confirmed by the presence of Vercel‑derived nameservers (ns1.vercel-dns-3.com through ns4.vercel-dns-3.com) and the detection of Vercel technology on the site. HTTPS is enforced via HSTS, and the TLS certificate is issued by Google Trust Services under the WR1 designation, indicating a valid certificate chain.
HTTP requests return a 404 status, suggesting the content is no longer served. The domain was created on 28 January 2020 and is registered through Vercel Inc., consistent with the hosting provider. The page title retrieved before takedown was "Token Voting | Vote on Crypto Listings," which aligns with the reported scam type of a crypto‑related impersonation.
VirusTotal analysis recorded five positive detections out of ninety‑three scanners, and the domain appears on a single security blocklist, specifically PhishDestroy. While the site is currently offline, the infrastructure artifacts—IP ownership, Vercel hosting, and the SSL configuration—provide sufficient indicators for threat‑intelligence feeds. Defenders should continue to block the domain at DNS and proxy layers, monitor for any re‑registration or similar sub‑domains that target the OKX brand, and incorporate the observed indicators (IP, nameservers, certificate issuer) into detection rules to pre‑empt future impersonation attempts.
Proceso de respuesta ante amenazas Pipeline
Estado de la lista de bloqueados pública
Tecnologías · 2 identified
Cloud platform for frontend deployment, optimized for Next.js.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Análisis de VirusTotal
Evidencias archivadas
Datos y informes externos
¿Te ha afectado esta página web?
Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.
Informa a las autoridades locales
Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.
Comprobar cualquier dominio
Análisis de amenazas utilizando listas de bloqueo almacenadas, WHOIS, DNS y evidencia de escaneo público
Escanear ahoraDenunciar un intento de phishing
Envía los dominios sospechosos a nuestra base de datos de amenazas: protege a la comunidad
DenunciarFlujo de amenazas en tiempo real
Informes de phishing recientes y cambios de disponibilidad observados
MonitorizarMantente informado, mantente a salvo
Supervisa las amenazas en tiempo real o impugna esta entrada si crees que se trata de un falso positivo.