Ir al informe de seguridad
Checked 09/08/2026 Ref DEAD3960

MALICIOUS — CRITICAL

imtokenofficial-cn[.]com

PhishDestroy has detected imtokenofficial-cn.com engaging in brand impersonation, specifically targeting OKX users.

100/100 evidence score · Critical
VirusTotal
15/91
Blocklists
No stored match
Disponibilidad
Encubierto · accesible · HTTP 301
Report / Add Evidence Appeal this listing
2026-04-15 06:12 UTCEncubierto · accesible · HTTP 301

Do not enter credentials, seed phrases, payment details, or personal information on this domain.

⚠️
Este dominio ha sido señalado como malicioso
Motores de seguridad que informan una detección: 15. Tenga extrema precaución: no ingrese credenciales o información personal.
Jump to section
Resumen del informe

imtokenofficial-cn.com — Encubierto · accesible (HTTP 301). Tipo de estafa: Brand Impersonation. Resumen de las pruebas: VirusTotal 15/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); cloaking observed; PhishDestroy score 100/100. Registrador: Dominet (HK).

El análisis detallado de PhishDestroy AI se mantiene en inglés para conservar el registro forense original.

Evidence Analysis

Ref DEAD3960

PhishDestroy has detected imtokenofficial-cn.com engaging in brand impersonation, specifically targeting OKX users. The domain appears to be designed to deceive individuals into believing they are interacting with the official OKX platform. This can lead to theft of personal information or cryptocurrency assets.

Technical analysis reveals that the domain, imtokenofficial-cn.com, was created on October 08, 2025 and registered through Dominet (HK) Limited. It resolves to IP address 160.124.192.212. VirusTotal currently shows a low detection rate of 11/95. The domain is secured with a Let's Encrypt SSL certificate. There is no current GSB or blocklist information available.

The domain is currently active, posing a risk to unsuspecting users. Immediate response actions should include adding imtokenofficial-cn.com to blocklists and informing OKX of the impersonation. Users should be warned to verify the authenticity of websites before entering sensitive information.

VirusTotal
VirusTotal
15 det.
URLScan
URLScan
Certificado TLS
Let's Encrypt
Edad
4 mo
Estado observado
Encubierto · accesible 301
PhishDestroy
DestroyList
En lista
Cobertura de los datos12 recorded checks
VirusTotal 15 / 91 URLQuery checked — no detections recorded PhishStats checked — no match recorded OTX no community references CF Radar scan completed URLScan capture informe almacenado URLScan verdict Análisis finalizado Bloqueos de DNS 12 comprobado — sin bloqueos TLS valid certificate, 78d WHOIS 4 mo old Captura de pantalla 3 captures · 3 sources Cadena de redireccionamientos no sondeado

Proceso de respuesta ante amenazas Pipeline

Descubrimiento
Checks
Reports
Disponibilidad
9/11

Estado de la lista de bloqueados pública

Captura guardada

Título de la página
404 Not Found
Certificado TLS
Valid transport encryption · Emitido por Let's Encrypt · valid for 78 days

Inteligencia de dominios

Dominio
URLScan Verdict Análisis finalizado score 0 report ↗
Servidor / ASN nginx · AS132839 POWER LINE DATACENTER
Reputación de IP abuse score 0/100 0 reports checked 13/07/2026
Dirección IP 160.124.192.212 ZA
UbicaciónZA Pretoria, ZA
RedAS132839 · Posix Systems (Pty) Ltd
RegistroCreado 15/04/2026 (116d)
Estado HTTP301 Moved Permanently
Cloaking Cloaking Detected Content divergence · score 1/6
redirect: raw=redirect_301; http=301; via=https_proxy; location=https://www.imtokenofficial-cn.com/; server=nginx
server: nginx title: 301 Moved Permanently
checked 09/08/2026
Elapsed Since First Report 13 days
Qué contabilizamos Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: Encubierto · accesible.
Qué contiene cada informe Los registros de informes salientes almacenados pueden hacer referencia a evidencia disponible en ese momento, como veredictos de proveedores, datos de registro, detalles de alojamiento, clasificaciones o capturas de pantalla. Esta página no infiere la carga útil entregada, el recibo, el acuse de recibo o la acción exacta por parte de un destinatario.
Detalles técnicosDNS, SAN de SSL, marcas de tiempo
Primera detección15/04/2026
IoC Extractionscanned 29/07/20260 wallet · 0 Telegram IoCs
Submitted URLhttps://imtokenofficial-cn.com/
Servidores de nombresns2.domainnamedns.com
TLS Fingerprint
TLS Observationvalid from 03/04/2026scanned 15/04/2026
TLS SAN Domainsm.imtokenofficial-cn.comwap.imtokenofficial-cn.comwww.imtokenofficial-cn.com
ICANN OVERSIGHT

Acreditación y contexto RAA

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

Accountability draft No se envía nada automáticamente.
Tecnologías · 2 identified
Nginx
Web servers Reverse proxies

High-performance HTTP server and reverse proxy, known for stability and low resource usage.

HSTS
Seguridad

HTTP Strict Transport Security — forces browsers to use HTTPS connections only.

Detected via Cloudflare Radar · Wappalyzer engine
Denunciar este dominio Envía pruebas y ayuda a proteger a los demás

Análisis de VirusTotal

15 / Los proveedores de seguridad de 91 marcaron este dominio
View on VT
Last analyzed Previous stored snapshot: 11 detections
ADMINUSLabs
alphaMountain.ai
BitDefender
Chong Lua Dao
CRDF
ESET
Fortinet
G-Data
Gridinsoft
Kaspersky
Lionic
SOCRadar
Sophos
VIPRE
Webroot
Análisis del rendimiento del sitio

Google PageSpeed Insights — mobile performance audit of imtokenofficial-cn.com · checked Apr 15, 2026

85
Needs Work
Performance
FCP
2.02s
First Contentful Paint
LCP
3.99s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
0ms
Total Blocking Time
SI
3.39s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor
Datos y informes externosIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
If credentials were compromised, report immediately. Do not engage with recovery scammers.

Si ingresó credenciales de cuenta, información personal o de pago, o descargó un archivo de este dominio, tome medidas inmediatas. A continuación encontrará recursos que le ayudarán a informar el incidente y protegerse.

Europol
Encuentre el canal de denuncia oficial para su país de la UE
National police directory
¡Cuidado con los estafadores que se hacen pasar por empresas de recuperación de datos! Los delincuentes pueden volver a contactar a las víctimas haciéndose pasar por investigadores, abogados o agentes de recuperación. No pague tarifas por adelantado ni comparta credenciales. Más información sobre el fraude en las ayudas de recuperación →

Informa a las autoridades locales

Seleccione su país para obtener contactos oficiales de cibercrimen o crear un borrador de queja →.

directorio de 97 países
Borrador asistido por IA: el proveedor de IA procesa los detalles del incidente Revíselo y envíelo usted mismo
Incrustar este informeRead-only HTML widget
HTML · IFRAME

Incrustar este informe

Comparte esta información sobre amenazas en tu página web o blog

embed.html
<iframe
  src="https://phishdestroy.io/es/embed/domain/imtokenofficial-cn.com"
  title="PhishDestroy threat report for imtokenofficial-cn.com"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

Una carta de agradecimiento muy sincera

Generador de borradores satíricos

Destinatario
Contexto de las tarifas

Borrador satírico. Las cifras de las tarifas son estimaciones; no se afirma que correspondan exactamente a este dominio.