08pf[.]cn
“欧易下载|欧易app下载注册官网|欧易交易所下载注册|虚拟货币交易 - 欧易交易所下载”
संग्रहीत पहचान
क्लोकिंग चेतावनी
- क्लोकिंग प्रकार
status_split- क्लोकिंग स्कोर
- 1/6
साक्ष्य सारांश
The domain 08pf.cn was observed targeting the cryptocurrency exchange brand OKX through a brand‑impersonation campaign. The domain, registered on March 28 2025 by 成都伊索信息科技有限公司, resolves to the IP address 156.226.74.60, which is allocated to AS135097 LUOGELANG (FRANCE) LIMITED and geolocated in Hong Kong. The DNS configuration lists ns1.judns.com and ns2.judns.com as authoritative nameservers. A TLS certificate issued by Let’s Encrypt (R10) was present at the time of analysis, indicating that the site offered HTTPS connectivity. The page title retrieved before the site was taken offline reads “欧易下载|欧易app下载注册官网|欧易交易所下载注册|虚拟货币交易 - 欧易交易所下载”, confirming the use of Chinese language and the appearance of OKX‑related keywords.
Reputation checks show a Gridinsoft trust score of 0 / 100 and a Google Safe Browsing classification of social engineering. The domain is listed on a single security blocklist and has been actively blocked by the PhishDestroy service. VirusTotal scans recorded 14 detections out of 95 scanned engines, reinforcing the malicious assessment. No additional public intelligence such as OTX references or malware kit identifiers were available.
The site is currently offline, limiting direct observation of payloads or credential‑collection mechanisms. Consequently, the exact content delivered to victims, including potential login forms or malicious binaries, remains unverified. Nonetheless, the convergence of registrar data, IP hosting, SSL provisioning, and multiple independent threat‑intel signals provides strong evidence that the domain was employed for brand‑impersonation phishing against OKX users.
Defenders are advised to enforce network‑level denial of 08pf.cn and its associated IP 156.226.74.60, update endpoint detection rules with the observed Safe Browsing and VirusTotal signatures, and monitor for any resurgence of the domain or similar registrant patterns. Continuous observation of the LUOGELANG AS block and the judns.
Data Coverage
नेटवर्क सुरक्षा इंटेलिजेंस
धमकी प्रतिक्रिया पाइपलाइन
ब्लॉकलिस्ट कवरेज
10 निगरानी वाले बाहरी स्रोत · संग्रहीत स्नैपशॉट 10/08/2026
पहचान समयरेखा
-
डोमेन स्थिति
पहुँच योग्य → पहुँच योग्य नहीं
-
Cloudflare Radar
Cloudflare Radar स्कैन संग्रहीत · स्कैन खोलें
वायरसटोटल विश्लेषण
क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।