सुरक्षा रिपोर्ट पर जाएँ
⚠️
इस डोमेन को दुर्भावनापूर्ण के रूप में चिह्नित किया गया है।
सुरक्षा इंजन एक पहचान की रिपोर्ट कर रहे हैं: 18। अत्यधिक सावधानी बरतें - क्रेडेंशियल या व्यक्तिगत जानकारी दर्ज न करें।
डोमेन सुरक्षा और ख़तरे की आसूचना

cnouyi[.]org

“Earn rewards when you get started on OKX | My referral code: 37602380 | OKX Europe”

धमकी भरा फैसला गंभीर 95/100 साक्ष्य स्कोर
उपलब्धता असत्यापित वर्तमान पहुंच योग्यता असत्यापित है
वायरस का कुल पता लगाना: 18/91 URLQuery threat systems: 3 alerts ब्रांड प्रतिरूपण: OKX
19/04/2026 OKX

साक्ष्य सारांश

आलोचनात्मक
Evidence score
95/100

PhishDestroy identifies cnouyi.org as an active generic phishing domain posing as a fraudulent investment gateway designed to harvest cryptocurrency wallet credentials and private keys. This domain appears to deploy a drainer kit tailored to siphon digital assets under the guise of 'investment opportunities' or 'portfolio management tools.' No specific brand is directly mentioned in available telemetry, suggesting a generic financial-themed lure rather than a targeted impersonation. The threat actor behind this domain uses obfuscated JavaScript and fake transaction prompts to trick victims into connecting malicious wallet extensions or entering seed phrases.

This domain exhibits multiple red flags verified through forensic analysis. cnouyi.org was registered on December 18, 2025, through Dynadot Inc., just days ago. It resolves to IP 54.215.31.113 and leverages a legitimate SSL certificate from Let's Encrypt to appear trustworthy. However, VirusTotal analysis confirms only 1 out of 95 security vendors currently detect this threat, and it remains unflagged by Google Safe Browsing (GSB) as of the latest scan. The domain has not yet appeared on major blocklists, indicating a newly active campaign with low detection coverage.

As of current intelligence, cnouyi.org is flagged as 'active' with elevated risk. Immediate action is recommended: block this domain at network and endpoint levels, update browser and DNS blocklists, and warn users to avoid accessing financial services links from unsolicited emails or social media. While the current risk is elevated due to low detection, rapid response can mitigate potential victimization. However, the absence from major blocklists and fresh SSL issuance suggests the campaign may expand quickly. Users are advised to verify all financial websites via official channels and never enter wallet credentials on unofficial portals.

VirusTotal
VirusTotal
18 det.
URLQuery
यूआरएलक्वेरी
3 threat alerts
TLS प्रमाणपत्र
Let's Encrypt 29d
आयु
4 mo
देखी गई स्थिति
असत्यापित
PhishDestroy
विनाश सूची
सूचीबद्ध

Data Coverage

VirusTotal 18 / 91 यूआरएलक्वेरी 3 threat-system alerts फ़िशस्टैट्स checked — no match recorded ओटीएक्स no community references सीएफ रडार scan completed URLScan capture संग्रहित रिपोर्ट URLScan verdict malicious डीएनएस ब्लॉक 12 जाँच पूरी — कोई ब्लॉक नहीं TLS valid certificate, 29d कौन है 4 mo old स्क्रीनशॉट 3 captures · 3 sources चेन पुनर्निर्देशित करें जांच नहीं की गई
नेटवर्क सुरक्षा इंटेलिजेंस
Threat Detection Systems 3 alerts
Detection System Indicator Verdict Alert
Private YARA rules static.okx.com/cdn/assets/okfe/util/ont/5.8.53/ont.js audit Hunting_JS_WebAssembly
Hagezi Threat Feed www.zhgwexpouy.net malicious Sinkholed
DNS4EU www.zhgwexpouy.net malicious Sinkholed

धमकी प्रतिक्रिया पाइपलाइन

खोज
Checks
Reports
उपलब्धता
10/12

ब्लॉकलिस्ट कवरेज

10 निगरानी वाले बाहरी स्रोत · संग्रहीत स्नैपशॉट 12/08/2026

10 निगरानी वाले बाहरी स्रोत कोई मिलान नहीं

सहेजा गया कैप्चर

पेज शीर्षक
Earn rewards when you get started on OKX | My referral code: 37602380 | OKX Europe
TLS प्रमाणपत्र
Valid transport encryption · जारीकर्ता Let's Encrypt · valid for 29 days

डोमेन इंटेलिजेंस

डोमेन
URLScan Verdict दुर्भावनापूर्ण score 100 Phishing brand: Okx report ↗
सर्वर / ASN TencentEdgeOne · AS16509 Amazon.com, Inc.
IP प्रतिष्ठा IP abuse confidence 23/100 10 reports checked 13/07/2026
रजिस्ट्रार Dynadot US(US)
दुरुपयोग संपर्कabuse@dynadot.com
IP पता 54.215.31.113 US
भौगोलिक स्थानUS San Jose, US
नेटवर्कAS16509 · AWS EC2 (us-west-1)
रिवर्स IPviewdns.info → rapiddns.io →
पंजीकरणनिर्मित 19/04/2026 (115d)
Elapsed Since First Report 4 days
हम क्या मापते हैं Raw elapsed time since the first stored abuse report. It is not a registrar response-time measurement. Latest observed status: असत्यापित.
प्रत्येक रिपोर्ट में क्या शामिल है संग्रहीत आउटगोइंग-रिपोर्ट रिकॉर्ड उस समय उपलब्ध साक्ष्य का संदर्भ दे सकते हैं, जैसे विक्रेता के फैसले, पंजीकरण डेटा, होस्टिंग विवरण, वर्गीकरण, या स्क्रीनशॉट। यह पृष्ठ किसी प्राप्तकर्ता द्वारा वितरित सटीक पेलोड, रसीद, पावती या कार्रवाई का अनुमान नहीं लगाता है।
तकनीकी विवरणDNS, TLS नाम और समय-मुद्राएँ
पहली बार पता चला19/04/2026
Submitted URLhttp://cnouyi.org/
नेमसर्वरns2.dyna-ns.net
TLS फिंगरप्रिंट
TLS अवलोकन17/02/2026 से मान्य19/04/2026 को स्कैन किया गया
ICANN OVERSIGHT

प्रत्यायन और आरएए संदर्भ

Registrar accreditation and DNS abuse obligations

For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.

Accreditation is a contract, not a safety certification.

RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.

मान्यता एक अनुबंध है, सुरक्षा की मुहर नहीं। ICANN शुल्क सत्यापित करें RAA §3.18 पढ़ें PHISHDESTROY INVESTIGATIONICANN funding, contracts, and DNS abuse oversight
Accountability draft कुछ भी अपने आप नहीं भेजा जाता।
इस डोमेन की रिपोर्ट करें सबूत जमा करें और दूसरों की सुरक्षा में मदद करें

वायरसटोटल विश्लेषण

18 / 91 सुरक्षा विक्रेताओं ने इस डोमेन को चिह्नित किया
View on VT
Last analyzed Previous stored snapshot: 3 detections
ADMINUSLabs
alphaMountain.ai
BitDefender
Chong Lua Dao
CRDF
साइरेडार
ईएसईटी
Emsisoft
Fortinet
G-Data
Gridinsoft
कास्परस्की
Lionic
नेटक्राफ्ट
SOCRadar
सोफोस
VIPRE
वेबरूट
साइट प्रदर्शन विश्लेषण

Google PageSpeed Insights — mobile performance audit of cnouyi.org · checked Apr 19, 2026

34
Poor
Performance
FCP
3.97s
First Contentful Paint
LCP
17.85s
Largest Contentful Paint
CLS
0
Cumulative Layout Shift
TBT
1404ms
Total Blocking Time
SI
8s
Speed Index
Powered by Google PageSpeed Insights · Mobile strategy · Scores: 90-100 Good 50-89 Needs Work 0-49 Poor

क्या आप इस साइट से प्रभावित हुए?

If credentials were compromised, report immediately. Do not engage with recovery scammers.

यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।

यूरोपोल
अपने ईयू देश के लिए आधिकारिक रिपोर्टिंग चैनल ढूंढें
National police directory
रिकवरी ठगों से सावधान रहें! अपराधी जांचकर्ता, वकील या रिकवरी एजेंट होने का नाटक करते हुए पीड़ितों से दोबारा संपर्क कर सकते हैं। अग्रिम शुल्क का भुगतान न करें या क्रेडेंशियल साझा न करें। रिकवरी धोखाधड़ी के बारे में और जानें →

अपने स्थानीय अधिकारियों को रिपोर्ट करें

आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।

97-देश निर्देशिका
एआई-सहायता प्राप्त ड्राफ्ट - घटना विवरण एआई प्रदाता द्वारा संसाधित किया जाता है इसकी स्वयं समीक्षा करें और सबमिट करें

किसी भी डोमेन की जाँच करें

संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण

अभी स्कैन करें

फ़िशिंग की रिपोर्ट करें

संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें

रिपोर्ट करें

सीधा खतरा फीड

हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए

निगरानी करें

जानकारी में रहें, सुरक्षित रहें

लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।

सीधा खतरा फीड इस लिस्टिंग के खिलाफ अपील करें

बाहरी उपकरण

स्कैमएडवाइज़रScamAdviser विश्वास स्कोर 40/100स्थिति: Likely Unsafeस्रोत खोलें
HTML · IFRAME

इस रिपोर्ट को एम्बेड करें

इस थ्रेट इंटेलिजेंस को अपनी वेबसाइट या ब्लॉग पर साझा करें।

embed.html
<iframe
  src="https://phishdestroy.io/hi/embed/domain/cnouyi.org"
  title="PhishDestroy threat report for cnouyi.org"
  width="100%" height="320"
  loading="lazy"
  referrerpolicy="no-referrer"
  sandbox="allow-same-origin allow-popups allow-popups-to-escape-sandbox"
  style="border:0;border-radius:12px;max-width:100%"
></iframe>

एक अत्यंत सच्चा धन्यवाद-पत्र

व्यंग्यात्मक मसौदा जनरेटर

प्राप्तकर्ता
शुल्क संदर्भ

यह व्यंग्यात्मक मसौदा है। शुल्क के आंकड़े अनुमान हैं; इन्हें इस डोमेन से ठीक-ठीक जोड़ने का दावा नहीं किया जाता।