Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@ntt.net.
The latest stored availability evidence still shows the domain reachable; 2 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
hans-oe[.]com[.]cn
“欧æ(OKX) - å ¨çé¢å çæ°åèµäº§äº¤æå¹³å° | å®å ¨ ä¸ä¸ 髿”
hans-oe.com.cn — असत्यापित. ब्रांड प्रतिरूपण: OKX; घोटाले का प्रकार: Fake Exchange. साक्ष्य सारांश: VirusTotal 20/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, Cluster25); URLQuery 2 alerts; CF Radar malicious; PhishDestroy score 95/100. रजिस्ट्रार: 浙江贰贰网络有限公司.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
PhishDestroy has confirmed that the domain hans-oe.com.cn is a sophisticated phishing site designed to impersonate the OKX cryptocurrency exchange. The site's page title, which translates to 'OKX - Global Leading Digital Asset Trading Platform | Safe Professional Efficient,' is a direct copy of the legitimate OKX homepage, intended to deceive users into entering their login credentials and potentially their two-factor authentication codes. This specific threat is categorized as a generic phishing attack targeting crypto asset holders, with the ultimate goal of draining victims' accounts.
The evidence against this domain is substantial. VirusTotal data shows that 18 out of 95 security vendors flagged the domain as malicious, a strong indicator of its fraudulent nature. Additionally, it appears on one security blocklist and was identified in one AlienVault OTX threat intelligence pulse. The domain was registered through the Chinese registrar 浙江贰贰网络有限公司 (Zhejiang Er'er Network Co., Ltd.) and was created on May 24, 2026, which is suspiciously dated in the future. It resolves to IP address 207.56.16.143 and uses a Let's Encrypt SSL certificate (R12) to appear legitimate. As of the latest check, the site has been taken offline, but users should remain vigilant as similar domains may appear.
If a user has visited hans-oe.com.cn or entered any personal information, they should immediately change their OKX account password and enable two-factor authentication if not already active. It is also advisable to contact OKX support to report the incident and monitor account activity for unauthorized transactions. PhishDestroy recommends verifying all exchange URLs directly from official sources and never clicking links from unsolicited emails or messages. Using a password manager and enabling hardware-based security keys can further reduce the risk of falling victim to such phishing campaigns.
नेटवर्क सुरक्षा इंटेलिजेंस
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | hans-oe.com.cn |
malicious | Sinkholed |
| Cloudflare DNS | hans-oe.com.cn |
malicious | Sinkholed |
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
तकनीकें · 2 identified
Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 100% विश्वासHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% विश्वासवायरसटोटल विश्लेषण
साक्ष्य और बाहरी रिपोर्टें
PD-20260524-AA1CC2 Recipient: abuse@ntt.net क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।