niftah[.]com
niftah.com की फ़िशिंग और सुरक्षा जाँच
“Earn rewards when you get started on OKX | My referral code: 4475707693 | OKX...”
niftah.com — अंतिम ज्ञात सक्रिय (HTTP 302). ब्रांड प्रतिरूपण: OKX; घोटाले का प्रकार: Brand Impersonation. साक्ष्य सारांश: VirusTotal 13/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); URLQuery 3 alerts; URLScan malicious verdict; CF Radar malicious; PhishDestroy score 99/100. रजिस्ट्रार: Dynadot.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
साक्ष्य सारांश
PhishDestroy first observed niftah.com on May 2, 2026. Stored content metadata identifies OKX as the apparent target. The captured page title is “Earn rewards when you get started on OKX | My referral code: 4475707693 | OKX Europe”. Evidence score: 99/100 (critical).
4 independent sources recorded positive findings: VirusTotal, Cloudflare Radar, URLQuery, and URLScan. VirusTotal recorded 13 detections among 91 engines: ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, CyRadar, Fortinet, G-Data on Jul 29, 2026 at 02:21 UTC. Cloudflare Radar classified the hostname as malicious and assigned the categories dga domains and security threats; its verdict timestamp was not retained. URLQuery recorded 3 threat-system alerts on May 2, 2026 at 12:16 UTC. URLScan returned a malicious verdict with score 100; scan metadata linked the capture to Okx and assigned phishing as its category on Jul 29, 2026 at 02:38 UTC.
HTTP 302 was recorded on Aug 9, 2026 at 02:24 UTC. Registration records for the domain list Dynadot Inc as the registrar and May 2, 2026 as the creation date. At collection time, the hostname resolved to 54.215.31.113 on AS16509 (Amazon.com, Inc.). The evidence archive retains 3 visual captures from PhishDestroy, URLScan, and URLQuery.
डेटा कवरेज12 recorded checks
नेटवर्क सुरक्षा इंटेलिजेंस
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | static.okx.com/cdn/assets/okfe/util/ont/5.8.53/ont.js |
audit | Hunting_JS_WebAssembly |
| Hagezi Threat Feed | www.ouyifugtjk.com |
malicious | Sinkholed |
| DNS4EU | www.ouyifugtjk.com |
malicious | Sinkholed |
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
तकनीकें · 8 identified
Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 100% विश्वासReact is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org 100% विश्वासOpenResty is a web platform based on nginx which can run Lua scripts using its LuaJIT engine.
openresty.org 100% विश्वासLexisNexis ThreatMetrix is an enterprise solution for online risk and fraud protection ('digital identity intelligence and digital authentication').
risk.lexisnexis.com 100% विश्वासOneTrust is a cloud-based data privacy management compliance platform.
www.onetrust.com 100% विश्वासHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% विश्वासGoogle Tag Manager is a tag management system (TMS) that allows you to quickly and easily update measurement codes and related code fragments collectively known as tags on your website or mobile app.
www.google.com 100% विश्वासवायरसटोटल विश्लेषण
साक्ष्य और बाहरी रिपोर्टेंIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।