token2049badge[.]site
“NBX Crypto Event — 7-8 October 2026”
token2049badge.site — सामग्री अनुपलब्ध (HTTP 502). ब्रांड प्रतिरूपण: Binance; घोटाले का प्रकार: Brand Impersonation. साक्ष्य सारांश: VirusTotal 1/94 (Gridinsoft); URLQuery 1 alert; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. रजिस्ट्रार: Hostinger.
मूल फॉरेंसिक रिकॉर्ड सुरक्षित रखने के लिए नीचे का विस्तृत PhishDestroy AI विश्लेषण अंग्रेज़ी में रखा गया है।
PhishDestroy flags token2049badge.site as an ACTIVE brand impersonation domain targeting OKX, posing as a legitimate event badge platform. This domain is currently under investigation but remains a credible threat to users expecting OKX-related services. The risk level is classified as 'active' due to the specific impersonation tactics employed, which include mimicking OKX branding to deceive visitors into divulging sensitive information or downloading malicious content. token2049badge.site resolves to the IP address 145.223.108.68, a hosting provider controlled by HOSTINGER operations, UAB. The domain was registered on March 28, 2026, and currently holds a clean SSL certificate issued by Let's Encrypt, which may further lull users into a false sense of security. Despite being undetected by VirusTotal (1/95 detections), this domain has not yet been widely flagged by blocklists or trust scoring systems, increasing its potential to evade early detection mechanisms. The combination of a recently created domain, a hosting provider with a mixed reputation, and no current detections creates a high-risk scenario for unsuspecting users.
This domain was registered through HOSTINGER operations, UAB, a provider known for both legitimate and fraudulent hosting services. The IP address 145.223.108.68 has been associated with multiple low-trust domains, though no direct malicious activity has been conclusively linked to it at this time. The SSL certificate from Let's Encrypt adds a veneer of legitimacy, which is a common tactic used by impersonation domains to appear trustworthy. The domain's creation date of March 28, 2026, places it in a high-risk category, as newly registered domains are frequently weaponized for phishing and brand impersonation within the first 48 hours. While VirusTotal currently shows 1/95 detections, this should not be misinterpreted as a clean bill of health, as threat intelligence feeds often lag behind emerging threats. The lack of widespread blocking suggests this domain is either very new or carefully crafted to avoid early detection, making proactive blocking by users and security systems essential.
To mitigate the risk posed by token2049badge.site, users should immediately block the domain at the network level and avoid accessing it via any means. Organizations are advised to update firewall rules and DNS filtering policies to include this domain and its associated IP address (145.223.108.68). Since this is a brand impersonation threat, users expecting OKX communications should verify any related domains or links through official OKX channels before engaging. Security teams should monitor for any further domain registrations or IP associations linked to this campaign, as threat actors often expand their infrastructure rapidly. Proactive threat hunting for similar domains mimicking OKX or other major exchanges is recommended to prevent similar impersonation attempts.
नेटवर्क सुरक्षा इंटेलिजेंस
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | token2049badge.site |
malicious | Sinkholed |
धमकी प्रतिक्रिया पाइपलाइन
सार्वजनिक ब्लॉकलिस्ट स्थिति
सहेजा गया कैप्चर
डोमेन इंटेलिजेंस
तकनीकी विवरणडीएनएस, एसएसएल एसएएन, टाइमस्टैम्प
ICANN OVERSIGHT
प्रत्यायन और आरएए संदर्भ
प्रत्यायन और आरएए संदर्भ
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
तकनीकें · 3 identified
High-performance web server compatible with Apache configurations.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
वायरसटोटल विश्लेषण
साइट प्रदर्शन विश्लेषण
Google PageSpeed Insights — mobile performance audit of token2049badge.site · checked Mar 30, 2026
साक्ष्य और बाहरी रिपोर्टें
PD-20260330-E44FF7 Recipient: domains@hostinger.com क्या आप इस साइट से प्रभावित हुए?
यदि आपने खाता क्रेडेंशियल, व्यक्तिगत या भुगतान जानकारी दर्ज की है, या इस डोमेन से कोई फ़ाइल डाउनलोड की है, तो तुरंत कार्रवाई करें। घटना की रिपोर्ट करने और अपनी सुरक्षा करने में आपकी सहायता के लिए नीचे संसाधन दिए गए हैं।
अपने स्थानीय अधिकारियों को रिपोर्ट करें
आधिकारिक साइबर अपराध संपर्क, या एक शिकायत ड्राफ्ट बनाएं → प्राप्त करने के लिए अपना देश चुनें।
किसी भी डोमेन की जाँच करें
संग्रहीत ब्लॉकलिस्ट, WHOIS, DNS और सार्वजनिक स्कैन साक्ष्य का उपयोग करके खतरे का विश्लेषण
अभी स्कैन करेंफ़िशिंग की रिपोर्ट करें
संदिग्ध डोमेन हमारे थ्रेट डेटाबेस में जमा करें — समुदाय की सुरक्षा करें
रिपोर्ट करेंसीधा खतरा फीड
हाल की फ़िशिंग रिपोर्टें और उपलब्धता में परिवर्तन देखे गए
निगरानी करेंजानकारी में रहें, सुरक्षित रहें
लाइव खतरों की निगरानी करें या यदि आपको लगता है कि यह एक गलत सकारात्मक है तो इस लिस्टिंग को चुनौती दें।