cpr-broker[.]com
“CPR Broker”
This domain is flagged for elevated-risk brand impersonation targeting OKX, a major cryptocurrency exchange platform. Analysis indicates the site is designed to deceive users into disclosing login credentials, wallet recovery phrases, or executing unauthorized transactions under the guise of legitimate trading services. The threat type is classified as credential harvesting with potential secondary financial fraud objectives, given the targeted brand's association with digital asset management. Infrastructure analysis reveals the domain cpr-broker.com was registered on April 01, 2024, through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar frequently observed in phishing campaigns. It currently resolves to IP address 104.21.87.146, hosted behind Cloudflare infrastructure, which may obscure origin servers and complicate takedown efforts. Detection metrics show 4 out of 95 security vendors on VirusTotal have flagged the domain, while Gridinsoft assigns a trust score of 0/100. The domain appears on one security blocklist and is actively blocked by PhishDestroy. Additional technical indicators include the use of Cloudflare Browser Insights and HTTP/3 protocol, suggesting efforts to mimic modern web application behavior. AlienVault OTX records the domain in one threat intelligence pulse, confirming its inclusion in recent malicious activity tracking. Mitigation requires immediate action from network defenders and end users. Organizations should implement DNS-based blocking for cpr-broker.com and its resolving IP 104.21.87.146 at perimeter security controls. Cryptocurrency service providers are advised to monitor for unauthorized access attempts originating from this domain and issue warnings to users about ongoing impersonation campaigns. End users should verify domain authenticity through official channels before entering credentials, enable multi-factor authentication on all financial accounts, and report suspicious communications to their exchange's fraud team. Given the domain's recent registration and low detection rates, security teams should prioritize monitoring for related infrastructure, including newly registered domains under the same registrar or IP range.
Catatan laporan keluar
Snapshot bukti yang dikirim
- Dikirim
- Catatan buku besar
- 1
- ID kasus
PD-20260503-C574B2- Judul halaman yang direkam
- CPR Broker
- Artefak PDF
- Bukti PDF
Teks bukti lengkap
Policy Violations: “Services may be used only for lawful purposes… fraud, abuse and illegal activity prohibited. Violations may result in immediate suspension.” + dedicated abuse handling and takedown
Applicable Laws: Crimes Ordinance Cap.200 (Fraud), Theft Ordinance Cap.210 §16A (fraud by deception), Personal Data (Privacy) Ordinance Cap.486
Intelijen Keamanan Jaringan Registrar context
Alur Tanggapan Ancaman Pipeline
Cakupan daftar blokir
10 sumber · disinkronkan 09/08/2026
Bukti hasil tersimpan
Hasil dan atribusi penonaktifan
- Hasil
- Registration hold observed
- Penyebab
- Registrar clientHold
- Pelaku
- NICENIC INTERNATIONAL GROUP CO., LIMITED
- Mekanisme
- Registrar clientHold
- Tingkat keyakinan
- 95%
Tindakan registrar
NICENIC INTERNATIONAL GROUP CO., LIMITED IANA 3765
Perkiraan waktu tidak tersedia
Rentang ketidakpastian: ±638.97 h Presisi waktu: LowLinimasa deteksi
Pengamatan tersimpan dalam urutan kronologis.
-
Cloudflare Radar
Cloudflare Radar: pertama kali diamati sebagai https://radar.cloudflare.com/scan/c9ba0f6a-80f1-44a7-8fd5-ea0979e4eaf0
-
VirusTotal
VirusTotal: 2 → 4
-
Pengamatan tersimpan
Pengamatan tersimpan: alive → dead
Tangkapan tersimpan
Intelijen Domain
Detail teknisDNS, SAN SSL, cap waktu
ICANN OVERSIGHT
Akreditasi dan konteks RAA
Akreditasi dan konteks RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Teknologi
3 teknologi dengan keyakinan tinggi teridentifikasi
Analisis VirusTotal
Bukti Terarsip
Apakah Anda Terpengaruh oleh Situs Ini?
Jika Anda memasukkan kredensial akun, informasi pribadi atau pembayaran, atau mengunduh file dari domain ini, segera ambil tindakan. Di bawah ini adalah sumber daya untuk membantu Anda melaporkan insiden tersebut dan melindungi diri Anda sendiri.
Laporkan kepada Pihak Berwenang di Daerah Anda
Pilih negara Anda untuk mendapatkan kontak resmi kejahatan dunia maya, atau membuat draf pengaduan →.
Periksa Domain Apa Pun
Analisis ancaman menggunakan daftar blokir yang disimpan, WHOIS, DNS, dan bukti pemindaian publik
Pindai SekarangLaporkan Phishing
Laporkan domain yang mencurigakan ke basis data ancaman kami — lindungi komunitas
LaporanPemberitahuan Ancaman Real-Time
Laporan phishing terbaru dan perubahan ketersediaan yang diamati
PantauTetap Terinformasi, Tetap Aman
Pantau ancaman secara langsung atau ajukan keberatan terhadap daftar ini jika Anda yakin ini merupakan false positive