08pf[.]cn
“欧易下载|欧易app下载注册官网|欧易交易所下载注册|虚拟货币交易 - 欧易交易所下载”
Detecção armazenada
Alerta de cloaking
- Tipo de cloaking
status_split- Pontuação de cloaking
- 1/6
Resumo das evidências
The domain 08pf.cn was observed targeting the cryptocurrency exchange brand OKX through a brand‑impersonation campaign. The domain, registered on March 28 2025 by 成都伊索信息科技有限公司, resolves to the IP address 156.226.74.60, which is allocated to AS135097 LUOGELANG (FRANCE) LIMITED and geolocated in Hong Kong. The DNS configuration lists ns1.judns.com and ns2.judns.com as authoritative nameservers. A TLS certificate issued by Let’s Encrypt (R10) was present at the time of analysis, indicating that the site offered HTTPS connectivity. The page title retrieved before the site was taken offline reads “欧易下载|欧易app下载注册官网|欧易交易所下载注册|虚拟货币交易 - 欧易交易所下载”, confirming the use of Chinese language and the appearance of OKX‑related keywords.
Reputation checks show a Gridinsoft trust score of 0 / 100 and a Google Safe Browsing classification of social engineering. The domain is listed on a single security blocklist and has been actively blocked by the PhishDestroy service. VirusTotal scans recorded 14 detections out of 95 scanned engines, reinforcing the malicious assessment. No additional public intelligence such as OTX references or malware kit identifiers were available.
The site is currently offline, limiting direct observation of payloads or credential‑collection mechanisms. Consequently, the exact content delivered to victims, including potential login forms or malicious binaries, remains unverified. Nonetheless, the convergence of registrar data, IP hosting, SSL provisioning, and multiple independent threat‑intel signals provides strong evidence that the domain was employed for brand‑impersonation phishing against OKX users.
Defenders are advised to enforce network‑level denial of 08pf.cn and its associated IP 156.226.74.60, update endpoint detection rules with the observed Safe Browsing and VirusTotal signatures, and monitor for any resurgence of the domain or similar registrant patterns. Continuous observation of the LUOGELANG AS block and the judns.
Data Coverage
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 12/08/2026
10 fontes externas monitoradas Sem correspondência
Linha do tempo de detecção
-
Status do domínio
Acessível → Inacessível
-
Cloudflare Radar
Varredura do Cloudflare Radar armazenada · Abrir varredura
Análise do VirusTotal
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo