cpr-broker[.]co
“CPR Broker”
cpr-broker.co — Conteúdo indisponível. Tipo de golpe: Brand Impersonation. Resumo das evidências: VirusTotal 0/94; PhishDestroy score 48/100. Registrador: CNOBIN INFORMATION TEC….
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
PhishDestroy identifies cpr-broker.co as an active brand impersonation phishing domain targeting OKX users. This fraudulent site mimics the legitimate OKX platform to deceive visitors into surrendering sensitive login credentials or financial data. The domain resolution to IP 188.114.97.3 and recent SSL certificate issuance by Google Trust Services suggest an attempt to appear legitimate at first glance. Threat actors registered the domain through CNOBIN INFORMATION TECHNOLOGY LIMITED on February 16, 2026, indicating a newly established infrastructure actively engaged in deceptive operations. This domain poses a high risk due to its specific targeting of OKX users and its current lack of detection on VirusTotal, which shows 0/95 detections as of the latest scan. The technical indicators, including the IP resolution and SSL certificate, are consistent with phishing campaigns designed to bypass initial security checks. While the domain has not yet been widely flagged on blocklists, its recent creation and active status warrant immediate attention from security teams and users alike. The absence of detections highlights the sophisticated nature of this impersonation attempt, making it a critical threat to monitor. Users who have visited cpr-broker.co should immediately assess their exposure by checking for any entered credentials or financial information. If any data was submitted, users must change their OKX account passwords immediately and enable multi-factor authentication (MFA). Additionally, users should scan their devices for malware using reputable security software and monitor their accounts for unauthorized transactions. Reporting the domain to OKX and relevant cybersecurity authorities can help mitigate further risks. Proactive vigilance and swift action are essential to prevent potential financial or data loss from this phishing scam.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 3 identified
Performance monitoring tool that measures website speed from real users.
www.cloudflare.comWeb infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of cpr-broker.co · checked Mar 29, 2026
Evidências e relatórios externos
PD-20260526-CCB5BF Recipient: abuse@ordertld.com Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo