Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@ntt.net.
The latest stored availability evidence still shows the domain reachable; 2 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
hans-oe[.]com[.]cn
“欧æ(OKX) - å ¨çé¢å çæ°åèµäº§äº¤æå¹³å° | å®å ¨ ä¸ä¸ 髿”
hans-oe.com.cn — Não verificado. Representação da marca: OKX; Tipo de golpe: Fake Exchange. Resumo das evidências: VirusTotal 20/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, Cluster25); URLQuery 2 alerts; CF Radar malicious; PhishDestroy score 95/100. Registrador: 浙江贰贰网络有限公司.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
PhishDestroy has confirmed that the domain hans-oe.com.cn is a sophisticated phishing site designed to impersonate the OKX cryptocurrency exchange. The site's page title, which translates to 'OKX - Global Leading Digital Asset Trading Platform | Safe Professional Efficient,' is a direct copy of the legitimate OKX homepage, intended to deceive users into entering their login credentials and potentially their two-factor authentication codes. This specific threat is categorized as a generic phishing attack targeting crypto asset holders, with the ultimate goal of draining victims' accounts.
The evidence against this domain is substantial. VirusTotal data shows that 18 out of 95 security vendors flagged the domain as malicious, a strong indicator of its fraudulent nature. Additionally, it appears on one security blocklist and was identified in one AlienVault OTX threat intelligence pulse. The domain was registered through the Chinese registrar 浙江贰贰网络有限公司 (Zhejiang Er'er Network Co., Ltd.) and was created on May 24, 2026, which is suspiciously dated in the future. It resolves to IP address 207.56.16.143 and uses a Let's Encrypt SSL certificate (R12) to appear legitimate. As of the latest check, the site has been taken offline, but users should remain vigilant as similar domains may appear.
If a user has visited hans-oe.com.cn or entered any personal information, they should immediately change their OKX account password and enable two-factor authentication if not already active. It is also advisable to contact OKX support to report the incident and monitor account activity for unauthorized transactions. PhishDestroy recommends verifying all exchange URLs directly from official sources and never clicking links from unsolicited emails or messages. Using a password manager and enabling hardware-based security keys can further reduce the risk of falling victim to such phishing campaigns.
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | hans-oe.com.cn |
malicious | Sinkholed |
| Cloudflare DNS | hans-oe.com.cn |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Tecnologias · 2 identified
Nginx is a web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache.
nginx.org 100% de confiançaHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% de confiançaAnálise do VirusTotal
Evidências e relatórios externos
PD-20260524-AA1CC2 Recipient: abuse@ntt.net Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo