MALICIOUS — CRITICAL
imtokenflp[.]com
This domain, imtokenflp.com, is flagged as an active brand impersonation threat targeting OKX, a major cryptocurrency exchange and wallet provider.
- VirusTotal
- 20/95
- Blocklists
- No stored match
- Disponibilidade
- Encoberto · alcançável · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
imtokenflp.com — Encoberto · alcançável (HTTP 502). Tipo de golpe: Crypto Scam. Resumo das evidências: VirusTotal 20/95 (ADMINUSLabs, Criminal IP, alphaMountain.ai, BitDefender, CyRadar); URLQuery 6 det.; CF Radar malicious; cloaking observed; PhishDestroy score 100/100. Registrador: Gname.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
Evidence Analysis
This domain, imtokenflp.com, is flagged as an active brand impersonation threat targeting OKX, a major cryptocurrency exchange and wallet provider. Analysis indicates the site mimics legitimate OKX wallet services, likely to harvest credentials or deploy crypto drainer malware. The domain does not currently host overt drainer kit artifacts but presents a placeholder page titled '网站筹建中' (Site Under Construction), a common tactic to evade initial scrutiny while preparing malicious payloads. No direct wallet interaction prompts are visible, but the infrastructure aligns with known phishing campaigns targeting crypto users through fake wallet interfaces or recovery portals. Infrastructure analysis reveals the following technical indicators: the domain was registered on September 07, 2025, through Gname.com Pte. Ltd., a registrar frequently associated with phishing domains. It resolves to IP address 188.114.96.3, hosted on Cloudflare’s network (AS13335), which is often leveraged to obscure origin servers and evade takedowns. The SSL certificate is issued by Let’s Encrypt (R13), a legitimate provider commonly abused in phishing operations. VirusTotal detection shows 20 out of 95 security vendors flagging the domain as malicious, while it appears on two blocklists: PhishDestroy and PhishingDB. Google Safe Browsing status is not explicitly provided but is likely marked as unsafe given the blocklist presence and VT score. Current status indicates the domain remains active, with no evidence of suspension or sinkholing. The placeholder page suggests the campaign may be in a preparatory phase, awaiting deployment of final malicious content. Response actions should include immediate blacklisting of the domain and IP across security gateways, as well as monitoring for related subdomains or typosquatting variants. Users are advised to verify wallet addresses via official OKX channels and avoid interacting with any unsolicited links or recovery prompts. The remaining risk is classified as high due to the domain’s active status, Cloudflare hosting, and established impersonation tactics targeting cryptocurrency assets.
Cobertura dos dados12 recorded checks
Inteligência de segurança de rede
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, SANs do SSL, carimbos de data e hora
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologias · 3 identified
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Third major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Análise do VirusTotal
Evidências arquivadas
Evidências e relatórios externosIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.