lp-tokenfi-com[.]pages[.]dev
“Portals Presale powered by Genesis”
Resumo das evidências
PhishDestroy identifies lp-tokenfi-com.pages.dev as an active brand impersonation threat specifically targeting OKX, a well-known cryptocurrency exchange. The domain is currently under investigation due to its suspicious nature and remains active at the time of analysis. This phishing domain was created on April 18, 2026, and is registered through Cloudflare, Inc., a common registrar for malicious sites seeking to obscure their origin. The domain resolves to IP address 172.66.45.46 and uses an SSL certificate from Google Trust Services / WE1. Despite being active, VirusTotal shows 0 out of 95 vendors have flagged the domain, which may indicate it is newly deployed or evading detection. However, it already appears on one security blocklist, suggesting some awareness among threat intelligence platforms. The page title, "Portals Presale powered by Genesis," is likely a lure to trick users into believing they are participating in a legitimate presale event associated with OKX. This aligns with typical brand impersonation tactics where attackers replicate the look and feel of a trusted brand to steal credentials or cryptocurrency. Given the specialized nature of the threat—brand impersonation of a crypto exchange—the risk is elevated for users who may be targeted through phishing emails or social media campaigns. PhishDestroy recommends that users avoid interacting with this domain entirely. If you have already visited the site, do not enter any personal information, passwords, or private keys. Change your OKX account credentials immediately and enable two-factor authentication. For organizations, block the domain at the network level and educate users about verifying URLs before engaging with presale or promotional offers. Continuous monitoring is advised, as the domain may evolve its tactics or redirect to additional malicious infrastructure.
Data Coverage
Inteligência de segurança de rede
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | qwei2odjc8tbmcs98e.com |
malicious | Sinkholed |
| DNS4EU | qwei2odjc8tbmcs98e.com |
malicious | Sinkholed |
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 11/08/2026
10 fontes externas monitoradas Sem correspondência
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of lp-tokenfi-com.pages.dev · checked Apr 18, 2026
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo