Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 2 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
os-xlayer[.]com
“X Layer | EVM Layer 2|OKB | OKX Wallet”
Observação armazenada
Contraste de títulos observado
Resumo das evidências
This domain, os-xlayer.com, is actively engaged in brand impersonation targeting OKX, a major cryptocurrency exchange platform. The phishing site presents itself as an official portal for X Layer, an EVM Layer 2 solution associated with OKX, using the page title 'X Layer | EVM Layer 2|OKB | OKX Wallet.' The threat type aligns with brand impersonation, likely intended to deceive users into interacting with fraudulent wallet or transaction interfaces, potentially leading to unauthorized asset transfers or credential harvesting.
Infrastructure analysis reveals the domain was registered on May 28, 2024, through Global Domain Group LLC, a registrar frequently observed in malicious campaigns. It resolves to the IP address 172.67.158.158, hosted on Cloudflare’s network (AS13335) in the United States. Detection metrics indicate limited but concerning visibility: VirusTotal reports 1 out of 95 security vendors flagging the domain as malicious. The domain appears on three independent security blocklists, including PhishDestroy and MetaMask’s threat intelligence feeds. The SSL certificate is issued by Let’s Encrypt (serial number E7), a common tactic to lend superficial legitimacy to phishing sites.
As of the latest assessment, os-xlayer.com remains active and unresolved, posing a persistent risk to users. No takedown actions have been observed, and the domain continues to resolve to its Cloudflare-hosted endpoint. The combination of brand impersonation, low initial detection rates, and use of bulletproof infrastructure suggests a calculated effort to evade automated defenses. Users are advised to verify domain authenticity via official channels, avoid interacting with unsolicited wallet prompts, and cross-reference URLs against known blocklists before engaging with cryptocurrency-related platforms.
Instantâneo das evidências enviadas
- Enviado
- Registros do livro-razão
- 1
- ID do caso
PD-20260528-8549D2- Título da página capturada
- X Layer | EVM Layer 2|OKB | OKX Wallet
- Artefato PDF
- Evidência em PDF
Base jurídica
Texto completo da evidência
Acceptable Use Policy (AUP): The domain os-xlayer.com is engaged in phishing activities, which directly contravenes the prohibition against illegal activities and deception outlined in your AUP.
Terms of Service (TOS): The fraudulent nature of the operations associated with this domain constitutes a clear violation of your TOS, which reserves the right to suspend or terminate services for such misconduct.
Applicable Laws (Unknown):
Computer Fraud and Abuse Act (CFAA): This U.S. federal law prohibits unauthorized access to computers and networks, which is relevant given the phishing activities associated with this domain.
Wire Fraud Statute (18 U.S.C. § 1343): This statute criminalizes the use of electronic communications to commit fraud, applicable to the fraudulent schemes being executed via os-xlayer.com.
CAN-SPAM Act (15 U.S.C. § 7701): This law regulates commercial email and prohibits misleading header information, which is often a component of phishing schemes.
Regulatory Note: Failure to take immediate action against this domain may expose your organization to liability under applicable laws and could result in regulatory scrutiny. It is imperative to act swiftly to mitigate any potential legal repercussions.
Data Coverage
Pipeline de resposta a ameaças
Cobertura de listas de bloqueio
10 fontes externas monitoradas · instantâneo de 10/08/2026
Captura armazenada
Inteligência de Domínios
Detalhes técnicosDNS, nomes TLS e datas
ICANN OVERSIGHT
Credenciamento e contexto RAA
Credenciamento e contexto RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Tecnologias
7 tecnologias identificadas com alta confiança
Análise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of os-xlayer.com · checked May 28, 2026
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo