revokes-aero-com[.]pages[.]dev
“Suspected phishing site | Cloudflare”
revokes-aero-com.pages.dev — Não verificado. Resumo das evidências: VirusTotal 12/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CyRadar); 3 external blocklist matches (MetaMask, ScamSniffer, SEAL); PhishDestroy score 100/100. Registrador: Cloudflare Pages.
A análise detalhada do PhishDestroy AI permanece em inglês para preservar o registro forense original.
This domain, revokes-aero-com.pages.dev, is flagged as a high-risk brand impersonation phishing site targeting OKX, a major cryptocurrency exchange platform. Analysis indicates the domain was designed to deceive users into believing they are interacting with legitimate OKX services, likely aiming to harvest credentials or facilitate unauthorized transactions. No specific drainer kit signatures were identified in initial scans, but the infrastructure aligns with known phishing campaigns impersonating financial and crypto-related services. Infrastructure analysis reveals the following technical indicators: the domain is detected by 11 out of 95 security vendors on VirusTotal, indicating moderate to high confidence in malicious classification. It is registered through Cloudflare Pages, a platform frequently abused for rapid deployment of phishing sites due to its ease of use and free hosting capabilities. The domain resolves to the IP address 172.66.47.91, associated with Cloudflare’s network infrastructure. The creation date of the domain is listed as March 25, 2026, which is anomalous and suggests either a typo-squatting attempt or an error in registration records. The SSL certificate is issued by Google Trust Services, providing a false sense of security to potential victims. The domain appears on four security blocklists, including MetaMask, PhishDestroy, SEAL, and ScamSniffer, further corroborating its malicious intent. Google Safe Browsing status was not explicitly provided but is likely flagged given the blocklist presence. As of the latest assessment, the domain has been taken offline, reducing immediate exposure to potential victims. However, the infrastructure and registration details suggest that the threat actors may redeploy similar phishing campaigns using comparable domains or hosting providers. Remaining risks include the potential for cloned or mirrored versions of the site to resurface under different domains, particularly those leveraging Cloudflare Pages or similar services. Users and organizations are advised to monitor for domains with similar naming patterns, enforce blocklist updates, and implement real-time domain reputation checks. Additionally, cryptocurrency users should verify the authenticity of any platform requesting credentials or transaction approvals, particularly those impersonating OKX or other high-profile exchanges.
Pipeline de resposta a ameaças
Status da lista de bloqueios pública
Inteligência forense
Tecnologias · 3 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% de confiançaCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% de confiançaHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% de confiançaAnálise do VirusTotal
Análise de desempenho do site
Google PageSpeed Insights — mobile performance audit of revokes-aero-com.pages.dev · checked Jun 26, 2026
Evidências e relatórios externos
Você foi afetado por este site?
Se você inseriu credenciais de conta, informações pessoais ou de pagamento, ou baixou um arquivo deste domínio, tome medidas imediatas. Abaixo estão os recursos para ajudá-lo a relatar o incidente e se proteger.
Notifique as autoridades locais
Selecione seu país para obter contactos oficiais do cibercrime ou crie um rascunho de reclamação →.
Verificar qualquer domínio
Análise de ameaças usando lista de bloqueio armazenada, WHOIS, DNS e evidências de verificação pública
Digitalize agoraDenunciar phishing
Envie domínios suspeitos para nosso banco de dados de ameaças — proteja a comunidade
DenunciarFeed de ameaças em tempo real
Relatórios recentes de phishing e alterações de disponibilidade observadas
MonitorarMantenha-se informado, mantenha-se seguro
Monitore ameaças em tempo real ou conteste esta listagem caso acredite que se trate de um falso positivo