MALICIOUS — CRITICAL
ouyi[.]support
PhishDestroy identifies ouyi.support as a live crypto drainer page designed to trick visitors into connecting crypto wallets and signing malicious transactions.
- VirusTotal
- 18/91
- Blocklists
- No stored match
- Доступность
- Последний известный активный · HTTP 302
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
ouyi.support — Последний известный активный (HTTP 302). Олицетворение бренда: OKX; Тип мошенничества: Brand Impersonation. Сводка доказательств: VirusTotal 18/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF); URLScan malicious verdict; PhishDestroy score 100/100. Регистратор: Dynadot.
Подробный анализ PhishDestroy AI ниже оставлен на английском, чтобы сохранить исходную криминалистическую запись.
Evidence Analysis
PhishDestroy identifies ouyi.support as a live crypto drainer page designed to trick visitors into connecting crypto wallets and signing malicious transactions. The site mimics a legitimate brand interface to lure users into approving unauthorized token transfers that drain funds within seconds. Anyone who connects a wallet or enters seed phrases on this page risks losing all assets in connected accounts.
This domain was flagged after registering on August 22, 2025, through Dynadot Inc. It resolves to IP 54.215.31.113 and uses a Let’s Encrypt SSL certificate to appear trustworthy. VirusTotal currently shows 3 out of 95 security engines detecting the threat, which is common for newly activated crypto drainers that evade initial scans. The combination of a fresh registration date and low detection rate makes this site particularly dangerous for unsuspecting users.
If you visited ouyi.support, immediately disconnect your wallet from the site, revoke any suspicious permissions in your wallet settings, and transfer remaining funds to a new wallet. Run a malware scan on your device and consider rotating all passwords used on crypto platforms. Report the domain to PhishDestroy for further analysis to help protect others.
Охват данных12 recorded checks
Процесс реагирования на угрозы
Статус в публичных блок-листах
Сохранённый снимок
Аналитика доменов
Технические сведенияDNS, SAN в протоколе SSL, временные метки
ICANN OVERSIGHT
Аккредитация и контекст RAA
Аккредитация и контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технологии · 9 identified
High-performance HTTP server and reverse proxy, known for stability and low resource usage.
JavaScript library for building user interfaces with component-based architecture.
Web platform based on Nginx with LuaJIT for scalable web apps.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Tag management system for deploying marketing and analytics tags.
tagmanager.google.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Анализ VirusTotal
Анализ производительности сайта
Google PageSpeed Insights — mobile performance audit of ouyi.support · checked Apr 20, 2026
Доказательства и внешние отчетыIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
Если вы ввели учетные данные, личную или платежную информацию или загрузили файл с этого домена, примите немедленные меры. Ниже приведены ресурсы, которые помогут вам сообщить об инциденте и защитить себя.
Сообщите об этом в местные органы власти
Выберите свою страну, чтобы получить официальные контакты по киберпреступности или создать проект жалобы →.