cyhershoke[.]com
“CYBERSHOKE – Серверы КС 2”
This domain, cyhershoke.com, represents an elevated-risk brand impersonation campaign targeting users of the OKX cryptocurrency exchange platform. Analysis indicates the infrastructure was specifically designed to mimic legitimate OKX authentication portals, likely to harvest user credentials, private keys, or two-factor authentication codes through deceptive login interfaces. The domain employs social engineering tactics common in cryptocurrency phishing, where victims are tricked into entering sensitive account information under the false pretense of security verification, account upgrades, or reward distributions. Infrastructure analysis reveals multiple technical indicators supporting this assessment. The domain was registered on March 27, 2026, through NICENIC INTERNATIONAL GROUP CO., LIMITED, a registrar frequently associated with high-risk domains. It resolves to the IP address 188.114.97.3, hosted by CloudFlare in Canada, a common obfuscation tactic to mask backend infrastructure. Detection metrics show 14 out of 95 security vendors on VirusTotal flagged the domain as malicious, while it appears on one security blocklist, specifically PhishDestroy. The SSL certificate, issued by Google Trust Services (WE1), provides a false sense of legitimacy to unsuspecting users. Users who may have interacted with cyhershoke.com should take immediate remedial actions to mitigate potential compromise. First, revoke any active sessions on the legitimate OKX platform and reset account credentials using a secure, non-compromised device. Enable multi-factor authentication if not already active, and monitor account activity for unauthorized transactions or configuration changes. If cryptocurrency wallets or private keys were entered, transfer assets to a new wallet immediately, as credentials may have been exfiltrated. Report the incident to the legitimate platform’s security team and consider filing a report with relevant cybersecurity authorities to aid in tracking the campaign.
Gönderilen rapor kaydı
Gönderilen kanıt anlık görüntüsü
- Gönderildi
- Kayıt defteri kayıtları
- 1
- Vaka kimliği
PD-20260327-4211B6- Yakalanan sayfa başlığı
- CYBERSHOKE – Серверы КС 2
- PDF belgesi
- PDF kanıtı
Kanıtın tam metni
Policy Violations: “Services may be used only for lawful purposes… fraud, abuse and illegal activity prohibited. Violations may result in immediate suspension.” + dedicated abuse handling and takedown
Applicable Laws: Crimes Ordinance Cap.200 (Fraud), Theft Ordinance Cap.210 §16A (fraud by deception), Personal Data (Privacy) Ordinance Cap.486
Ağ Güvenliği İstihbaratı Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| OpenDNS | cyhershoke.com |
phishing | Phishing Block |
| Cloudflare DNS | cyhershoke.com |
malicious | Sinkholed |
| DNS4EU | cyhershoke.com |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 kaynak · 10.08.2026 tarihinde eşitlendi
Tespit zaman çizelgesi
Kaydedilmiş gözlemler kronolojik sıradadır.
-
Erişilebilirlik
Erişilebilirlik: ilk kez dns_inactive olarak gözlemlendi
f93a11f87e4d -
Erişilebilirlik
Erişilebilirlik: dns_inactive → unknown
1d101bf701e9 -
Erişilebilirlik
Erişilebilirlik: unknown → dns_inactive
2a62bfb0563c -
Erişilebilirlik
Erişilebilirlik: dns_inactive → inactive
703fb67ebb87 -
Erişilebilirlik
Erişilebilirlik: inactive → dns_inactive
f52d526b76a1 -
Erişilebilirlik
Erişilebilirlik: dns_inactive → unknown
7632cb5f04ff -
Erişilebilirlik
Erişilebilirlik: unknown → inactive
47c10a1ae604 -
Erişilebilirlik
Erişilebilirlik: inactive → unknown
671c54a0a7bd -
Erişilebilirlik
Erişilebilirlik: unknown → dns_inactive
6dfe9145995c -
Erişilebilirlik
Erişilebilirlik: dns_inactive → inactive
ed33b110685d
Tümünü göster (6)
-
Erişilebilirlik
Erişilebilirlik: inactive → dns_inactive
641ed81dc4d5 -
Erişilebilirlik
Erişilebilirlik: dns_inactive → unknown
4b1288db9b07 -
Erişilebilirlik
Erişilebilirlik: unknown → inactive
89e0541576eb -
Erişilebilirlik
Erişilebilirlik: inactive → unknown
e3751b657fc6 -
Erişilebilirlik
Erişilebilirlik: unknown → dns_inactive
d0b7046e8c2f -
Erişilebilirlik
Erişilebilirlik: dns_inactive → inactive
de74c53c34dd
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of cyhershoke.com · checked Mar 28, 2026
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin