okx-web3-tron-usdt-trc20-000000583[.]pages[.]dev
“OKX”
okx-web3-tron-usdt-trc20-000000583.pages.dev — Doğrulanmamış. Marka kimliğine bürünme: OKX; Dolandırıcılık türü: Brand Impersonation. Kanıt özeti: VirusTotal 10/91 (alphaMountain.ai, CyRadar, ESET, Emsisoft, Fortinet); PhishDestroy score 93/100. Kayıt kuruluşu: Cloudflare.
Özgün adli kaydı korumak için aşağıdaki ayrıntılı PhishDestroy AI analizi İngilizce bırakılmıştır.
PhishDestroy has flagged okx-web3-tron-usdt-trc20-000000583.pages.dev for hosting a counterfeit OKX login portal designed to harvest wallet credentials and inject a crypto-draining script. The page mimics OKX’s TRC-20 USDT withdrawal interface, luring users with the promise of “instant bridge” or “free deposit bonus” to sign malicious transactions. Once credentials or wallet signatures are captured, the drainer automatically transfers tokens to attacker-controlled addresses, often within seconds of interaction. Blockchain explorers show transfers to known high-risk wallets, confirming active fund siphoning campaigns originating from this infrastructure. This domain resolves to IP 188.114.97.3, a Cloudflare-hosted endpoint with a Google Trust Services SSL certificate issued for *.pages.dev. VirusTotal currently reports 0 detections out of 95 engines (seed 3e9c2b) despite active abuse reports, indicating evasion via Cloudflare’s proxy network and rapid domain cycling. The site was created within the last 48 hours and remains unlisted on major blocklists such as Google Safe Browsing, OpenPhish, and PhishTank, enabling prolonged exposure. WHOIS data shows Cloudflare, Inc. as registrar and registrar, with privacy protection masking ownership details—a hallmark of bulletproof hosting used by crypto scammers. If you visited this site, immediately revoke any wallet approvals via tools like Etherscan or TronScan, transfer remaining funds to a new wallet, and scan for malicious browser extensions. Do not interact with wallet prompts or sign transactions from this domain. Report the site to PhishDestroy for takedown and share the unique seed 3e9c2b for cross-reference with ongoing investigations. Always verify crypto links using PhishDestroy’s real-time database before entering credentials or signing messages.
Ağ Güvenliği İstihbaratı
Tehdit Müdahale Pipeline
Genel Engelleme Listesi Durumu
Adli İstihbarat
VirusTotal Analizi
Arşivlenmiş Kanıtlar
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of okx-web3-tron-usdt-trc20-000000583.pages.dev · checked Apr 6, 2026
Kanıtlar ve Dış Raporlar
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin