Notification and current-status evidence
The sent-report ledger records the first outgoing report at . A report was sent to the recorded registrar; contact details remain in Domain Intelligence. The latest stored availability evidence still shows the domain reachable; 4 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
ouxyu[.]com
“Earn rewards when you get started on OKX | My referral code: 30628644 | OKX Europe”
PhishDestroy identifies ouxyu.com as a suspected crypto drainer phishing domain registered on December 9, 2024, currently under active investigation for generic phishing activity. The domain shows no affiliation with any legitimate brand and lacks identifiable drainer kit signatures in initial scans. Its structure mimics common cryptocurrency or wallet-themed landing pages, a tactic frequently employed by phishing actors to harvest credentials or private keys from unsuspecting users. The absence of detections in VirusTotal (4/95) suggests this domain is either newly operational or employs evasion techniques to avoid immediate detection. Further behavioral analysis is required to confirm payload delivery mechanisms and exfiltration endpoints.
The domain resolves to IP 54.215.31.113 and is registered via Dynadot Inc. with a Let's Encrypt SSL certificate, which does not indicate legitimacy. The domain was created on December 9, 2024, and currently shows no presence on Google Safe Browsing (GSB) blocklists. Independent threat intelligence platforms report zero third-party detections (4/95 on VirusTotal), and no public blocklists have flagged this domain at the time of analysis. These technical indicators suggest a recently emerged or stealthily operated phishing infrastructure.
As of this report, ouxyu.com remains active with an under-investigation status. No public takedown actions have been confirmed, and risk mitigation is pending further analysis. Users are advised to avoid interaction with this domain and report any suspicious encounters. Remaining risk is classified as undetermined pending completion of forensic analysis, but early indicators suggest potential for credential theft or cryptocurrency theft via fake wallet interfaces. Immediate domain blocking and IP-based filtering are recommended for organizations and security teams.
Gönderilen rapor kaydı
Gönderilen kanıt anlık görüntüsü
- Gönderildi
- Kayıt defteri kayıtları
- 1
- Vaka kimliği
PD-20260404-B2A409- Yakalanan sayfa başlığı
- Earn rewards when you get started on OKX | My referral code: 30628644 | OKX Europe
- PDF belgesi
- PDF kanıtı
Kanıtın tam metni
Policy Violations: Acceptable Use forbids illegal content; Spam & Abuse Policy prohibits phishing, fraud, malware; Dynadot may disable DNS and suspend domains
Applicable Laws: CFAA 18 U.S.C. §1030, Wire Fraud 18 U.S.C. §1343, CAN-SPAM Act
Ağ Güvenliği İstihbaratı
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Private YARA rules | static.okx.com/cdn/assets/okfe/util/ont/5.8.45/ont.js |
audit | Hunting_JS_WebAssembly |
| Hagezi Threat Feed | www.zhgwexpouy.net |
malicious | Sinkholed |
| DNS4EU | www.zhgwexpouy.net |
malicious | Sinkholed |
Tehdit Müdahale Pipeline
Engelleme listesi kapsamı
10 kaynak · 10.08.2026 tarihinde eşitlendi
Kaydedilen görüntü
Etki Alanı Analizi
Teknik ayrıntılarDNS, TLS adları ve zaman damgaları
ICANN OVERSIGHT
Akreditasyon ve RAA bağlamı
Akreditasyon ve RAA bağlamı
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
VirusTotal Analizi
Site Performans Analizi
Google PageSpeed Insights — mobile performance audit of ouxyu.com · checked Apr 4, 2026
Bu Siteden Etkilendiniz mi?
Hesap kimlik bilgilerini, kişisel bilgileri veya ödeme bilgilerini girdiyseniz ya da bu alan adından bir dosya indirdiyseniz hemen harekete geçin. Aşağıda olayı bildirmenize ve kendinizi korumanıza yardımcı olacak kaynaklar bulunmaktadır.
Yerel Yetkililere Bildirin
resmi siber suç iletişim bilgileri veya şikayet taslağı oluştur → almak için ülkenizi seçin.
Herhangi Bir Alan Adını Kontrol Et
Saklanan engelleme listesi, WHOIS, DNS ve genel tarama kanıtlarını kullanarak tehdit analizi
Şimdi TaraOltalama Olayını Bildir
Şüpheli alan adlarını tehdit veritabanımıza bildirin — topluluğu koruyun
BildirCanlı Tehdit Akışı
Son kimlik avı raporları ve gözlemlenen kullanılabilirlik değişiklikleri
İzleGelişmelerden Haberdar Olun, Güvende Kalın
Canlı tehditleri izleyin veya bunun yanlış bir uyarı olduğunu düşünüyorsanız bu kayda itiraz edin