okx-web3-usdt-trc20-payfor-00000028[.]pages[.]dev
“OKX”
okx-web3-usdt-trc20-payfor-00000028.pages.dev — Неперевірений. Уособлення бренду: OKX; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 12/91 (alphaMountain.ai, BitDefender, CyRadar, Emsisoft, Fortinet); Google Safe Browsing flagged; PhishDestroy score 100/100. Реєстратор: Cloudflare.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
This domain is flagged as a high-risk brand impersonation threat targeting OKX cryptocurrency users. Analysis indicates the infrastructure is designed to deceive victims into transferring USDT-TRC20 tokens to attacker-controlled wallets under the pretense of legitimate OKX web3 services. Infrastructure analysis reveals the following technical indicators: the domain was created on March 28, 2026, and is currently active. It resolves to IP address 172.66.44.173, hosted on Cloudflare infrastructure in Canada. The domain is registered through Cloudflare, Inc., and appears on one security blocklist. Google Safe Browsing explicitly flags it as phishing, while VirusTotal shows 13 out of 95 security vendors detecting malicious activity. The SSL certificate is issued by Google Trust Services (WE1), a common pattern observed in phishing domains leveraging legitimate CDN services. To mitigate this threat, users should avoid interacting with the domain entirely. Cryptocurrency holders should verify all transaction requests through official OKX channels only, using bookmarked URLs or the verified mobile application. Network administrators should implement DNS-based blocking for this domain and monitor for connections to 172.66.44.173. Security teams should treat any credentials or wallet addresses associated with this domain as compromised and initiate internal incident response procedures for affected users. The domain's use of Cloudflare hosting suggests potential fast-flux techniques, warranting continuous monitoring for related infrastructure.
Розвіддані з мережевої безпеки
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 4 identified
Fast, small JavaScript library simplifying HTML manipulation, event handling, and Ajax.
HTTP Strict Transport Security — forces browsers to use HTTPS connections only.
Web infrastructure and security company providing CDN, DDoS mitigation, and DNS services.
www.cloudflare.comThird major version of HTTP protocol, built on QUIC for faster, more reliable connections.
Аналіз VirusTotal
Аналіз продуктивності сайту
Google PageSpeed Insights — mobile performance audit of okx-web3-usdt-trc20-payfor-00000028.pages.dev · checked Mar 28, 2026
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога