pay-for-usdt-trc20-000236[.]pages[.]dev
“OKX”
pay-for-usdt-trc20-000236.pages.dev — Неперевірений. Уособлення бренду: OKX; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 13/91 (alphaMountain.ai, BitDefender, CyRadar, ESET, Emsisoft); URLQuery 1 alert; PhishDestroy score 94/100. Реєстратор: Cloudflare.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
pay-for-usdt-trc20-000236.pages.dev is currently hosting a page titled “OKX”. The site returns HTTP 200 and resolves to the Cloudflare‑owned address 188.114.97.3, which is geolocated to Canada. Registration occurred on 27 April 2026 and the domain is served through Cloudflare’s DNS (alex... and lars...). TLS is provided by Google Trust Services under the WE1 certificate, and HTTP/3 with HSTS is observed. Front‑end libraries include jQuery, confirming the presence of typical web‑application components. The domain is listed on a single security blocklist (PhishDestroy) and is classified as a brand‑impersonation phishing campaign targeting the OKX brand. VirusTotal scans show 14 of 91 vendors flagging the host, and Gridinsoft assigns a trust score of 0 / 100, indicating a high likelihood of malicious intent. The infrastructure is fully cloud‑based, offering no direct host‑level indicators beyond the shared Cloudflare IP range. No additional intelligence such as malware payloads, command‑and‑control endpoints, or credential‑harvesting URLs has been disclosed. Defenders should block the domain at perimeter and DNS layers, monitor for outbound connections to 188.114.97.3, and include the domain in threat‑intel feeds. Because the site uses a valid TLS certificate, standard TLS inspection may be required to uncover any embedded malicious content. Continuous re‑evaluation is advised as further indicators may emerge.
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | pay-for-usdt-trc20-000236.pages.dev |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Технології · 4 identified
jQuery is a JavaScript library which is a free, open-source software designed to simplify HTML DOM tree traversal and manipulation, as well as event handling, CSS animation, and Ajax.
jquery.com 100% впевненостіHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% впевненостіCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% впевненостіHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% впевненостіАналіз VirusTotal
Докази та зовнішні звіти
Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога