Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@dynadot.com.
The latest stored availability evidence still shows the domain reachable; 2 months has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
zhgwexpouyi[.]info
“Earn rewards when you get started on OKX | My referral code: 49758894 | OKX”
zhgwexpouyi.info — Неперевірений. Уособлення бренду: OKX; Тип шахрайства: Brand Impersonation. Зведення доказів: VirusTotal 16/91 (alphaMountain.ai, BitDefender, Chong Lua Dao, CRDF, CyRadar); URLQuery 2 alerts; URLScan malicious verdict; CF Radar malicious; PhishDestroy score 95/100. Реєстратор: Dynadot.
Докладний аналіз PhishDestroy AI нижче залишено англійською, щоб зберегти оригінальний криміналістичний запис.
The domain zhgwexpouyi.info has been identified as a brand impersonation threat specifically targeting OKX, a cryptocurrency exchange platform. This phishing domain attempted to deceive users by presenting a page titled 'Earn rewards when you get started on OKX | My referral code: 49758894 | OKX Europe', leveraging a referral code to appear legitimate. The site was designed to harvest login credentials or personal information from unsuspecting victims seeking cryptocurrency rewards.
Technical indicators reveal that the domain was flagged by 3 out of 95 security vendors on VirusTotal, indicating moderate detection. It was registered through Dynadot Inc on February 11, 2026, and resolved to IP address 54.215.31.113. The SSL certificate was issued by Let's Encrypt (YR2), and the domain appeared on one security blocklist. Notably, Google Safe Browsing did not flag the domain, which may have allowed it to operate undetected for a period.
The domain is currently offline, having been taken down following detection. PhishDestroy recommends that users who may have interacted with zhgwexpouyi.info immediately change their OKX passwords and enable two-factor authentication. Remaining risk is low due to the takedown, but vigilance against similar phishing attempts is advised.
Розвіддані з мережевої безпеки
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | zhgwexpouyi.info |
malicious | Sinkholed |
| DNS4EU | zhgwexpouyi.info |
malicious | Sinkholed |
Процес реагування на загрози Pipeline
Статус у публічних блоклистах
Збережений знімок
Аналітика доменів
Технічні деталіDNS, SAN-адреси SSL, мітки часу
ICANN OVERSIGHT
Акредитація та контекст RAA
Акредитація та контекст RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Технології · 6 identified
React is an open-source JavaScript library for building user interfaces or UI components.
reactjs.org 100% впевненостіOneTrust is a cloud-based data privacy management compliance platform.
www.onetrust.com 100% впевненостіHTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 100% впевненостіGoogle Tag Manager is a tag management system (TMS) that allows you to quickly and easily update measurement codes and related code fragments collectively known as tags on your website or mobile app.
www.google.com 100% впевненостіGoogle Analytics is a free web analytics service that tracks and reports website traffic.
google.com 100% впевненостіАналіз VirusTotal
Докази та зовнішні звіти
PD-20260617-8D2910 Recipient: abuse@dynadot.com Чи вплинув на вас цей сайт?
Якщо ви ввели облікові дані облікового запису, особисту чи платіжну інформацію або завантажили файл із цього домену, негайно вживіть заходів. Нижче наведено ресурси, які допоможуть вам повідомити про інцидент і захистити себе.
Зверніться до місцевих органів влади
Виберіть свою країну, щоб отримати офіційні контакти кіберзлочинців або створити проект скарги →.
Перевірити будь-який домен
Аналіз загроз за допомогою збереженого списку блокувань, WHOIS, DNS і загальнодоступних доказів сканування
Сканувати заразПовідомити про фішинг
Додавайте підозрілі домени до нашої бази даних загроз — захищайте спільноту
ПовідомитиПотокова стрічка про загрози
Останні звіти про фішинг і помічені зміни доступності
ВідстежуватиБудьте в курсі подій, дбайте про свою безпеку
Слідкуйте за актуальними загрозами або оскаржте цей запис, якщо вважаєте, що це помилкова тривога