rtxtoken.live
“Vercel Security Checkpoint”
This domain www.rtxtoken.live is flagged for active brand impersonation targeting OKX. 3 out of 95 security vendors have flagged it on VirusTotal.
Phân tích chi tiết của PhishDestroy AI bên dưới được giữ bằng tiếng Anh để bảo toàn hồ sơ pháp chứng gốc.
Tóm tắt bằng chứng
This domain, www.rtxtoken.live, poses a significant threat as an active brand impersonation site targeting the cryptocurrency exchange OKX. The site is designed to appear legitimate and may trick users into divulging sensitive information, such as login credentials, by mimicking the look and feel of the genuine OKX website.
Analysis indicates that www.rtxtoken.live has been flagged by 3 out of 95 security vendors on VirusTotal, suggesting a level of sophistication in its design and execution. The domain is registered through NICENIC INTERNATIONAL GROUP CO., LIMITED, which has a history of being associated with suspicious activities. Additionally, the site resolves to the IP address 64.29.17.1 and uses a Let's Encrypt SSL certificate, which is common among both legitimate and malicious sites. The presence of the page title 'Vercel Security Checkpoint' does not guarantee the site's safety and may be used to deceive users.
If a user has visited www.rtxtoken.live, they should immediately take steps to secure their accounts. This includes changing passwords for OKX and any other accounts where the same credentials were used. Users should also monitor their financial accounts for any unauthorized transactions and report any suspicious activity to their bank or financial institution. Furthermore, it is recommended to run a full system scan using reputable antivirus software to ensure that no malware was installed. For those who suspect they may have fallen victim to this impersonation, contacting OKX support directly through their official website is crucial to receive further guidance and assistance.
Tình báo an ninh mạng Registrar context
Forensic History & Detection Timeline
-
VirusTotal Detections Update Jun 25, 2026 · 19:10 UTCVirusTotal scanner detections updated from 0 to 3. Added scanner alerts: Gridinsoft, SOCRadar, alphaMountain.ai.
Pipeline ứng phó với các mối đe dọa
Trạng thái trong danh sách chặn công khai
Evasion analysis
Cloaking & traffic-distribution check
Stored crawler-versus-browser observations for this host, plus a live fingerprint check for Keitaro-style traffic distribution systems.
- Stored cloaking flag
- Not yet scanned
- Last cloaking scan
- Server header seen by scanner
Vercel
Scanner note: dead_http: raw=http_451; http=451; via=https_proxy; server=Vercel; provider_error=DEPLOYMENT_DISABLED
Provider response during scan: DEPLOYMENT_DISABLED
Bản chụp đã lưu · 2 sources
Thông tin về tên miền
Chi tiết kỹ thuậtDNS, SAN trong SSL, dấu thời gian
ICANN OVERSIGHT
Bối cảnh công nhận và RAA
Bối cảnh công nhận và RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Latest Classified Outcome 2026-09-21 02:46:09 UTC
Phân tích của VirusTotal
Phân tích hiệu suất trang
Google PageSpeed Insights — mobile performance audit of rtxtoken.live · checked Jun 25, 2026
Bằng chứng và các báo cáo bên ngoài
Bạn có bị ảnh hưởng bởi trang web này không?
Nếu bạn đã nhập thông tin xác thực tài khoản, thông tin cá nhân hoặc thông tin thanh toán hoặc đã tải xuống tệp từ miền này, hãy hành động ngay lập tức. Dưới đây là các nguồn lực giúp bạn báo cáo vụ việc và bảo vệ chính mình.
Hãy báo cáo với chính quyền địa phương
Chọn quốc gia của bạn để nhận liên hệ tội phạm mạng chính thức hoặc soạn thảo đơn khiếu nại →.
Kiểm tra bất kỳ tên miền nào
Phân tích mối đe dọa bằng cách sử dụng danh sách chặn được lưu trữ, WHOIS, DNS và bằng chứng quét công khai
Quét ngayBáo cáo lừa đảo qua email
Hãy gửi các tên miền đáng ngờ đến cơ sở dữ liệu mối đe dọa của chúng tôi — để bảo vệ cộng đồng
Báo cáoDòng tin tức về các mối đe dọa thời gian thực
Các báo cáo lừa đảo gần đây và những thay đổi về tính khả dụng được quan sát thấy
Theo dõiLuôn cập nhật thông tin, luôn an toàn
Theo dõi các mối đe dọa đang diễn ra hoặc phản đối danh sách này nếu bạn cho rằng đây là kết quả báo động sai