w6-okx[.]com[.]cn
“欧æOKXå®ç½æ³¨åä¸è½½-2026ææ°çOKX交ææAPPä¸è½½|å®å认è¯éç¦å©”
w6-okx.com.cn — 内容不可用 (HTTP 502). 品牌冒充:OKX; 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 4/91 (alphaMountain.ai, Bfore.Ai PreCrime, Netcraft, SOCRadar); URLQuery 1 alert; 2 external blocklist matches (MetaMask, SEAL); CF Radar malicious; PhishDestroy score 66/100. 注册商: 浙江贰贰网络有限公司.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
PhishDestroy identifies w6-okx.com.cn as an active brand impersonation site targeting OKX users. This domain resolves to IP 188.114.96.3 and was registered on March 20, 2026 through 浙江贰贰网络有限公司, leveraging a Let’s Encrypt SSL certificate to appear legitimate. VirusTotal currently shows 4/95 detections, indicating it has evaded detection by most antivirus engines. No confirmed listings on major blocklists such as PhishTank, OpenPhish, or URLVoid were detected at the time of analysis. While the domain is flagged as 'under_investigation,' its recent registration, lack of detection coverage, and use of a reputable SSL issuer suggest an emerging threat designed to harvest login credentials under the guise of a trusted exchange platform.
Technical indicators include the domain’s association with IP 188.114.96.3, which has no known reputation for legitimate OKX services and is hosted on infrastructure often associated with low-cost, high-risk deployments. The domain’s name—w6-okx.com.cn—explicitly impersonates the OKX brand with the 'w6' prefix likely intended to bypass simple keyword filters. The use of .com.cn (China’s ccTLD) and registration through a domestic registrar may indicate targeting of Chinese-speaking users or an attempt to exploit regional trust dynamics. Despite the absence of detections, the combination of brand impersonation, recent domain age, and hosting on a shared IP with minimal reputation signals a high-risk scam in early deployment.
To mitigate exposure, users should immediately block w6-okx.com.cn at the network and DNS levels and avoid accessing the site under any circumstances. Enable multi-factor authentication (MFA) on all OKX accounts and verify login URLs against the official OKX website (okx.com). Report any interactions with this domain to OKX support and your local cybercrime unit. Organizations are advised to update threat intelligence feeds to include this domain and monitor for similar patterns in domain registration or hosting behaviors. Proactive user education on recognizing impersonation tactics and verifying official channels remains essential to prevent credential theft and financial loss.
网络安全情报
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| DNS4EU | w6-okx.com.cn |
malicious | Sinkholed |
威胁响应 Pipeline
公共封禁名单状态
所用技术 · 5 identified
HTTP Strict Transport Security (HSTS) informs browsers that the site should only be accessed using HTTPS.
www.rfc-editor.org 置信度 100%Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 置信度 100%Cloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 置信度 100%Baidu Analytics (百度统计) is a free tool for tracking and reporting traffic data of users visiting your site.
tongji.baidu.com 置信度 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 置信度 100%VirusTotal 分析
证据与外部报告
PD-20260427-E1757C Recipient: walidfatiha789@gmail.com 您是否受到本网站的影响?
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。