MALICIOUS — HIGH
zoomtoken[.]net
PhishDestroy identifies zoomtoken.net as an active domain engaged in brand impersonation targeting the OKX cryptocurrency exchange.
- VirusTotal
- 0/92
- Blocklists
- 2 · MetaMask, SEAL
- 可用性
- 内容不可用 · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
zoomtoken.net — 内容不可用 (HTTP 502). 诈骗类型:Brand Impersonation. 证据摘要: VirusTotal 0/92; 2 external blocklist matches (MetaMask, SEAL); PhishDestroy score 66/100. 注册商: Hostinger.
为保留原始取证记录,下方的 PhishDestroy AI 详细分析仍使用英文。
Evidence Analysis
PhishDestroy identifies zoomtoken.net as an active domain engaged in brand impersonation targeting the OKX cryptocurrency exchange. This threat involves the creation of a counterfeit token domain designed to deceive users into interacting with fraudulent OKX-branded materials, potentially leading to financial loss through wallet compromise or fake token purchases. The domain leverages the trusted reputation of a well-known brand to exploit user trust and harvest credentials or cryptocurrency assets. Users should treat this domain as hostile and avoid any interaction, including wallet connections or data entry. zoomtoken.net exhibits several red flags consistent with malicious intent. The domain is currently resolving to IP address 145.223.77.134 and was registered through HOSTINGER operations, UAB on May 14, 2026. VirusTotal analysis shows 0 detections out of 95 scanning engines, indicating this threat has not yet been widely recognized by automated security systems. The domain is listed on 1 security blocklist and has been blocked by MetaMask, demonstrating proactive blocking by a major wallet provider. Despite using a Let's Encrypt SSL certificate, which provides no meaningful security assurance for users, the combination of recent registration, absence from detection systems, and immediate brand impersonation activity creates a dangerous threat profile that requires immediate attention from security teams and end users. Mitigation against this specific threat requires immediate domain blocking and user education on cryptocurrency scam tactics. Organizations should add zoomtoken.net and its IP address (145.223.77.134) to network blocklists and endpoint detection rules to prevent accidental exposure. Users should be advised to never enter credentials or connect cryptocurrency wallets to unfamiliar domains, regardless of branding. The combination of MetaMask blocking and low detection rates suggests this threat is newly emerged, making traditional signature-based defenses ineffective. Security teams should monitor for similar domains registered around the same date (May 14, 2026) and proactively block any newly registered domains containing 'token' or 'okx' in their naming convention. Cryptocurrency users should verify any token sale or exchange communication directly through official OKX channels and avoid clicking promotional links from unsolicited sources.
数据覆盖范围12 recorded checks
网络安全情报
威胁响应 Pipeline
公共封禁名单状态
已保存的截图
域名情报
技术细节DNS、SSL SAN、时间戳
ICANN OVERSIGHT
认证和 RAA 背景
认证和 RAA 背景
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
所用技术 · 3 identified
Hostinger is an employee-owned Web hosting provider and internet domain registrar.
www.hostinger.com 置信度 100%HTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 置信度 100%VirusTotal 分析
网站性能分析
Google PageSpeed Insights — mobile performance audit of zoomtoken.net · checked May 16, 2026
证据与外部报告Independent lookups and source reports
PD-20260516-F647F5 Recipient: abuse-tracker@hostinger.com Victim safety and official reportingImmediate actions and verified reporting channels
如果您输入了帐户凭据、个人或付款信息,或者从此域下载了文件,请立即采取措施。以下资源可帮助您报告事件并保护自己。