okx-web[.]app
Category: Phishing
To use full-featured product, you have to purchase a license for Combo Cleaner. Limited seven days free trial available. Combo Cleaner is owned and operated by RCS LT, the parent company of PCRisk.com.
Description of okx-web[.]app
The domain okx-web[.]app appears to present itself as a cryptocurrency wallet and Web3 access page. Its title and metadata reference an "OKX Wallet" experience for importing or connecting a wallet, exploring decentralized applications, and interacting with multi-chain crypto services such as staking, swapping, and trading. The screenshot shows a minimal landing page focused on wallet connection actions rather than broader company or product information.
Based on the domain name and page branding, the site appears to be imitating or closely resembling the well-known OKX cryptocurrency platform rather than operating from that platform's primary domain. The naming pattern, combined with the wallet-import prompt and Web3 positioning, suggests the page may be intended to attract users looking for OKX-related wallet services.
No clear evidence in the provided scan identifies an independent legitimate operator behind this domain. The site appears to be a newly registered crypto-themed web property using branding associated with an established exchange and wallet ecosystem.
Safety Assessment for okx-web[.]app
Multiple security signals indicate elevated risk at the time of this scan. The domain was flagged by 16 out of 92 security engines, and several web-classification sources categorized it as phishing, fraud-related, or a newly registered suspicious website. In addition, blacklist data shows the domain was listed for social-engineering activity by a major browsing-protection source, which is a strong indicator of attempted credential harvesting or deceptive user interaction.
The domain also closely resembles okx.com in plain language and may be a look-alike intended to benefit from user confusion with the established OKX brand. That concern is reinforced by the page content: the screenshot prominently offers wallet connection and wallet import actions, which are common targets in crypto phishing campaigns because they can be used to solicit seed phrases, private keys, or other sensitive wallet credentials.
Although the malware file scan did not detect malicious files in the sampled content, that does not outweigh the broader phishing indicators. Based on these findings, this website may pose potential risks to visitors.
Technical Description
The site was using a valid Let's Encrypt TLS certificate at the time of the scan, hosted on a LiteSpeed web server at IP address 37.49.229.75 with hosting attributed to ESTOXY OU in Amsterdam, Netherlands. The domain is extremely new, registered only 3 days before the scan, has no Tranco ranking, and uses unsigned DNSSEC, which does not by itself indicate abuse but provides less DNS integrity assurance.
From a technical risk perspective, the strongest concerns are not the certificate or basic hosting setup, but the combination of very recent registration, phishing-related detections across multiple security engines, social-engineering blacklist presence, and branding that appears to mimic a known cryptocurrency service. The page also references wallet-related functionality and an additional related domain, which may warrant extra caution during further investigation.
Share your experience with this website. Was it safe? Did you encounter any issues?