MALICIOUS — HIGH
فحص التصيد والأمان للنطاق zurifarm.com
zurifarm[.]
PhishDestroy identifies zurifarm.com (seed: 636fbb) as an active credential theft domain under investigation for hosting fraudulent login portals.
- VirusTotal
- 3/91
- Blocklists
- No stored match
- التوفر
- المحتوى غير متوفر · HTTP 502
Do not enter credentials, seed phrases, payment details, or personal information on this domain.
Jump to section
zurifarm.com — المحتوى غير متوفر (HTTP 502). نوع الاحتيال: Credential Phishing. ملخص الأدلة: VirusTotal 3/91 (CRDF, Gridinsoft, SOCRadar); URLQuery 2 alerts; PhishDestroy score 65/100. مسجّل النطاق: Fewmoretaps OU d/b/a T….
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
Evidence Analysis
PhishDestroy identifies zurifarm.com (seed: 636fbb) as an active credential theft domain under investigation for hosting fraudulent login portals. This tactic aims to harvest user credentials for unauthorized access to financial or personal accounts, posing significant risks to visitors.
This domain was flagged with 0 detections out of 95 on VirusTotal, indicating no immediate antivirus or security tool blocking. The domain was registered through Fewmoretaps OU d/b/a Trustname.com, created on March 16, 2026, and currently resolves to IP 5.78.179.92. Due to its recent creation and low detection rate, it remains unlisted on major blocklists and holds an unverified trust score, making it a high-risk target for unsuspecting users.
Mitigation for credential theft domains like zurifarm.com requires proactive blocking at the network level. Organizations should add the domain and its resolving IP to firewall, DNS, and email filtering blocklists immediately. Users should avoid interacting with unsolicited links, verify site legitimacy via official channels, and enable multi-factor authentication on all critical accounts to reduce exposure to credential harvesting attacks.
Stored source results
Recorded verdicts and infrastructure observations for this domain.
نطاق تغطية البيانات12 recorded checks
استخبارات أمن الشبكات Registrar context
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Hagezi Threat Feed | zurifarm.com |
malicious | Sinkholed |
| DNS4EU | zurifarm.com |
malicious | Sinkholed |
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
تحليل VirusTotal
الأدلة والتقارير الخارجيةIndependent lookups and source reports
Victim safety and official reportingImmediate actions and verified reporting channels
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.