app-zebec[.]network
“Zebec Network | Real‑Time Crypto Payroll & Payments”
On May 15, 2024, PhishDestroy identified the domain app-zebec.network as a credential harvesting endpoint engaged in active phishing campaigns. The domain mimics legitimate financial services to deceive victims into surrendering login credentials, posing a significant risk to enterprise and personal users alike. Current telemetry confirms ongoing malicious activity, warranting immediate defensive measures. This domain, registered through PDR Ltd. d/b/a PublicDomainRegistry.com, was created on April 29, 2026, and resolves to the IP address 188.114.97.3. VirusTotal analysis reveals that 1 of 95 security vendors flagged this domain for malicious activity, with no observed blocklist presence at this time. The SSL certificate, issued by Let’s Encrypt, may lend an air of legitimacy, though issuance mechanisms are frequently abused by threat actors to evade detection. Further, the domain’s recent creation date suggests opportunistic registration targeting current events or trending financial narratives. As of this advisory, app-zebec.network remains active and is actively resolving to its associated IP. Organizations and users are strongly advised to block this domain at the network perimeter and DNS level to prevent user exposure. Implementing browser-based controls such as safe browsing policies and endpoint detection rules (e.g., YARA signatures) is recommended to mitigate risk. Additionally, users should be reminded to verify website authenticity via multi-factor authentication and to avoid clicking on unsolicited links purporting to originate from financial institutions. Continuous monitoring of this domain and associated infrastructure is advised due to the evolving nature of credential harvesting campaigns.
Network Security Intelligence
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Quad9 DNS | app-zebec.network |
malicious | Sinkholed |
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies · 3 identified
Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 100% confidenceCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% confidenceHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% confidenceVirusTotal Analysis
Site Performance Analysis
Google PageSpeed Insights — mobile performance audit of app-zebec.network · checked Apr 29, 2026
Evidence & External Reports
PD-20260429-F0243C Recipient: abuse@publicdomainregistry.com Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive