# PhishDestroy threat dossier — zbcn.hadin.net ================================================================ Fetched: 2026-05-01 17:04:13 UTC Canonical: https://phishdestroy.io/domain/zbcn.hadin.net/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 56/100 (PhishDestroy scoring — see methodology below) ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 3/94 security vendors flagged this domain Flagging vendors: ADMINUSLabs, ChainPatrol, Fortinet URLQuery: 2 detections ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 45.140.205.214 (CH, Bern) ASN: AS215540 GLOBAL CONNECTIVITY SOLUTIONS LLP Hosting org: Global Connectivity Solutions LLP Registrar: Gname.com Pte. Ltd. Nameservers: ["celeste.ns.cloudflare.com", "junade.ns.cloudflare.com"] Registered: 2026-04-18 Page title: Secure Verification ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Let's Encrypt / E8 Expires: 2026-07-12 Status: INVALID chain Fingerprint: 2d6d1b80610895c0a43c442abc10673bf141d8a3d63c905bf43ad60308e56d5f Subject Alternative Names (related infrastructure — often same operator): - hadin.net ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-04-18 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-04-18 15:45:37 UTC (by PhishDestroy tracker) Earliest abuse rec: 2026-04-18 12:49:11 UTC — PREDATES current WHOIS registration; retained from a previous registration cycle of the same domain name Last verified: 2026-04-26 19:40:22 UTC Neutralised: 2026-04-22 08:40:26 UTC Current status: taken down (registrar suspended or DNS dead) Note: one or more events above predate the WHOIS creation date. This typically means the same domain name was previously registered, detected, dropped, and then re-registered by a new party. PhishDestroy preserves the full historical record for operator-attribution research even when the underlying infrastructure changes hands. ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019da09c-7a2d-75e9-bb64-79fc3e0d80d0/ URLQuery: https://urlquery.net/report/10b8153a-e4d2-4fc5-a933-0e2f91dd5dba Wayback Machine: https://web.archive.org/web/*/zbcn.hadin.net crt.sh CT logs: https://crt.sh/?q=%25.zbcn.hadin.net Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=zbcn.hadin.net AlienVault OTX: https://otx.alienvault.com/indicator/domain/zbcn.hadin.net URLhaus: https://urlhaus.abuse.ch/host/zbcn.hadin.net/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-04-18 15:48:33 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] PhishDestroy identifies zbcn.hadin.net as an active confirmation stealing phishing site impersonating secure verification flows. The domain employs social engineering tactics to harvest victims’ authentication credentials and session tokens under the guise of routine account validation. No specific brand or drainer kit family has been attributed yet; investigation remains ongoing to map infrastructure to known malware families or transnational threat actors. Technical analysis confirms zbcn.hadin.net resolving to 45.140.205.214 with a Let's Encrypt SSL certificate and domain creation dated May 07, 2012. The registrar is listed as Gname.com Pte. Ltd., and VirusTotal currently shows 0 out of 95 detection engines flagging the page. Google Safe Browsing has not blacklisted this domain, and public blocklists contain no current entries. These characteristics indicate early-stage malicious hosting with low third-party visibility. Current status shows the phishing page remains live and fully operational, with the page title “Secure Verification” in use. Despite zero detection coverage and a benign registration profile, this domain poses an active threat to users expecting legitimate verification portals. Users should avoid interacting with any login prompts on zbcn.hadin.net, and system administrators are urged to block the IP 45.140.205.214 and domain at network edge. Remaining risk is assessed as active and significant until takedown occurs or detection signatures mature. Investigative seed: 5caef7. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260418-3BE430 Favicon MD5: 90229c0feb7d2ef63087d0f5ca245e90 TLS cert SHA-256: 2d6d1b80610895c0a43c442abc10673bf141d8a3d63c905bf43ad60308e56d5f ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/zbcn.hadin.net/ JSON API: https://api.destroy.tools/v1/check?domain=zbcn.hadin.net Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 131,000+ phishing domains. Confirmed takedowns: 91,000+. Site: https://phishdestroy.io