# PhishDestroy threat dossier — zealouswap.com ================================================================ Fetched: 2026-06-30 06:48:45 UTC Canonical: https://phishdestroy.io/domain/zealouswap.com/ ## VERDICT ---------------------------------------------------------------- TAKEN DOWN (neutralised) Composite threat score: 100/100 (PhishDestroy scoring — see methodology below) Scam classification: Crypto Drainer ## DETECTION EVIDENCE ---------------------------------------------------------------- VirusTotal: 1/91 security vendors flagged this domain Flagging vendors: Gridinsoft AlienVault OTX: 1 pulses (threat-intel feed mentions) Public blocklists: listed on 3 independent blocklists ## INFRASTRUCTURE ---------------------------------------------------------------- IP address: 172.67.193.194 (US, San Francisco) ASN: ASAS13335 CLOUDFLARENET - Cloudflare, Inc., US Hosting org: AS13335 Cloudflare, Inc. Registrar: Dynadot Inc Nameservers: anderson.ns.cloudflare.com, perla.ns.cloudflare.com Registered: 2026-06-12 Expires: 2027-06-12 Page title: Zealous Swap - Kaspa DEX with Sustainable Liquidity Infrastructure ## TLS CERTIFICATE ---------------------------------------------------------------- Issuer: Google Trust Services / WE1 Expires: 2026-09-10 Status: INVALID chain Fingerprint: 0f11dbbbd4bc155927eb6367c4616f7ff7e5f2e3632ff3090e5429ab5e3765cb ## ABUSE-REPORT HISTORY (evidence of registrar non-response) ---------------------------------------------------------------- Status: CLOSED — no report required. This domain was neutralised before the abuse-report cycle could be dispatched — either the hosting provider / registrar suspended it on their own, the DNS went dead, or the operator abandoned the infrastructure. PhishDestroy keeps the evidence bundle on file for audit but no formal notice was sent. ## TIMELINE ---------------------------------------------------------------- Domain registered: 2026-06-12 (per WHOIS / CT — may reflect a renewal or transfer date, not first-ever registration) First detected: 2026-06-15 13:32:40 UTC (by PhishDestroy tracker) First reported: 2026-06-17 20:42:23 UTC (abuse notice filed) Last verified: 2026-06-30 08:20:34 UTC Neutralised: 2026-06-16 00:40:13 UTC Current status: taken down (registrar suspended or DNS dead) ## EXTERNAL CORROBORATION (third-party evidence) ---------------------------------------------------------------- URLScan.io: https://urlscan.io/result/019ecb0c-bdc3-722f-bec7-3631e24a3296/ URLQuery: https://urlquery.net/report/261038bd-c732-47ad-b488-cb775bf6b843 Wayback Machine: https://web.archive.org/web/*/zealouswap.com crt.sh CT logs: https://crt.sh/?q=%25.zealouswap.com Google transparency: https://transparencyreport.google.com/safe-browsing/search?url=zealouswap.com AlienVault OTX: https://otx.alienvault.com/indicator/domain/zealouswap.com URLhaus: https://urlhaus.abuse.ch/host/zealouswap.com/ ## ANALYST NARRATIVE ---------------------------------------------------------------- [Generated: 2026-06-25 18:24:55 UTC — narrative may predate facts above. Treat fields in TIMELINE / DETECTION EVIDENCE / INFRASTRUCTURE as authoritative if they differ from the prose below.] This domain, zealouswap.com, is actively flagged as a crypto drainer targeting cryptocurrency users. Analysis indicates the site impersonates a decentralized exchange (DEX) platform, specifically mimicking Kaspa DEX infrastructure to deceive victims into authorizing malicious transactions. The domain remains operational as of the latest verification, posing an ongoing threat to users interacting with its interface. Infrastructure analysis reveals the domain was registered on June 12, 2026, through Dynadot Inc, an uncommon timeline suggesting potential domain squatting or preemptive registration for malicious purposes. It resolves to IP address 172.67.193.194, hosted on AS13335 (Cloudflare, Inc.), a network frequently leveraged to obscure origin servers. The SSL certificate is issued by Google Trust Services (WE1), a legitimate provider often exploited to lend false credibility. VirusTotal detection shows 1 of 95 security vendors flagging the domain, while it appears on 3 distinct security blocklists, including PhishDestroy and MetaMask. The page title, 'Zealous Swap - Kaspa DEX with Sustainable Liquidity Infrastructure,' reinforces the impersonation of a legitimate Kaspa-based DEX. Current status confirms the domain is still active, with no evidence of takedown or mitigation. Risk assessment classifies this as high due to the direct financial threat posed by crypto drainers, which execute unauthorized transactions to siphon assets from connected wallets. Users are advised to immediately block the domain at the network level and revoke any wallet permissions granted to zealouswap.com or associated smart contracts. Cryptocurrency holders should verify DEX platforms via official sources, scrutinize domain registration dates, and cross-reference IP resolutions with known legitimate endpoints. Security teams should update blocklists to include this domain and its resolved IP, while monitoring for related infrastructure using the unique seed b3b4cb for correlation. ## EVIDENCE HASHES ---------------------------------------------------------------- PhishDestroy Case ID: PD-20260617-CC6AFA Favicon MD5: 90229c0feb7d2ef63087d0f5ca245e90 TLS cert SHA-256: 0f11dbbbd4bc155927eb6367c4616f7ff7e5f2e3632ff3090e5429ab5e3765cb ## SCORING METHODOLOGY ---------------------------------------------------------------- Composite score is NOT derived from VirusTotal alone. PhishDestroy aggregates: - VirusTotal positive ratio - Public blocklist consensus (MetaMask, ScamSniffer, OpenPhish, PhishTank, URLhaus, CryptoFirewall, SEAL, Polkadot, Enkrypt, Phishunt, DiscordPhishing, PhishingDB) - Cloaking detection (HTTP 666 or rendering delta between bot and real visitor) - DNS-filter consensus (Quad9, CleanBrowsing, NextDNS, AdGuard, Cloudflare, etc.) - AlienVault OTX pulses + Cloudflare Radar + Google Safe Browsing - URLScan / URLQuery verdicts - Brand-impersonation heuristics (DOM analysis of forms, logos, wording) - Known phishing-kit fingerprinting (favicon hash, JS obfuscation signatures) - Wallet-drainer family classification (Angel, MS, Rainbow, Pink, Inferno, ...) - Free-TLS vs paid-cert ratio (throwaway infrastructure signal) - Registrar/hosting abuse history (this registrar's track record) - Human researcher sign-off (volunteer takedown team) A domain present in our database is ALREADY flagged. A low VT count by itself does NOT mean the domain is safe — new scam domains routinely show 0/95 VT for their first 7–30 days while actively draining wallets. Always cross-reference the composite score and the individual indicators above, not just VT. ## CORRECTIONS / APPEALS ---------------------------------------------------------------- Full HTML report: https://phishdestroy.io/domain/zealouswap.com/ JSON API: https://api.destroy.tools/v1/check?domain=zealouswap.com Appeal a flag: https://phishdestroy.io/appeals/ (responded to within 48 hours, FP rate <0.01%) Submit a report: https://t.me/PhishDestroy_bot About PhishDestroy: volunteer-driven open-source threat-intelligence platform. Tracked: 172,677 domains (13,093 alive under monitoring, 158,994 confirmed takedowns/dead). Site: https://phishdestroy.io