# zefowex.com — SUSPICIOUS > Zefowex.com was linked to a phishing campaign targeting online casino users. Avoid interaction and verify site legitimacy before sharing data. ## Summary PhishDestroy identifies zefowex.com as a medium-risk phishing domain primarily associated with generic phishing threats. The site was crafted to deceive users by promoting a blockchain-based online casino, potentially aiming to steal personal or financial information through fraudulent means. Supporting evidence includes the domain's recent creation date (August 10, 2025) and registration via Key-Systems GmbH, which points to a newly established infrastructure. VirusTotal flags 3 out of 95 security vendors on this domain, and it appears on one security blocklist. The domain resolved to the IP address 104.21.42.210 and received a very low trust score of 1/100 from Gridinsoft, indicating significant suspicion. The page title and content suggest attempts to lure victims with cryptocurrency gambling incentives, a common vector for phishing attacks. Currently, the domain is offline, mitigating immediate risk to users. However, users should remain cautious and avoid engaging with this or similar domains. It is recommended to verify any site’s authenticity independently before submitting sensitive information, especially when dealing with newly created domains promoting financial products or services. Monitoring and blocking such domains help prevent phishing-induced credential or fund theft. ## Threat Details - Verdict: SUSPICIOUS - Site status: dead (HTTP 403) - Page title: ZEFOWEX | Play at the best online casino based on Blockchain ## Domain Intelligence - Registered: 2025-08-10 23:18:04 - Expires: 2026-08-10 23:18:04 - Registrar: Key-Systems GmbH - Country: DE - IP: 104.21.42.210 - IP Country: US - IP City: San Francisco - IP Org: AS13335 Cloudflare, Inc. - Nameservers: aragorn.ns.cloudflare.com gwen.ns.cloudflare.com - SSL Issuer: none ## Detection Status - VirusTotal: 3 vendors flagged Vendors: ["ADMINUSLabs", "alphaMountain.ai", "Fortinet"] - Google Safe Browsing: clean - Blocklists: 1 hits Lists: ["PhishDestroy"] ## Evidence - Screenshot: https://urlscan.io/screenshots/019a410c-0701-734d-9f4c-1d97f213a7c9.png - Cloudflare Radar: https://radar.cloudflare.com/scan/95ef27b7-9318-4d06-b632-d940b4671da5 - PhishDestroy: https://phishdestroy.io/domain/zefowex.com/ - LLM endpoint: https://phishdestroy.io/domain/zefowex.com/llm.txt ## If You Visited This Site 1. Change any passwords you may have entered 2. Enable 2FA on all related accounts 3. Monitor your accounts for unauthorized activity 4. Report to: FBI IC3, Europol, local authorities --- Report by PhishDestroy | https://phishdestroy.io/domain/zefowex.com/ Last updated: 2026-03-19