Notification and current-status evidence
The sent-report ledger records the first outgoing report at .
The recorded recipient is abuse@spaceship.com.
The latest stored availability evidence still shows the domain reachable; 22 days has elapsed since the first outgoing report.
ICANN RAA §3.18 describes registrar abuse-contact and handling obligations. This section records outgoing timestamps, listed recipients, case identifiers, and later availability. It does not by itself prove receipt, acknowledgement, investigation, remediation, or contractual non-compliance.
zenreward[.]site
Phishing and security check for zenreward.site
“Rewards Center”
Analysis of zenreward.site, created on 22 June 2026 and currently active, reveals a short‑lived phishing infrastructure that exploits Cloudflare’s edge network. The domain resolves to IP 172.67.157.185, an address owned by Cloudflare, Inc. and geolocated to Canada. Registration was performed through Spaceship, Inc., and the authoritative nameservers are kai.ns.cloudflare.com and lana.ns.cloudflare.com, confirming reliance on Cloudflare DNS services. The site serves a page titled “Rewards Center” over HTTPS with a certificate issued by Google Trust Services (WE1), indicating a legitimate‑looking TLS configuration. HTTP responses return status code 200 and the server advertises Cloudflare Browser Insights and HTTP/3 support, matching typical Cloudflare hosting behaviour.
Threat intelligence signals are significant: fifteen of ninety‑one VirusTotal scanners flag the domain as malicious, and it appears on one external blocklist. PhishDestroy has already added zenreward.site to its blocklist, providing an additional protective layer. No public Safe Browsing, Open Threat Exchange, or detailed payload information (such as credential‑harvesting forms) has been observed, leaving the exact phishing content uncertain.
Given the high‑risk rating, defenders should treat zenreward.site as a priority indicator. Immediate mitigation steps include adding the domain and its resolving IP address to outbound filtering and DNS‑level blocklists, updating intrusion‑prevention signatures to detect traffic to the domain, and ensuring that URL filtering solutions block the site. Because the infrastructure relies on Cloudflare, IP‑based blocking may inadvertently affect legitimate services; therefore, domain‑based blocking is recommended. Continuous monitoring for newly registered domains using the same registrar or similar naming patterns (e.g., “reward” or “zen”) can help anticipate related campaigns.
Network Security Intelligence
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Nextron YARA rules | zenreward.site/ |
malware | Unique code from Jetriz, Swid & Jeniva of the Tetris framework |
| Hagezi Threat Feed | zenreward.site |
malicious | Sinkholed |
| DNS4EU | zenreward.site |
malicious | Sinkholed |
Threat Response Pipeline
Public Blocklist Status
Stored Capture
Domain Intelligence
Technical detailsDNS, SSL SANs, timestamps
ICANN OVERSIGHT
Accreditation and RAA context
Accreditation and RAA context
Registrar accreditation and DNS abuse obligations
For this gTLD, the registrar above operates under an ICANN accreditation agreement. The links below provide the official fee schedule and current DNS abuse compliance guidance.
Accreditation is a contract, not a safety certification.
RAA §3.18 establishes abuse-contact and handling requirements. This report can document stored outbound notices and later technical observations; it does not by itself establish receipt, investigation, remediation, or contractual non-compliance.
Technologies · 3 identified
Cloudflare Browser Insights is a tool that measures the performance of websites from the perspective of users.
www.cloudflare.com 100% confidenceCloudflare is a web-infrastructure and website-security company, providing content-delivery-network services, DDoS mitigation, Internet security, and distributed domain-name-server services.
www.cloudflare.com 100% confidenceHTTP/3 is the third major version of the Hypertext Transfer Protocol used to exchange information on the World Wide Web.
httpwg.org 100% confidenceVirusTotal Analysis
Evidence & External Reports
PD-20260717-C7BE4A Recipient: abuse@spaceship.com Were You Affected by This Site?
If credentials, payment data, or files were exposed, report the incident immediately. Change affected passwords, revoke active sessions, and scan the device.
Report to Your Local Authorities
Select your country to get official cybercrime contacts, or create a complaint draft →.
Check Any Domain
Threat analysis using stored blocklist, WHOIS, DNS, and public scan evidence
Scan NowReport Phishing
Submit suspicious domains to our threat database — protect the community
ReportLive Threat Feed
Recent phishing reports and observed availability changes
MonitorStay Informed, Stay Safe
Monitor live threats or contest this listing if you believe it's a false positive